Skip to main content

Mission Security Engineer

Apex SpaceSecurityOperations
Pay
$162K–$198K
per year
Work mode
On-site
Internship
Education
Master's or PhD

Los Angeles, CA at a glance

Rent
#2 of 51
$2,070/mo+46% vs US avg
Weather
#17 of 51
366 mild days0 hot · 0 cold
Income tax
#1 of 51
13.3% top rateCalifornia

What you need

Tech

PythonGoRMFOSCALSPARTA

Experience

  • 1-10+ yrs space security
  • RMF authorization

Education

  • BS in systems engineering or CS

What you'll do

  • Own space vehicle authorization
  • Build authorization packages
  • Define cloud authorization boundary
  • Implement controls as code

Spacecraft represent the most pressing unmet need across the entire aerospace industry. As more launch vehicles come online and the cost to orbit decreases, more companies launching payloads to space continue to emerge.

For the first time in history, this influx of payload companies combined with reduced launch costs has resulted in a massive increase in need for commercial spacecraft platforms, known as satellite buses. These buses hold the payloads of our customers and are flown on launch vehicles.

Apex manufactures these satellite buses at scale using a combination of software, vertical integration, and hardware that is designed for manufacturing. Our spacecraft enable the future of society: ranging from earth observation to communications and more.

We’d love for you to join us on our mission of providing humankind access to the galaxy beyond our planet. 


About the Role

In this position, you will own or contribute to the authorization posture of two systems: a space vehicle and a classified cloud mission operations environment. You will contribute to cyber engineering and produce RMF authorization documentation, build and sustain authorization packages, own the plan of action and milestones day to day, and run continuous monitoring. This is mission systems work throughout, not traditional enterprise IT security.

We are open to candidates from ISSE, SSE, ISSM, or ISSO backgrounds, and are hiring across levels: from new and recent graduates through senior engineering, officer, and manager experience.

Responsibilities:
May include any or all of the following:

Authorization Ownership

  • Build and sustain authorization packages for both boundaries: system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, assessment coordination, and the residual risk picture carried to the AO.

  • Get assessors engaged early on our evidence-generation approach so generated artifacts are trusted before a package depends on them.

  • Own the POA&M.

  • Maintain the authorization system of record (eMASS or equivalent).

Space Vehicle Segment

  • Own the authorization boundary determination for the flight segment and the rationale that survives assessor scrutiny.

  • Categorize under CNSSI 1253 and defend overlay selection, treating the Space Platform Overlay as the starting place it is rather than a finished answer — pushing back where our onboard security capability exceeds what the published tailoring assumes.

  • Tailor the control baseline with per-control rationale, using Aerospace's Space Segment Cybersecurity Profile (TOR-2023-02161 Rev A) and SPARTA-linked tailoring, including arguing controls back in where our onboard capability exceeds what those baselines assumed.

  • Define the type-authorization for the bus and design how each vehicle off the line generates its own conformance evidence so fleet growth does not mean linear growth in assessment labor.

  • Derive verifiable security requirements from threat using SPARTA TTPs as the traceability key, owned by the software and mission integration engineers who will build and test against them.

  • Translate verification and production artifacts into assessment evidence and tell engineering early when what they produce will not satisfy an assessor.

  • Own the continuous monitoring story for a fielded fleet: security audit downlinked across contact windows, configuration drift across vehicles, and on-orbit software update as a recurring authorization event.

Classified Cloud Mission Operations Environment

  • Define and document the authorization boundary for mission systems in classified cloud (AWS, Azure classified regions, or equivalent), including impact-level scoping and the seam with ground stations and the RF edge.

  • Own the control and evidence story for operator command authority: identity, role separation, least privilege, two-person integrity, non-repudiation, and complete audit of every command that reaches the vehicle.

  • Build and defend the control inheritance model and prove the customer-responsible set with live evidence rather than assertion, validating what the cloud service provider and the platform satisfy versus what remains customer responsibility for the mission-unique applications.

  • Implement controls as code, so infrastructure-as-code, policy-as-code, and pipeline configuration serve as the implementation and the evidence at once.

  • Make change control and continuous monitoring work at operations tempo, never putting a contact window at risk, positioned for the DoD transition toward the Cybersecurity Risk Management Construct (CSRMC) and continuous authorization.

  • Manage security incident reporting and coordination for the boundary.

Automation and Generation

  • Define what evidence you need and in what form.

  • Design the OSCAL-based evidence data model and the mapping layer that resolves a property assertion to control identifiers across 800-53, CNSSI 1253 baselines, overlays, and program-unique control sets.

  • Build the pipeline that renders SSP sections, assessment evidence, POA&M items, and continuous monitoring reports deterministically from pinned evidence snapshots.

  • Integrate with the authorization system of record (eMASS or equivalent) programmatically, so generated artifacts land where assessors actually look.

