Apex
Los Angeles, CA
Mission Security Engineer
We tailor your resume to this role and apply for you in seconds.
Apply to Mission Security Engineer at ApexJob details
- Location
- Los Angeles, CA
- Work type
- Onsite
- Compensation
- $162,000 - $198,000/yr
- Clearance
- Required
- Posted
- today
- Apply on
- jobs.ashbyhq.com
About this role
Apex manufactures satellite buses at scale to expand access to space and support applications including Earth observation and communications. The Mission Security Engineer will own authorization postures for a space vehicle and classified cloud mission operations environment, develop RMF documentation and authorization packages, manage continuous monitoring, and automate evidence generation across mission systems.
What you'll do:
- Build and sustain authorization packages for both boundaries: system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, assessment coordination, and the residual risk picture carried to the AO
- Get assessors engaged early on our evidence-generation approach so generated artifacts are trusted before a package depends on them
- Own the POA&M
- Maintain the authorization system of record (eMASS or equivalent)
- Own the authorization boundary determination for the flight segment and the rationale that survives assessor scrutiny
- Categorize under CNSSI 1253 and defend overlay selection, treating the Space Platform Overlay as the starting place it is rather than a finished answer — pushing back where our onboard security capability exceeds what the published tailoring assumes
- Tailor the control baseline with per-control rationale, using Aerospace's Space Segment Cybersecurity Profile (TOR-2023-02161 Rev A) and SPARTA-linked tailoring, including arguing controls back in where our onboard capability exceeds what those baselines assumed
- Define the type-authorization for the bus and design how each vehicle off the line generates its own conformance evidence so fleet growth does not mean linear growth in assessment labor
- Derive verifiable security requirements from threat using SPARTA TTPs as the traceability key, owned by the software and mission integration engineers who will build and test against them
- Translate verification and production artifacts into assessment evidence and tell engineering early when what they produce will not satisfy an assessor
- Own the continuous monitoring story for a fielded fleet: security audit downlinked across contact windows, configuration drift across vehicles, and on-orbit software update as a recurring authorization event
- Define and document the authorization boundary for mission systems in classified cloud (AWS, Azure classified regions, or equivalent), including impact-level scoping and the seam with ground stations and the RF edge
What they're looking for:
- U.S. Citizenship (must possess the ability to access export-controlled data)
- Experience with technical tooling: reading pipeline output, querying an API, interpreting scanner and configuration state
- Bachelor's, master's, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field
- Clear experience with hands-on building via coursework, internships, research code, personal projects, CTFs, a co-op, or an early role and/or some exposure to RMF, security compliance, cloud, or software engineering
- Willingness to learn RMF from the ground up, with a demonstrated ability to pick up a complicated technical domain quickly and hold a lot of detail without losing the thread
- Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows
- Strong experience in embedded/space systems or cloud infrastructure
- Multiple systems taken to authorization in national security or DoD environments, with fluency in RMF as practiced: categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers
- Ability to speak concretely about categorization, tailoring, assessment, and authorization, and to design, document, or test a report and determine whether it constitutes evidence that a control is satisfied
- Direct experience with at least one accredited cloud environment and one non-traditional system such as embedded, weapons, platform IT, industrial, or space
- Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows
- Active Top Secret clearance with SCI access and SAP eligibility strongly preferred
Benefits:
- Receive equity in Apex, letting you benefit from the work you create
- 100% company-paid medical, dental, and vision for you and your dependents, plus $100k life insurance at no cost
- Comprehensive PTO package to reset and recharge - starting at 15 days vacation, growing to 20+ days annually, plus 10 paid holidays
- Competitive 401(k) plan with generous matching - 100% match on first 3%, 50% on next 2%
- 8 weeks paid parental leave plus childcare reimbursement up to $350/day for work-related travel
- Daily catered lunch and unlimited snacks
- Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family
- Your dream desk setup and all the tools you need to be your most productive self
- World-class Playa Vista office with the benefit of in-person collaboration with amazing coworkers and flexibility to integrate work and life
- Work alongside experts from aerospace, new space, and other cutting-edge industries to make a lasting difference
Ready to apply to Apex?
ApplyBolt finds matching jobs, tailors your resume, and submits applications for you.