Senior Security Engineer, Identity and Access Management (IAM) (Aerospace)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Location: Los Angeles, CA, United States. The role involves access to ITAR-controlled information and requires the hire to be a U.S. person or otherwise eligible for a federally issued export-control license.
Salary: $150,000β$220,000 per year, plus equity.
Company
is a Series C aerospace startup building high-power satellite platforms for commercial and U.S. government missions from low Earth orbit to deep space.
What you will do
- Own and mature the enterprise identity platform, including identity providers, SSO, federation, directory services, and conditional access.
- Design authentication standards using SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos, and drive adoption of FIDO2/WebAuthn-based MFA.
- Build joiner, mover, and leaver automation, just-in-time access, RBAC/ABAC models, access reviews, and least-privilege standards.
- Operate privileged access, secrets management, credential rotation, and machine/workload identity for automated pipelines and mission systems.
- Harden AWS, Azure, or GCP IAM and automate identity operations with code and infrastructure as code.
- Partner with security operations and engineering on identity threat detection, investigations, architecture reviews, documentation, and mentoring.
Requirements
- 5+ years of experience in identity and access management, security engineering, or infrastructure engineering.
- Hands-on administration of an enterprise identity provider such as Okta, Microsoft Entra ID, Ping, or Google Identity.
- Experience with identity lifecycle automation, RBAC or ABAC, access reviews, privileged access management, and secrets management.
- Experience with cloud IAM in AWS, Azure, or GCP and least-privilege role and policy design.
- 2+ years of development experience with a modern programming language for identity automation, or a relevant STEM bachelor's degree.
- Must qualify as a U.S. person under ITAR or be eligible for a federally issued export-control license.
Nice to have
- Identity or security certifications such as Okta Certified Administrator, Microsoft SC-300, or CISSP.
- Infrastructure as code with Terraform, CloudFormation, or CDK, and policy as code with OPA or Cedar.
- Identity threat detection and response, Active Directory modernization, or legacy-system integration experience.
- Experience with identity and access control in aerospace, defense, manufacturing, OT, engineering, or mission and ground-segment environments.
Culture & Benefits
- Fast-paced Series C environment focused on building large-scale satellite platforms.
- Paid time off, medical, dental, and vision coverage.
- Life insurance and paid parental leave.
- Equity in the company and additional benefits and perks.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β