Principal Cloud Security Engineer

Rocket Lab USA

Long Beach (CA)

On-site

USD 152,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Stock purchase program
Company stock
Medical plans
Dental and vision
Paid vacation and holidays
401(k) with match
EV charging subsidy
Onsite fitness centers
Discounted gym memberships
Snacks and beverages
Merch store discount

Job summary

Rocket Lab USA in Long Beach, CA seeks a Principal Cloud Security Engineer to secure our cloud-first platform across IaaS, PaaS, SaaS and FaaS. You will design controls, automate security, and guide DevSecOps and MLOps practices while collaborating with development teams.

You will drive risk analyses, IAM, audits, and tooling across AWS/Azure/GCP, with strong focus on incident response and secure software delivery. A 12+ year IT/cybersecurity background and US citizenship are required.

Qualifications

  • 12+ years of scripting and IaC tools experience.
  • Degree or equivalent years of work experience (16+ total years).
  • Cloud security architecture across AWS, Azure, GCP.

Responsibilities

  • Design, implement, and monitor security controls for hybrid cloud environments (IaaS, PaaS, SaaS, FaaS).
  • Develop automation to support cyber team objectives.
  • Provide security support for reviews and risk analyses.
  • Manage IAM for cloud resources and applications.
  • Collaborate with DevOps/SDLC, DevSecOps, and MLOps teams.
  • Lead audits, compliance reviews, and incident guidance.

Skills

Bash
PowerShell
Python
Terraform
Ansible
Git
Cloud security
IAM
Risk assessment
CI/CD security

Education

Bachelor's degree or equivalent

Tools

AWS
Azure
Google Cloud
AWS Security Hub
Azure Security Center
Cloud Custodian
Trivy
OpenSCAP
Tenable
Bringa
GitHub

Job description

ABOUT ROCKET LAB

Rocket Lab is the end-to-end space company building rockets, spacecraft, and critical subsystems that keep the world connected, protected, expand humanity's reach to the Moon, Mars, and beyond. We move fast, build real hardware for meaningful missions, and make the impossible routine. Come shape the future with us.

IT

Rocket Lab's IT team is responsible for how our global teams access information and run operations across our computer systems, networks, and devices. Our hardworking IT team is a group of flexible problem-solvers working in a fast-paced environment but who also thrive under the challenge of supporting all of our proprietary systems and people, from finance to launch operations.

PRINCIPAL CLOUD SECURITY ENGINEER

Based onsite at Rocket Lab's office in Long Beach, CA the Principal Cloud Security Engineer must demonstrate a firm grasp of cloud-first, automated, API-driven security and statistical risk concepts and communication. They will work on securing all facets of Rocket Lab's cloud presence: the wide array of vendor services, code pipelines deploying into prod and non-prod environments, and automation performing an assortment of business‑critical operations. They will provide analyses including quantifiable statistical information regarding IT and Cybersecurity risk to business partners with fiduciary responsibility. They will support the IT organization to develop a secure, reliable, and fiercely efficient platform to empower the Rocket Lab's objectives as a rapidly growing multinational space company.

