CybersecurityJobs.io
← Back to all jobs

Job Description

SpaceX is seeking a Security Engineer for its Vulnerability Management team in Texas (onsite). The position focuses on identifying, assessing, and driving remediation for vulnerabilities and threats, while also building and maintaining internal tools that help teams respond with speed and clarity.

Key Responsibilities

  • Develop security tools, processes, and guidance to improve adoption while supporting delivery timelines.
  • Conduct software code reviews to surface insecure patterns and support remediation by engineering teams.
  • Perform web application security testing using established frameworks and tools.
  • Triage and validate Bugcrowd reports, coordinate with external researchers, and collaborate with internal stakeholders on remediation and disclosure.
  • Execute Purple Team exercises to test controls, improve detection, and close identified gaps.
  • Support Red Team operations or simulations, including scoping, execution support, and post-exercise analysis.
  • Build and run vulnerability communication processes that deliver timely, actionable alerts to relevant teams.
  • Perform continuous threat assessment by integrating threat intelligence, emerging vulnerabilities, and observed attack trends into scanning coverage, notifications, and prioritization.
  • Partner with other security sub-teams such as detection and response, compliance, application security, and infrastructure to maintain alignment and reduce duplication.
  • Escalate critical or time-sensitive issues promptly and provide practical mitigation options.
  • Document findings, generate metrics, and deliver regular risk summaries to leadership.

Required Qualifications

  • Bachelor’s degree in computer science or another STEM discipline, or 2+ years of professional experience in security software development in lieu of a degree.
  • Experience with Python, and familiarity with Go, C#, C/C++, or Rust.
  • Experience designing and implementing security solutions for operating systems, distributed systems, or other enterprise or large-scale infrastructure.

Technologies

  • Python, GO, C#, C/C++, Rust
  • Bugcrowd
  • HTTP/S, DNS, TCP/IP

Preferred Skills and Experience

  • Experience identifying, assessing, and remediating vulnerabilities across applications, infrastructure, or cloud.
  • Experience working directly with engineering teams to close security findings.
  • Scripting and automation experience (Python, Bash, PowerShell, or similar) and the ability to develop internal tools.
  • Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls) as they relate to vulnerability exposure.
  • Reverse engineering or vulnerability development experience.
  • Experience triaging reports from bug bounty platforms (Bugcrowd, HackerOne, or similar).
  • Hands-on participation in Purple Team or Red Team exercises.
  • OT Security experience.
  • Experience with continuous threat assessment, threat intelligence, or risk-based vulnerability prioritization.
  • Experience developing internal security tools, dashboards, or automation pipelines with production-quality code and integrations.
  • Experience with web application testing frameworks and tools.
  • Experience performing software code reviews for security issues.
  • Experience improving developer experience around security tooling and processes.
  • Knowledge of network segmentation principles and implementation.
  • Experience with asset discovery or inventory processes.
  • Experience building or operating emerging vulnerability notification and alerting workflows.
  • Familiarity with AI/LLMs and MCPs.
  • Familiarity with cloud environments (AWS, Azure, GCP) and their native security and vulnerability features.
  • Experience with configuration management, patching, or infrastructure-as-code.
  • Knowledge of threat modeling, risk scoring (such as CVSS), and prioritization frameworks.
  • Familiarity with enterprise security controls and best practices for Windows, Linux, and macOS.
  • Strong communication skills to translate technical findings into business impact and remediation steps.
  • Relevant certifications (for example, OSCP, GSEC, or equivalent) or demonstrated equivalent experience.
  • Problem-solving ability to quickly determine root causes of issues.

Additional Information

  • Onsite role in Texas. Hybrid or remote work will not be considered.
  • Must be willing to work extended hours and/or weekends as needed.

ITAR Requirements

To conform to U.S. Government export regulations, the applicant must be one of the following: (i) a U.S. citizen or national, (ii) a U.S. lawful, permanent resident (green card holder), (iii) a Refugee under 8 U.S.C. § 1157, (iv) an Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.

Similar Jobs