Security Engineer
Job Description
The Security Engineer (Red Team) role supports SpaceX’s Information Security and Vulnerability Management team by identifying, assessing, and helping remediate vulnerabilities and threats. The position also emphasizes developing security tooling and operational processes to improve detection, prioritization, and risk communication.
Responsibilities
- Develop tools, processes, and security guidance that improve adoption without slowing delivery.
- Perform software code reviews to identify insecure patterns and assist teams with remediation.
- Conduct web application security testing using established frameworks and tools.
- Triaging and validating Bugcrowd reports, coordinating with researchers, and partnering with internal teams on remediation and disclosure.
- Execute Purple Team exercises to test controls, enhance detection, and close identified gaps.
- Contribute to Red Team operations or simulations, including scoping, execution support, and post-exercise analysis.
- Build and operate vulnerability communication processes that provide timely, actionable alerts on new threats.
- Perform continuous threat assessment by incorporating threat intelligence, emerging vulnerabilities, and attack trends into scanning coverage, notifications, and prioritization.
- Collaborate with other security sub-teams including detection/response, compliance, application security, and infrastructure to maintain consistent efforts and reduce duplication.
- Escalate critical or time-sensitive issues promptly and offer practical mitigation options.
- Document findings, produce metrics, and deliver regular risk summaries to leadership.
Requirements
- Bachelor’s degree in computer science or another STEM discipline; or 2+ years of professional experience in security software development in lieu of a degree.
- Experience with Python; experience with GO, C#, C/C++, or Rust.
- Experience designing and implementing security solutions for operating systems, distributed systems, or other enterprise or large-scale infrastructure.
Preferred Skills and Experience
- Experience identifying, assessing, and remediating vulnerabilities across applications, infrastructure, or cloud.
- Experience working directly with engineering teams to close findings.
- Scripting and automation experience using Python, Bash, PowerShell, or similar, including building internal tools.
- Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls) and their relationship to vulnerability exposure.
- Reverse engineering or vulnerability development experience.
- Experience triaging or working reports from bug bounty platforms such as Bugcrowd or HackerOne.
- Hands-on participation in Purple Team or Red Team exercises.
- OT Security experience.
- Experience with continuous threat assessment, threat intelligence, or risk-based vulnerability prioritization.
- Experience developing internal security tools, dashboards, or automation pipelines with production-quality code and integrations.
- Experience with web application testing frameworks and tools.
- Experience performing software code reviews for security issues.
- Experience improving developer experience for security tooling and processes.
- Knowledge of network segmentation principles and implementation.
- Experience with asset discovery or inventory processes.
- Experience building or operating emerging vulnerability notification or alerting workflows.
- Familiarity with AI/LLMs and MCPs.
- Familiarity with cloud environments (AWS, Azure, GCP) and their native security or vulnerability features.
- Experience with configuration management, patching, or infrastructure-as-code.
- Knowledge of threat modeling, risk scoring (for example, CVSS), and prioritization frameworks.
- Familiarity with enterprise security controls and best practices for Windows, Linux, and macOS.
- Strong communication skills, translating technical findings into business impact and clear remediation steps.
- Relevant certifications (for example, OSCP, GSEC, or equivalent) or demonstrated equivalent experience.
- Demonstrated problem-solving skills, including ability to determine root causes quickly.
Location and Work Schedule
- Texas (onsite)
- Must be willing to work extended hours and/or weekends as needed.
- Hybrid or remote work will not be considered.
Required Technologies
- Python
- GO
- C#
- C/C++
- Rust
- Bugcrowd
ITAR Requirements
To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.