WHAT YOU'LL GET TO DO:
  • Design, implement, and maintain security controls for hybrid cloud‑based environments, including infrastructure as a service (IaaS), platform as a service (PaaS), software as a service (SaaS), and function as a service (FaaS) solutions.
  • Design and develop custom automation in pursuit of cyber team objectives.
  • Provide security support for internal and external design reviews related to security.
  • Conduct security assessments and risk analyses to identify vulnerabilities and develop mitigation strategies for automated infrastructure such as public cloud, CI/CD pipelines, and agentic systems.
  • Work with Infrastructure Operations to Implement and manage identity and access management (IAM) solutions to control access to cloud resources and applications.
  • Develop documentation, plans, and proofs of concept for cybersecurity‑related platform improvements.
  • Configure and monitor cloud security tools and services.
  • Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC), DevOps, and MLOps processes.
  • Maintain systems to help the team stay up‑to‑date on emerging threats, vulnerabilities, and industry best practices related to DevSecOps/MLOps and recommend proactive measures to enhance security posture.
  • Provide guidance and support to internal teams on security‑related matters, including incident response, compliance, and security awareness training.
  • Participate in regular security audits, assessments, and compliance reviews to ensure adherence to regulatory requirements and industry standards.
YOU'LL BRING THESE QUALIFICATIONS
  • Education and Experience in IT and Cybersecurity
    • 12+ years of experience in scripting languages (e.g., Bash, PowerShell, Python) and configuration management/infrastructure as code tools (e.g., Puppet, Ansible, Terraform).
    • Bachelor's degree or equivalent years of work experience (16+ years of total work experience)
  • Cloud Security and Architecture Expertise
    • Proven experience in cloud security architecture, design, and implementation across major cloud platforms (AWS, Azure, Google Cloud).
    • Hands-on experience with cloud security tools and services (e.g., AWS Security Hub, Azure Security Center, Google Cloud Security Command Center).
  • Compliance, Vulnerability Management, and IT Governance
    • Experience working under US Government compliance regimes (e.g., CMMC, NIST, DISA STIG) and ITIL/Change Review systems.
    • Proficiency in vulnerability management systems (e.g., Tenable, Bringa) and CLI scanning tools (e.g., Trivy, OpenSCAP).
  • Version Control, Networking, and Secure Communication
    • Extensive experience with git-driven version control systems (e.g., GitHub, GitLab, Bitbucket).
    • Strong understanding of networking concepts, encryption techniques, and secure communication protocols.
  • Data and Analytics Expertise
    • Experience with databases (e.g., PostgreSQL, SQLite) and data formats (e.g., Parquet, Arrow).
    • Proficiency in analytics systems (e.g., PowerBI, Jupyter) and vendor‑agnostic assessment engines (e.g., Cloud Custodian, Panther).
  • U.S. citizenship is required, due to program requirements.
THESE QUALIFICATIONS WOULD BE NICE TO HAVE:
  • Advanced degree in computer science, information technology, cybersecurity, or equivalent career experience
  • Involvement with community cybersecurity organizations
  • Experience with the following:
    • AWS GovCloud / Azure GCC High
    • CI/CD pipeline security
    • Tier 2 cloud vendors
    • Hybrid cloud engineering
    • SAST and DAST testing
    • Secrets management / vaults / HSMs
    • Cloud incident response / forensics
    • Log aggregators like Graylog, ELK, or Splunk

This position may require prolonged periods of sitting, standing, walking, computer work, and occasional exposure to moderate levels of noise, dust, and fumes in production areas.

Join one of the world's fastest-growing space companies and own a piece of it. In addition to competitive base pay, you’ll receive company stock as part of your total compensation package, giving you a direct stake in our success. As we expand to new launch sites, groundbreaking missions, and global markets, your ownership has the opportunity to grow alongside the company.

Our comprehensive benefits package includes our industry‑leading Employee Stock Purchase Program (with a 15% discount on company stock), top‑tier medical plans (HMO, PPO, and a zero cost HDHP option with a significant HSA company contribution), dental and vision coverage, paid vacation and sick time, 11 paid holidays, flexible spending and dependent care accounts, paid parental leave, disability and life insurance, and a 401(k) retirement plan with company match.

Additional perks include subsidized EV charging, onsite fitness centers (where available), discounted gym memberships, complimentary snacks and beverages, 50% employee discount on our popular merch store, and a variety of other employee discounts.

Level and base salary will be determined on a case‑by‑case basis and may vary based on the following considerations: job‑related knowledge and skills, education, and experience.

Base Pay Range (CA Only): $152,300 — $165,000 USD

WHAT TO EXPECT

We're on a mission to unlock the potential of space to improve life on Earth, but that's not an easy task. It takes hard work, determination, relentless innovation, teamwork, grit, and an unwavering commitment to achieving what others often deem impossible. Our people out‑think, out‑work, and out‑pace. We pride ourselves on having each other's backs, checking our egos at the door, and rolling up our sleeves on all tasks big and small. We thrive under pressure, work to tight deadlines, and our focus is always on how we can deliver, rather than dwelling on the challenges that stand in the way.

