Principal Security Design Engineer

Iridium

California (MO)

Hybrid

USD 170,000 - 250,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work policy
Medical insurance
Dental insurance
Vision insurance
401(k) retirement plan
Paid time off
Paid holidays
Parental leave
Stock and bonus

Job summary

Iridium is seeking a Principal Security Engineer to design secure architecture from inception, conduct adversarial assessments, and guide threat modeling for a high-impact pre-launch service. You will influence design decisions, partner with engineering, and lead security initiatives in a hybrid work setting.

You will build threat models, perform red‑team assessments, and ensure secure identity integrations across SAML, OIDC, OAuth 2.0, WebAuthn, and CTAP, while mentoring teammates and shaping

Qualifications

  • 10+ years of experience in network and information security, with depth in offensive or adversarial security; red team experience preferred.
  • Strong applied expertise in AWS security fundamentals (IAM, VPC, misconfigurations).
  • Hands-on understanding of identity protocols (SAML, OIDC, OAuth 2.0, WebAuthn, CTAP) and how flows can be attacked or strengthened.
  • Ability to communicate security risk to engineers and non-technical stakeholders, including customers and partners.
  • Experience as an individual contributor in a high ambiguity, high trust, small team environment.
  • Excellent communication, able to convey complex topics clearly and adapt to different audiences.
  • Ability to build relationships with senior leadership and provide constructive feedback.
  • Analytical mindset to generate effective solutions and drive them to completion.
  • Creativity and resourcefulness to make reliable decisions on new assignments.
  • Thrives in a dynamic environment with shifting priorities.
  • Proactive in sharing knowledge with others.

Responsibilities

  • Analyze AWS-based cloud infrastructure, APIs, and services to identify attack paths and translate findings into defensive priorities.
  • Advise on secure design decisions across cloud infrastructure and application logic early in development.
  • Develop and maintain threat models and foster a threat-modeling culture in a small pre-launch team.
  • Conduct or commission red-team style assessments across network, app, cloud, identity flows, and supply-chain vectors.
  • Communicate security findings with business impact, guiding pragmatic prioritization and decisions.
  • Evaluate integration of Iridium's service with partner identity systems (SAML, OIDC, OAuth 2.0, WebAuthn, CTAP).
  • Identify weaknesses in these integrations and strengthen step-up authentication and assurance contexts.
  • Serve as tier-2 security SME in partner or customer conversations; collaborate with engineering, product, and partner-facing teams.
  • Help establish early security practices, lightweight processes, and standards for a pre-launch environment.
  • Provide mentorship to engineers and future security team members.

Skills

Security engineering
AWS security
Red team
Threat modeling
Identity protocols
Clear communication

Job description

Company Overview

Iridium is an award-winning satellite communications company operating the world's only truly global voice and data network, delivering reliable connectivity anywhere on Earth. For more than 20 years, Iridium has powered mission-critical communications for governments, businesses, aviation, maritime, and the rapidly expanding Internet of Things.


Now part of Iridium, Aireon is the world’s only space-based air traffic surveillance system, providing real‑time visibility of aircraft over oceans, the poles, and remote regions. Together, Iridium and Aireon are helping build a safer, more connected, and more efficient future for global aviation.


Join our team and help shape how the world stays connected. We foster a collaborative, inclusive culture where employees are empowered to innovate, grow professionally, and make a meaningful impact.



What We’re Looking For:

Iridium is building security ‑ critical infrastructure for a new service currently in low ‑ visibility proof ‑ of ‑ concept engagements with prospective partners. We are seeking a Principal Security Engineer to join at the earliest stage and ensure security is designed correctly from the start.


This role provides deep adversarial and architectural expertise, identifying how this service could be attacked and guiding how we defend it. You will work as a principal ‑ level technical peer to engineering, influence early design decisions, drive red ‑ team style assessments, and serve as a tier ‑ 2 subject ‑ matter expert in select partner and customer conversations. As one of the first security specialists on the team, you will help establish early security practices and a threat ‑ modeling culture that will scale as the team grows.



What You’ll Do:


Security Architecture & Threat Modeling


  • Analyze our AWS‑based cloud infrastructure, APIs, and supporting services to identify realistic attack paths and translate findings into clear defensive priorities.

  • Advise engineering leadership on secure design decisions across cloud infrastructure, application logic, and device/key ‑ management touchpoints early in the development lifecycle.

  • Develop and maintain service ‑ specific threat models and guide an emerging threat ‑ modeling culture for a small, fast ‑ moving pre ‑ launch engineering team.



Adversarial Testing & Red Team Assessments


  • Conduct or commission red ‑ team style assessments spanning network, application, cloud configuration, identity flows, and adjacent supply ‑ chain vectors.

  • Communicate security findings in terms of business impact, driving pragmatic prioritization and informed decision ‑.



Identity & Access Flow Security


  • Evaluate how Iridium’s service integrates into partner identity and access systems (SAML, OIDC, OAuth 2.0, WebAuthn, CTAP).

  • Identify how these integrations could be attacked, misused, or strengthened, particularly in step ‑ up authentication and assurance contexts.



Cross ‑ Functional & External Influence


  • Serve as a tier ‑ 2 security SME in select partner or prospective ‑ customer conversations where deep technical expertise is required beyond sales engineering capabilities.

  • Collaborate closely with engineering, product, and partner ‑ facing teams to ensure security decisions are incorporated throughout the service architecture.

  • Foundational Security Practices & Mentorship

  • Help establish early security practices, lightweight processes, and technical standards appropriate for a pre ‑ launch product environment.