  • Use AI-assisted drafting and crosswalk tooling for control narratives, framework mappings, and monitoring summaries, with human review on anything an AO reads and full traceability from every statement to a source record.

  • Push toward controls whose satisfaction is demonstrated by system state rather than by narrative.

Required Qualifications

At Every Level

  • U.S. Citizenship (must possess the ability to access export-controlled data)

  • Active Top Secret clearance with SCI access and SAP eligibility strongly preferred

  • Experience with technical tooling: reading pipeline output, querying an API, interpreting scanner and configuration state

Entry Level (1–3+ Years)

  • Bachelor's, master's, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field

  • Clear experience with hands-on building via coursework, internships, research code, personal projects, CTFs, a co-op, or an early role and/or some exposure to RMF, security compliance, cloud, or software engineering

  • Willingness to learn RMF from the ground up, with a demonstrated ability to pick up a complicated technical domain quickly and hold a lot of detail without losing the thread

Senior Level (5–10+ Years)

  • Strong experience in embedded/space systems or cloud infrastructure

  • Multiple systems taken to authorization in national security or DoD environments, with fluency in RMF as practiced: categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers

  • Ability to speak concretely about categorization, tailoring, assessment, and authorization, and to design, document, or test a report and determine whether it constitutes evidence that a control is satisfied

  • Direct experience with at least one accredited cloud environment and one non-traditional system such as embedded, weapons, platform IT, industrial, or space

Preferred Qualifications

  • Experience with OSCAL, eMASS APIs, Xacta, controls-as-code, or continuous-controls-monitoring implementation

  • Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows

  • Experience with continuous authorization, ongoing authorization, or cATO

  • Experience building with AI-assisted development

  • Understanding of Mission Operations including satellite command and control, mission planning, flight dynamics, telemetry processing, or multi-mission ground segments

  • Embedded or safety-critical background in space, automotive, or industrial control

  • Experience with SPARTA, NIST IR 8270 or IR 8401, CCSDS security standards, Space Platform Overlay, NASA/Space Force system protection standards, or space-system threat modeling

  • Experience with classified cloud accreditation at IL5/IL6 or IC equivalents, or accreditation under JSIG or ICD 703

  • Qualified, or able to qualify, under DoDM 8140.03 for a systems security engineering, security architecture, or Information Systems Security Manager work role. CISSP, CISSP-ISSEP, CISM, and SecurityX map well.


Why Join Apex?

Apex believes in creating a work environment that you look forward to embracing every day. Our employees love working at Apex, and we want you to love it too. We're a fast-growing startup that has raised more than $500M in funding, and we invest heavily in our people from day one.


What We Offer For Full-time Employees:

  • Shared upside: Receive equity in Apex, letting you benefit from the work you create

  • Best-in-class healthcare: 100% company-paid medical, dental, and vision for you and your dependents, plus $100k life insurance at no cost

  • Comprehensive PTO package to reset and recharge - starting at 15 days vacation, growing to 20+ days annually, plus 10 paid holidays

  • Competitive 401(k) plan with generous matching - 100% match on first 3%, 50% on next 2%

  • 8 weeks paid parental leave plus childcare reimbursement up to $350/day for work-related travel

  • Daily catered lunch and unlimited snacks to keep you fueled throughout the day

  • Vibrant community: Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family

  • Your dream desk setup and all the tools you need to be your most productive self

  • World-class Playa Vista office with the benefit of in-person collaboration with amazing coworkers and flexibility to integrate work and life

  • Real impact opportunity: Work alongside experts from aerospace, new space, and other cutting-edge industries to make a lasting difference

Ready to join a team where your contributions matter and your future is bright? Let's build something extraordinary together.


Equal Opportunity Employer

Apex Technology, Inc. is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Candidates and employees are always evaluated based on merit, qualifications, and performance. We will never discriminate on the basis of race, color, gender, national origin, ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability, or any other legally protected status.


Optimize your resume for this job

Get a match score and the keywords you're missing

Optimize resume

About Apex Space

Spacecraft represent the most pressing need across the entire aerospace industry. As more launch vehicles come online and the cost to orbit decreases, more companies launching payloads to space continue to emerge. For the first time in history, this influx of payload companies combined with reduced launch costs has resulted in a massive increase in need for commercial spacecraft platforms, known as satellite buses. These buses hold the payloads of our customers and are flown on launch vehicles. Apex manufactures these satellite buses at scale using a combination of software, vertical integration, and hardware that is designed for manufacturing. Our spacecraft enable the future of society: ranging from earth observation to communications and more. We’d love for you to join us on our mission of providing humankind access to the galaxy beyond our planet.

Similar Security roles

Mission Security Engineer
$162K–$198K · Apex Space
Apply