Security and Network Engineer

California Institute of Technology

Pasadena (CA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work up to 1 day per week

Job summary

IPAC at Caltech seeks a Security and Network Engineer to support cybersecurity, compliance architecture, and high-performance network infrastructure powering NASA, NSF, and funded observatories. You will work with a team to shape IPAC's cybersecurity posture while integrating with data center and network engineers.

The role focuses on implementing NIST/NASA frameworks, enterprise firewalls (Palo Alto), and secure perimeters, with collaboration across Arista and Cisco environments at Caltech's

Qualifications

  • Bachelor's degree in information technology or related field with 5+ years of network administration and cybersecurity experience
  • Hands-on design and administration with Arista or Cisco hardware
  • Experience managing enterprise firewalls and network security perimeters
  • Experience with network penetration testing and security auditing
  • Familiarity with federal cybersecurity frameworks (NIST RMF, SP 800-53)
  • US PERSON as defined by ITAR regulations

Responsibilities

  • Coordinate NASA ATO compliance and reporting.
  • Design, maintain SSPs and POA&M tracking for missions and IPAC infrastructure.
  • Translate NIST SP 800-53 and NASA directives into enforceable network architectures.
  • Design, deploy, audit, and maintain firewall rules and perimeters across enterprise edge.
  • Collaborate with Data Center staff to apply security to IPAC infrastructure.
  • Monitor threats with centralized logging and security alerting.
  • Perform other duties as assigned.

Skills

Network administration
Cybersecurity
NIST RMF
Arista/Cisco
Firewalls
Threat monitoring

Education

Bachelor's degree in Information Technology or related field

Tools

Palo Alto
Rapid7
CrowdStrike
Linux
SIEM

Job description

Job Category:

Fulltime Regular

Exempt Overtime Eligible:

Overtime Eligible

Benefits Eligible:

Benefit Based

Caltech is a world-renowned science and engineering institute that marshals some of the world's brightest minds and most innovative tools to address fundamental scientific questions. We thrive on finding and cultivating talented people who are passionate about what they do. Join us and be a part of the diverse Caltech community.

Job Summary

IPAC at Caltech is seeking a Security and Network Engineer to support the cybersecurity, compliance architecture, and high-performance network infrastructure powering world-class NASA, NSF, and privately funded ground and spaceborne observatories. As a member of the IPAC Support Group (ISG) Data Center Engineering team, you will focus heavily on shaping IPAC's overall cybersecurity posture while working alongside other network, systems, and database engineers to build and defend the vital pipelines that connect the global astronomical community to invaluable scientific data.

IPAC, situated within the Division of Physics, Mathematics, and Astronomy at Caltech (www.caltech.edu), provides science operations, pipeline processing, user support, and data services for high-profile missions including the Nancy Grace Roman Space Telescope, SPHEREx, Euclid, the Near-Earth Object Surveyor, and the Zwicky Transient Facility (ZTF). Our diverse portfolio of research archives includes multi-petabyte datasets like the NASA/IPAC Infrared Science Archive (IRSA), alongside highly curated reference repositories like the NASA Extragalactic Database (NED) and the NASA Exoplanet Archive, which are key research references for modern astrophysics and exoplanet science.

This role prioritizes robust cybersecurity governance and technical systems defense. While cybersecurity and federal compliance are the primary focuses of this position, your core network engineering expertise will directly inform your security architecture. As part of a close-knit team of about ten engineers, you will help shape IPAC's cybersecurity architecture, coordinate federal compliance activities, and provide network-security expertise across the organization.

Essential Job Duties and Responsibilities

As an IPAC Security and Network Engineer, your role will be to:

