CybersecurityJobs.io
← Back to all jobs

Job Description

Apex Technology, Inc. is seeking a Mission Security Engineer to help shape the authorization posture of a space vehicle and a classified cloud mission operations environment. In this onsite role in Los Angeles, you will build and sustain RMF authorization packages, maintain an authorization system of record, and support continuous monitoring using modern evidence automation with OSCAL and associated tooling.

This position focuses on mission systems security work rather than traditional enterprise IT security. You will own critical authorization artifacts end to end, engage assessors early on evidence generation, and help translate engineering output into assessor-ready evidence that supports sustained authorization across a fielded fleet.

What you will do

  • Build and sustain authorization packages for both authorization boundaries, including system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, assessment coordination, and the residual risk picture carried to the AO.
  • Drive evidence-generation planning with assessors early so artifacts produced for packages are trusted before dependencies form.
  • Own the plan of action and milestones (POA&M).
  • Maintain the authorization system of record (eMASS or equivalent).
  • Own authorization boundary determination for the flight segment and ensure the rationale withstands assessor scrutiny.
  • Categorize under CNSSI 1253 and defend overlay selection, using the Space Platform Overlay as a starting point and pushing back where onboard security capability exceeds published tailoring assumptions.
  • Tailor the control baseline with per-control rationale, including use of Aerospace’s Space Segment Cybersecurity Profile (TOR-2023-02161 Rev A) and SPARTA-linked tailoring, and argue controls back in when onboard capability exceeds baseline assumptions.
  • Define type-authorization for the bus and design how each vehicle generates its own conformance evidence to avoid linear assessment labor growth across the fleet.
  • Derive verifiable security requirements from threats using SPARTA TTPs as the traceability key, owned by software and mission integration engineers who will build and test against them.
  • Translate verification and production artifacts into assessment evidence, and alert engineering when outputs will not satisfy assessor expectations.
  • Own the continuous monitoring story for a fielded fleet, covering security audit downlinks across contact windows, configuration drift across vehicles, and on-orbit software updates as recurring authorization events.
  • Define and document the authorization boundary for classified cloud mission systems (AWS, Azure classified regions, or equivalent), including impact-level scoping and the seam between ground stations and the RF edge.
  • Own the control and evidence story for operator command authority, including identity, role separation, least privilege, two-person integrity, non-repudiation, and complete audit of every command reaching the vehicle.
  • Define and defend a control inheritance model, proving the customer-responsible set with live evidence rather than assertion, validating cloud service provider and platform responsibilities against mission-unique application responsibilities.
  • Implement controls as code, using infrastructure-as-code, policy-as-code, and pipeline configuration to serve both implementation and evidence.
  • Make change control and continuous monitoring work at operational tempo without putting contact windows at risk, aligned with the DoD transition toward the Cybersecurity Risk Management Construct (CSRMC) and continuous authorization.
  • Manage security incident reporting and coordination for the boundary.
  • Define what evidence is needed and in what form.
  • Design the OSCAL-based evidence data model and the mapping layer that resolves a property assertion to control identifiers across 800-53, CNSSI 1253 baselines, overlays, and program-unique control sets.
  • Build a pipeline that deterministically renders SSP sections, assessment evidence, POA&M items, and continuous monitoring reports from pinned evidence snapshots.
  • Integrate programmatically with the authorization system of record (eMASS or equivalent) so artifacts land where assessors look.
  • Use AI-assisted drafting and crosswalk tooling for control narratives, framework mappings, and monitoring summaries, with human review on anything an AO reads and full traceability from each statement to a source record.
  • Move toward controls whose satisfaction is demonstrated by system state rather than narrative.

How you qualify

  • U.S. Citizenship (ability to access export-controlled data is required)
  • Active Top Secret clearance with SCI access and SAP eligibility strongly preferred
  • Experience with technical tooling such as reading pipeline output, querying an API, and interpreting scanner and configuration state
  • Bachelor’s, master’s, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field
  • Clear experience building hands-on via coursework, internships, research code, personal projects, CTFs, co-op, or an early role, including exposure to RMF, security compliance, cloud, or software engineering
  • Willingness to learn RMF from the ground up, demonstrating the ability to pick up a complex technical domain quickly while retaining detail
  • Strong experience in embedded/space systems or cloud infrastructure
  • Experience taking multiple systems through authorization in national security or DoD environments with fluency in RMF as practiced (categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers)
  • Ability to discuss categorization, tailoring, assessment, and authorization concretely, including designing, documenting, or testing reports and determining whether they constitute evidence that a control is satisfied
  • Direct experience with at least one accredited cloud environment and one non-traditional system (for example: embedded, weapons, platform IT, industrial, or space)

Technologies you will work with

  • eMASS, OSCAL, SPARTA, CNSSI 1253, 800-53
  • AWS, Azure (classified regions)
  • TOR-2023-02161 Rev A, SPARTA TTPs
  • Xacta, Python, Go, CI/CD
  • Infrastructure-as-code, policy-as-code, Git-based workflows
  • SSP, POA&M, CSRMC, DoD transition toward CSRMC and continuous authorization

Education

  • Bachelor’s, master’s, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field

Compensation and location

  • Location: Los Angeles, CA (onsite)
  • Salary: USD 162,000 - 198,000 per yearly

Benefits

  • Receive equity in Apex
  • 100% company-paid medical, dental, and vision for you and your dependents
  • $100k life insurance at no cost
  • Comprehensive PTO package to reset and recharge, starting at 15 days vacation and growing to 20+ days annually, plus 10 paid holidays
  • Competitive 401(k) plan with generous matching: 100% match on first 3%, 50% on next 2%
  • 8 weeks paid parental leave plus childcare reimbursement up to $350/day for work-related travel
  • Daily catered lunch and unlimited snacks
  • Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family
  • Your dream desk setup and all the tools you need to be your most productive self
  • World-class Playa Vista office with in-person collaboration and flexibility to integrate work and life
  • Work alongside experts from aerospace, new space, and other cutting-edge industries to make a lasting difference

Leveling and background fit

  • Open to candidates from ISSE, SSE, ISSM, or ISSO backgrounds, with hiring across levels from new and recent graduates through senior engineering, officer, and manager experience
  • At every level: U.S. Citizenship required; Active Top Secret clearance with SCI access and SAP eligibility strongly preferred; experience with technical tooling for pipelines, APIs, and scanner/config interpretation

Preferred qualifications

  • Experience with OSCAL, eMASS APIs, Xacta, controls-as-code, or continuous-controls-monitoring implementation
  • Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows
  • Experience with continuous authorization, ongoing authorization, or cATO
  • Experience building with AI-assisted development
  • Understanding of Mission Operations including satellite command and control, mission planning, flight dynamics, telemetry processing, or multi-mission ground segments
  • Embedded or safety-critical background in space, automotive, or industrial control
  • Experience with SPARTA, NIST IR 8270 or IR 8401, CCSDS security standards, Space Platform Overlay, NASA/Space Force system protection standards, or space-system threat modeling
  • Experience with classified cloud accreditation at IL5/IL6 or IC equivalents, or accreditation under JSIG or ICD 703
  • Qualified, or able to qualify, under DoDM 8140.03 for a systems security engineering, security architecture, or Information Systems Security Manager work role; CISSP, CISSP-ISSEP, CISM, and SecurityX map well

Similar Jobs