Назад
Company hidden
9 часов назад

Lead Product Security Engineer (Aerospace)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Product Security Engineer (Aerospace): Securing application software, CI/CD pipelines, Kubernetes infrastructure, product PKI, and distributed aerospace communication systems with an accent on cryptography, supply-chain security, and firmware collaboration. Focus on hardening GKE and Kubernetes environments, designing mTLS and certificate lifecycle systems, leading product incident response, and translating CMMC, FedRAMP, and DFARS controls into engineering work.

Location: Remote in the United States; flexible hybrid remote/in-office schedules are also available. Access to export-controlled information requires meeting applicable U.S. government ITAR/EAR eligibility criteria.

Company

hirify.global develops laser communications technology and temporospatial software-defined networking platforms for aerospace, satellite, airborne, cislunar, and deep-space communication networks.

What you will do

  • Own application and software security, including SAST, DAST, SCA, secure SDLC, threat modeling, and vulnerability management.
  • Harden GitLab CI/CD pipelines and software supply chains through build provenance, dependency integrity, signing, and SLSA-aligned controls.
  • Secure GKE and Kubernetes product infrastructure with container security, workload identity, network policies, runtime protection, and secure baselines.
  • Design and operate product PKI, including certificate issuance, lifecycle management, rotation, key management, and mTLS for distributed services and remote assets.
  • Lead product security incident response, vulnerability triage, remediation tracking, exception handling, coordination with engineering, and post-mortems.
  • Partner with hardware and firmware teams on secure boot, key storage, firmware security, and hardware supply-chain integrity.

Requirements

  • Senior- or staff-level hands-on experience in product security or security engineering, with substantial application security depth.
  • Production experience securing cloud environments, IAM, organization policies, VPC Service Controls, KMS, and Kubernetes.
  • Strong foundations in cryptography, PKI architecture, key management, signing, mTLS, and secrets handling at scale.
  • Hands-on coding ability in Python, Bash, and Go, including automation, tooling, Terraform, and security controls.
  • Experience building security programs, leading product incident response, mentoring engineers, and working with hardware or firmware teams.
  • Working knowledge of CMMC, FedRAMP, and DFARS, with the ability to translate compliance controls into engineering work.

Nice to have

  • Experience with NIST 800-53, NIST 800-171, DoD SRG, or government-cloud platforms.
  • Hardware security experience with HSMs, TPMs, secure elements, supply-chain attestation, embedded security, secure boot, roots of trust, or OTA update integrity.
  • Experience operating vulnerability disclosure programs or bug bounties, including researcher communications and CVE coordination.

Culture & Benefits

  • Work on aerospace communications and critical national security programs.
  • Professional development and career advancement opportunities.
  • Collaborative, supportive, and inclusive workplace.
  • Flexible remote and in-office work arrangements.
  • Competitive compensation, equity options, 401(k), health, dental, vision, life insurance, and paid time off.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →