user avatar

Mission Security Engineer

Apex Technology, Inc.

Posted today

Job Requirements

Los Angeles, CA
Top Secret/SCI Polygraph not specified
Early Career (2+ yrs experience)
$162,000 - $198,000

Job Description

Spacecraft represent the most pressing unmet need across the entire aerospace industry. As more launch vehicles come online and the cost to orbit decreases, more companies launching payloads to space continue to emerge.

For the first time in history, this influx of payload companies combined with reduced launch costs has resulted in a massive increase in need for commercial spacecraft platforms, known as satellite buses. These buses hold the payloads of our customers and are flown on launch vehicles.

Apex manufactures these satellite buses at scale using a combination of software, vertical integration, and hardware that is designed for manufacturing. Our spacecraft enable the future of society: ranging from earth observation to communications and more.

We’d love for you to join us on our mission of providing humankind access to the galaxy beyond our planet.

About the Role
In this position, you will own the authorization posture of two systems: a space vehicle with a multi-decade operational life, and a classified cloud mission operations environment that changes daily and cannot miss a pass, hosting command and control, telemetry, mission planning, flight dynamics, and payload processing. You will contribute to cyber engineering and produce RMF authorization documentation, build and sustain authorization packages, own the plan of action and milestones day to day, and run continuous monitoring. This is mission systems work throughout, not traditional enterprise IT security.

We are open to candidates from ISSE, SSE, ISSM, or ISSO backgrounds, and are hiring across levels: from new and recent graduates through senior engineering, officer, and manager experience.

Responsibilities:
May include any or all of the following:

Authorization Ownership

Build and sustain authorization packages for both boundaries: system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, assessment coordination, and the residual risk picture carried to the AO.

Get assessors engaged early on our evidence-generation approach so generated artifacts are trusted before a package depends on them.

Own the POA&M.

Maintain the authorization system of record (eMASS or equivalent).

Space Vehicle Segment

Own the authorization boundary determination for the flight segment and the rationale that survives assessor scrutiny.

Categorize under CNSSI 1253 and defend overlay selection, treating the Space Platform Overlay as the starting place it is rather than a finished answer — pushing back where our onboard security capability exceeds what the published tailoring assumes.

Tailor the control baseline with per-control rationale, using Aerospace's Space Segment Cybersecurity Profile (TOR-2023-02161 Rev A) and SPARTA-linked tailoring, including arguing controls back in where our onboard capability exceeds what those baselines assumed.

Define the type-authorization for the bus and design how each vehicle off the line generates its own conformance evidence so fleet growth does not mean linear growth in assessment labor.

Derive verifiable security requirements from threat using SPARTA TTPs as the traceability key, owned by the software and mission integration engineers who will build and test against them.

Translate verification and production artifacts into assessment evidence and tell engineering early when what they produce will not satisfy an assessor.

Own the continuous monitoring story for a fielded fleet: security audit downlinked across contact windows, configuration drift across vehicles, and on-orbit software update as a recurring authorization event.

Classified Cloud Mission Operations Environment

Define and document the authorization boundary for mission systems in classified cloud (AWS, Azure classified regions, or equivalent), including impact-level scoping and the seam with ground stations and the RF edge.

Own the control and evidence story for operator command authority: identity, role separation, least privilege, two-person integrity, non-repudiation, and complete audit of every command that reaches the vehicle.

Build and defend the control inheritance model and prove the customer-responsible set with live evidence rather than assertion, validating what the cloud service provider and the platform satisfy versus what remains customer responsibility for the mission-unique applications.

Implement controls as code, so infrastructure-as-code, policy-as-code, and pipeline configuration serve as the implementation and the evidence at once.

Make change control and continuous monitoring work at operations tempo, never putting a contact window at risk, positioned for the DoD transition toward the Cybersecurity Risk Management Construct (CSRMC) and continuous authorization.

Manage security incident reporting and coordination for the boundary.

Automation and Generation

Define what evidence you need and in what form.

Design the OSCAL-based evidence data model and the mapping layer that resolves a property assertion to control identifiers across 800-53, CNSSI 1253 baselines, overlays, and program-unique control sets.

Build the pipeline that renders SSP sections, assessment evidence, POA&M items, and continuous monitoring reports deterministically from pinned evidence snapshots.

Integrate with the authorization system of record (eMASS or equivalent) programmatically, so generated artifacts land where assessors actually look.

Use AI-assisted drafting and crosswalk tooling for control narratives, framework mappings, and monitoring summaries, with human review on anything an AO reads and full traceability from every statement to a source record.

Push toward controls whose satisfaction is demonstrated by system state rather than by narrative.

Required Qualifications

At Every Level

U.S. Citizenship (must possess the ability to access export-controlled data)

Active Top Secret clearance with SCI access and SAP eligibility strongly preferred

Experience with technical tooling: reading pipeline output, querying an API, interpreting scanner and configuration state

Entry Level (1–3+ Years)

Bachelor's, master's, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field

Clear experience with hands-on building via coursework, internships, research code, personal projects, CTFs, a co-op, or an early role and/or some exposure to RMF, security compliance, cloud, or software engineering

Willingness to learn RMF from the ground up, with a demonstrated ability to pick up a complicated technical domain quickly and hold a lot of detail without losing the thread

Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows

Senior Level (5–10+ Years)

Strong experience in embedded/space systems or cloud infrastructure

Multiple systems taken to authorization in national security or DoD environments, with fluency in RMF as practiced: categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers

Ability to speak concretely about categorization, tailoring, assessment, and authorization, and to design, document, or test a report and determine whether it constitutes evidence that a control is satisfied

Direct experience with at least one accredited cloud environment and one non-traditional system such as embedded, weapons, platform IT, industrial, or space

Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows

Preferred Qualifications

OSCAL, eMASS APIs, Xacta, controls-as-code, or continuous-controls-monitoring implementation experience

Experience with continuous authorization, ongoing authorization, or cATO

Experience building with AI-assisted development

Understanding of Mission Operations including satellite command and control, mission planning, flight dynamics, telemetry processing, or multi-mission ground segments

Embedded or safety-critical background in space, automotive, or industrial control

SPARTA, NIST IR 8270 or IR 8401, CCSDS security standards, Space Platform Overlay, NASA/Space Force system protection standards, or space-system threat modeling

Classified cloud accreditation at IL5/IL6 or IC equivalents, or accreditation under JSIG or ICD 703

Qualified, or able to qualify, under DoDM 8140.03 for a systems security engineering, security architecture, or Information Systems Security Manager work role. CISSP, CISSP-ISSEP, CISM, and SecurityX map well.
group id: 91136884