Remote job
Senior Security Engineer
Job details
About this role
Role overview
This role focuses on protecting space mission infrastructure end-to-end, including satellite platforms, ground systems, command-and-control interfaces, and supporting cloud environments. The engineer will operate with significant autonomy to design controls, monitor threats, and harden systems across an aerospace mission stack. The position also contributes to compliance programs aligned to frameworks such as NIST SP 800-171 and CMMC.
Responsibilities
- Design and implement cybersecurity controls for satellite software, ground systems, communication links, and mission infrastructure - Build secure development practices for flight and mission software, including threat modeling, code review, vulnerability management, and security testing - Monitor mission networks and satellite assets for cyber threats, lead incident investigation, and coordinate containment and recovery - Architect network security including firewall rule sets, IDS/IPS tuning, segmentation strategy, and VPN infrastructure - Harden identity platforms such as Okta and AWS IAM with SSO integrations, conditional access policies, privilege reviews, and lifecycle automation - Drive cloud security posture across AWS, covering IAM policy hygiene, S3 protections, security group reviews, and GuardDuty and CloudTrail monitoring - Develop SIEM detections and response playbooks, maintain DLP controls for controlled unclassified information, and support forensic analysis during incidents - Maintain System Security Plan narratives, gather compliance evidence, and prepare for CMMC and NIST 800-171 assessments
Requirements
- At least 5 years of experience in information security or security engineering roles - Active TS/SCI clearance, or eligibility to obtain one - Familiarity with satellite communication protocols, embedded systems, and RF or space-to-ground link security - Hands-on experience securing aerospace or mission systems such as satellites, ground stations, flight software, or command-and-control interfaces - Proficiency with AWS cloud security services including IAM, VPC, Security Groups, CloudTrail, GuardDuty, and Config - Working knowledge of SIEM platforms such as Splunk, Sentinel, or Elastic for detection engineering and log analysis - Familiarity with compliance frameworks including NIST 800-171, CMMC, SOC 2, or ISO 27001 - Strong written and verbal communication skills, with the ability to convey technical risk to engineers and leadership
Nice to have
- Relevant certifications such as CISSP, GIAC, CEH, or AWS Security Specialty - Experience with infrastructure-as-code security in Terraform or CloudFormation and CI/CD pipeline protection - Background operating under ITAR or EAR export control requirements
Benefits and work setup
- Flexible work arrangement with options for on-site, hybrid, or fully remote from a wide set of approved U.S. states - Compensation package includes equity plus benefits such as medical, dental, and vision insurance, 401(k) retirement plan, short- and long-term disability, and life insurance - Generous time off including three weeks of paid vacation for new employees, twelve paid holidays, unlimited sick time, and paid parental leave
Export control note
The role involves access to export-controlled information. To comply with U.S. Government export regulations, applicants must be a U.S. person (citizen, national, lawful permanent resident, refugee, or asylee) or otherwise eligible to access such information without, or with the ability to obtain, the required export authorization.