  • Provide mentorship and guidance to engineers and future security team members as the capability grows.



What You’ll Need to Succeed:


  • 10+ years of experience in network and information security, with demonstrated depth in offensive or adversarial security; red team experience strongly preferred.

  • Strong applied expertise in AWS security fundamentals (IAM, VPC architecture, common cloud misconfigurations and exploitation patterns).

  • Solid hands on understanding of modern identity and access protocols (SAML, OIDC, OAuth 2.0, WebAuthn, CTAP), including how these flows can be attacked or strengthened.

  • Demonstrated ability to communicate security risk clearly to both engineers and non technical stakeholders, including customers and partners.

  • Experience operating as an individual contributor in a high ambiguity, high trust, small team environment.

  • Excellent communication skills, with the ability to convey products, deliverables, analyses, and/or issues clearly and confidently, and recognize and adapt to different communication techniques

  • Can easily build meaningful relationships with others, including senior leadership outside of your own department, and comfortable providing constructive feedback to your team members and management

  • Be able to analyze a situation or problem, generate effective solutions, and see those solutions through to completion

  • Must possess the creativity and resourcefulness needed to make reliable decisions and determine methods on new assignments

  • Can thrive in a dynamic environment by handling multiple tasks and managing shifting priorities

  • Be proactive in sharing knowledge you’ve learned with others



Things That Would be Great if You Brought to the Table:


  • Experience with hardware root ‑ of ‑ trust, secure elements, or embedded device attestation concepts.

  • Experience in regulated or compliance ‑ sensitive industries (financial services, gaming/gambling, critical infrastructure).

  • Industry certifications (OSCP, CISSP, or similar) are welcome but not a substitute for demonstrated hands ‑ on depth.

  • Active security clearance not required; ability to obtain and maintain one is a plus.



We’ll also need you to:


  • Be able to travel up to 20%

  • This position directly performs under, supports, or is exposed to a U.S. government contract. To comply with the requirements of that U.S. government contract, applicants for this position must be U.S. citizen



Work Environment:

This position primarily works in an office setting and is largely sedentary with the majority of the position working with a computer. The role typically requires the use of basic office equipment such as a phone, video, computer, keyboard, mouse, and printer.


We believe in‑person connection drives innovation, strengthens mentorship, and builds culture, while flexibility enables employees to do their best work. Under Iridium’s Hybrid Work Policy, employees are expected to work at least four days per week (approximately 80%) in an Iridium office to support collaboration, relationship‑building, and professional growth.



Additional Information

This job description outlines the general nature and level of work for this role and is not a comprehensive list of duties, responsibilities, or qualifications. Employees may be assigned additional responsibilities as needed.



Base Pay Range:

Actual compensation will be determined based on a variety of factors and this range represents an estimate of compensation at the time of posting. Base salary is only one part of our compensation package for this role. You may also be eligible for company stock and annual bonus. Employee benefits also include medical, dental, and vision insurance coverage; 401(k) retirement plan options; paid time off and paid holidays; paid parental leave; and other discounts and perks.



Iridium is an Equal Opportunity Employer, including individuals with disabilities and protected veterans.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Design Engineer
Principal Security Design Engineer

Iridium Communications Inc • McLean (VA)

On-site
USD 180,000 - 240,000
Stock options
Annual bonus
Medical insurance
+6
Principal Security Design Engineer
Principal Security Design Engineer

Iridium Satellite LLC • Redwood City (CA)

Hybrid
USD 180,000 - 240,000
Medical Insurance
Dental Insurance
Vision Insurance
+4
Principal Security Design Engineer
Principal Security Design Engineer

Iridium Satellite LLC • McLean (VA)

Hybrid
USD 180,000 - 240,000
Health benefits
401(k) plan
Paid time off
+2
Senior Security Engineer (SWOOP)
Senior Security Engineer (SWOOP)

Iridium Communications Inc • Tempe (AZ)

On-site
USD 115,000 - 150,000
Hybrid work schedule
Stock option program
Medical, dental, and vision insurance
+1
Senior Product Manager (Cyber, PAM and IAM)
Senior Product Manager (Cyber, PAM and IAM)

Iridium • McLean (VA)

On-site
USD 147,000 - 193,000
Company stock
Annual bonus
Medical insurance
+1
Senior Cloud DevSecOps Engineer
Senior Cloud DevSecOps Engineer

Iridium Satellite LLC • Tempe (AZ)

On-site
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+5
Senior Product Manager (Cyber, PAM and IAM)
Senior Product Manager (Cyber, PAM and IAM)

Iridium Satellite LLC • McLean (VA)

On-site
USD 147,000 - 193,000
Company stock
Annual bonus
Medical, dental, and vision insurance
+1
Principal Software Engineer
Principal Software Engineer

Iridium Satellite, LLC • Chandler (AZ)

On-site
USD 150,000 - 200,000
Stock options
Annual bonus
Medical, dental, and vision insurance
+3
Senior Systems Engineer, On-Orbit Test Coordinator
Senior Systems Engineer, On-Orbit Test Coordinator

Iridium • Grand Forks Air Force Base (ND)

Hybrid
USD 115,000 - 155,000
Medical, dental, and vision insurance
401(k) retirement plan
Stock options and annual bonus
Director, Business Development (Cyber Security & PAM Ecosystem)
Director, Business Development (Cyber Security & PAM Ecosystem)

Iridium • California (MO)

Hybrid
USD 235,000 - 306,000
Stock options
Annual bonus
Medical insurance
+4