Senior Security Engineer (Cloud & Network Security)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: United States (Remote). Applicants must qualify as a U.S. person, be eligible to access export-controlled information without authorization, or be eligible and reasonably likely to obtain the required export authorization.
Company
develops laser communications technology and temporospatial software-defined networking platforms for aerospace, satellite, airborne, cislunar, and deep-space communications.
What you will do
- Design and operate secure cloud networking architectures across GCP, AWS, or Azure, including VPCs, subnets, peering, transit gateways, firewalls, and traffic controls.
- Implement network segmentation, micro-segmentation, zero trust controls, IDS/IPS, DNS security, NAC, and network monitoring across cloud and on-premises environments.
- Design and manage PKI infrastructure, certificate lifecycles, mTLS, VPN authentication, code signing, IAM, PAM, MFA, RBAC, and SSO systems.
- Implement technical controls aligned with CMMC Level 2, FedRAMP, NIST 800-171, NIST RMF, DISA STIGs, and CIS Benchmarks.
- Maintain SIEM, EDR, vulnerability scanning, logging, alerting, compliance evidence collection, and security reporting automation.
- Document security architecture, network diagrams, access control matrices, system security plans, assessment reports, and remediation plans.
Requirements
- 5+ years of experience in cloud infrastructure security, network security, or IT systems engineering with a security focus.
- Hands-on experience securing GCP, AWS, or Azure environments, including networking, IAM, and logging controls; GCP is strongly preferred.
- Experience managing firewalls, security groups, VPC/VNet architecture, traffic inspection, and next-generation firewall policies.
- Working knowledge of PKI, certificate lifecycle management, TLS, mTLS, and FIPS 140-2/140-3.
- Experience with IAM, PAM, MFA, RBAC, SSO, SIEM platforms, log aggregation, and infrastructure security monitoring.
- Direct experience with CMMC L2, FedRAMP, or NIST 800-171 compliance programs and strong communication skills.
Nice to have
- Active Secret or Top Secret clearance, or the ability to obtain one.
- Experience with enterprise or government PKI, HSMs, FIPS-validated cryptographic modules, and federal environments.
- Experience with Wiz, AWS Security Hub, GCP Security Command Center, Azure Defender, Terraform, or Ansible.
- Knowledge of DISA STIGs, CIS Benchmarks, NAC, SD-WAN, SASE, Linux, Windows, and cloud hardening.
- Security certifications such as CISSP, CCSP, Security+, or relevant cloud security certifications.
Culture & Benefits
- Work on aerospace communications and national security programs.
- Flexible working arrangements, including hybrid remote/in-office schedules.
- Professional development and advancement opportunities.
- Collaborative, supportive, and inclusive workplace.
- Competitive compensation, equity options, paid time off, health, dental, vision, life insurance, and 401(k).
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β