Important information

FOR CANDIDATES SEEKING TO WORK IN US OFFICES ONLY:

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), Rocket Lab Employees must be a U.S. citizen, lawful U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum, or be eligible to obtain the required authorizations from the U.S. Department of State and/or the U.S. Department of Commerce, as applicable. Learn more about ITAR here.

Rocket Lab provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This policy applies to all terms and conditions of employment at Rocket Lab, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Applicants requiring a reasonable accommodation for the application/interview process for a job in the United States should contact Giulia Johnson at g.biow@rocketlabusa.com.This dedicated resource is intended solely to assist job seekers with disabilities whose disability prevents them from being able to apply/interview. Only messages left for this purpose will be considered. A response to your request may take up to two business days.

FOR CANDIDATES SEEKING TO WORK IN NEW ZEALAND OFFICES ONLY:

For security reasons, background checks will be undertaken prior to any employment offers being made to an applicant. These checks will include nationality checks as it is a requirement of this position that you be eligible to access equipment and data regulated by the United States' International Traffic in Arms Regulations.

Under these Regulations, you may be ineligible for this role if you hold citizenship of Australia, Japan, New Zealand, Switzerland, the European Union, or a country that is part of NATO, or if you hold ineligible dual citizenship or nationality. For more information on these Regulations, click here ITAR Regulations.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Cloud Security Engineer
Principal Cloud Security Engineer

Rocket Lab Corp. • Long Beach (CA)

On-site
USD 152,000 - 165,000
Company stock grant
EV charging
Onsite fitness centers
+1
Principal Cloud Security Engineer
Principal Cloud Security Engineer

Space Talent • Long Beach (CA)

On-site
USD 152,000 - 165,000
Employee Stock Purchase Program
Medical plans
Dental and Vision coverage
+2
Cybersecurity Engineer II - Secret Clearance
Cybersecurity Engineer II - Secret Clearance

Rocket Lab USA • Long Beach (CA)

On-site
USD 110,000 - 135,000
Stock options
Employee Stock Purchase Program
Medical plans
+1
Director, IT Infrastructure
Director, IT Infrastructure

Rocketlab • Long Beach (CA)

On-site
USD 175,000 - 233,000
Employee Stock Purchase Program
Medical plans
Paid vacation & holidays
+1
Supervisor, IT Support
Supervisor, IT Support

Rocket Lab USA • Long Beach (CA)

On-site
USD 77,000 - 96,000
Company stock
Stock purchase plan
Medical benefits
Principal Software Engineer - TS/SCI
Principal Software Engineer - TS/SCI

Rocket Lab Corp. • Long Beach (CA), Northern (KY)

Hybrid
USD 170,000 - 260,000
Stock purchase program
Medical plans
Dental & Vision
+2
Director, IT Infrastructure
Director, IT Infrastructure

Socket.dev • Long Beach (CA)

On-site
USD 175,000 - 233,000
Stock options
Health benefits
401(k) match
+1
Senior IT Network Engineer II
Senior IT Network Engineer II

Rocket Lab • Long Beach (CA)

On-site
USD 115,000 - 140,000
Top-tier medical HMO
Company-sponsored medical HSA plan
Dental and vision coverage
+6
Senior Cybersecurity Engineer II - Secret Clearance
Senior Cybersecurity Engineer II - Secret Clearance

Socket.dev • Long Beach (CA)

On-site
USD 150,000 - 227,000
Employee stock purchase program
Stock options
Medical, dental, vision plans
+2
Cybersecurity Engineer II - Secret Clearance
Cybersecurity Engineer II - Secret Clearance

Socket.dev • Long Beach (CA)

On-site
USD 110,000 - 135,000
Employee Stock Purchase Program
Medical plans (HMO/PPO)
Dental and vision coverage
+5