  • Manage NASA ATO Compliance & Reporting: Coordinate IPAC's compliance, documentation, and reporting requirements necessary to achieve and maintain our NASA Authority to Operate (ATO) status. Lead the generation, aggregation, and continuous monitoring of evidence required to prove compliance with federal mandates.
  • Develop Security Plans & Frameworks: Design, maintain, and audit comprehensive System Security Plans (SSPs) and related Plan of Action and Milestones (POA&M) tracking for individual space missions, research projects, and IPAC-wide infrastructure.
  • Implement NIST & NASA Frameworks: Translate federal compliance guidelines-specifically NIST SP 800-53 security controls, FIPS requirements, and NASA-specific IT security directives-into enforceable network architectures, system configurations, and operational workflows.
  • Manage Enterprise Security Perimeters: Design, deploy, audit, and maintain firewall rules, intrusion prevention systems, and secure zone configurations across our enterprise edge, utilizing Palo Alto firewalls and related security platforms.
  • Provide Network Consultation & Backup Support: Collaborate with Data Center staff to apply security and networking expertise to IPAC infrastructure. Leverage your network engineering background to ensure compliance frameworks align practically with our network, systems, and software architectures. Provide cross-functional backup support to peer network engineers managing core Arista and Cisco routing and switching environments.
  • Monitor & Mitigate Threats: Implement and manage network-level monitoring, centralized logging, and security alerting tools to proactively analyze vulnerabilities, detect anomalies, and defend our data center environments.
  • Perform other duties as assigned.
Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Computer Engineering, or a related field, plus 5+ years of relevant experience in network administration and cybersecurity (or an equivalent combination of education and experience).
  • Solid hands-on network design and administration experience, particularly with Arista, Cisco, or similar enterprise networking hardware.
  • Proven experience managing enterprise firewalls and network security perimeters.
  • Experience with network penetration testing and security auditing. Experience with packet capture and data analysis.
  • Demonstrated expertise in cybersecurity principles, including network access control, threat mitigation, and secure architecture design.
  • Working familiarity with federal cybersecurity compliance frameworks (e.g., NIST SP 800-53, RMF).
  • Qualify as a US PERSON as defined by ITAR regulations: A US person is a citizen of the United States, a lawful permanent resident alien of the US ('Green Card' holder), or an individual granted refugee or asylee status under US law.
Preferred Qualifications

Beyond these basic qualifications, there are skills and experiences which will give you a head start here. We are a specialized environment looking for a well-rounded engineer who thrives in a shared-responsibility model. If you have experience in a few of these areas, you will hit the ground running, but even if these don't yet describe you and your experience, we would still like to hear from you:

  • Security Policy Development and Implementation: Experience drafting, updating, and enforcing organizational IT security policies, acceptable use guidelines, and incident response procedures in an academic or research setting.
  • Compliance Frameworks & ATO Lifecycle: Practical experience steering systems through the federal cybersecurity Risk Management Framework (RMF) to secure or maintain an ATO. Direct familiarity with auditing NIST SP 800-53 controls, FIPS standards, or related NASA cybersecurity guidelines.
  • Security & Vulnerability Tooling: Hands-on experience with the deployment, configuration, and operational oversight of enterprise security tools, such as Rapid7 for vulnerability scanning and reporting, and CrowdStrike for endpoint protection.
  • Systems & Scripting: Strong Linux systems administration skills (Red Hat or Debian) and experience leveraging scripting/programming languages (e.g., Python, Bash) for security analysis, log parsing, or task automation.
  • Cloud Security: Experience implementing and monitoring security controls within public cloud environments (e.g., AWS).
  • Mission Alignment: A genuine interest in science, astronomy, or space exploration. Understanding mission objectives helps us build better systems for the scientists and staff we support.
  • Teamwork & Collaboration: A strong collaborative mindset, a willingness to share operational duties, and the ability to communicate security and compliance constraints clearly and pragmatically within an active engineering group.
Required Documents
  • Full Resume.
  • Cover Letter (briefly highlighting key qualifications and fit for this role).
  • Names and Contact information of 3 professional references.
Application Details
  • This is an on-site position at the Caltech campus in Pasadena, California. Remote work is normally allowed up to one day per week.
  • Applicants for this position must be a United States (US) person as defined by ITAR regulations - A US person is a citizen of the United States, a lawful permanent resident alien of the US ('Green Card' holder), or individuals granted refugee and asylee status under US law.
  • Applications are due by August 31, 2026
Life at IPAC

People choose to work at IPAC for many reasons, and our casual, employee-centric culture often leads to fulfilling, long-term careers and positive relationships. Whether in science, engineering, or administration, IPAC staff share a unique sense of pride in knowing their individual talents support human discovery.

Unlike traditional corporate tech, IPAC emphasizes sustainable workloads and a healthy work-life balance: after-hours work is rare, shared across the operations team, and typically limited to exceptional situations. We actively support ongoing professional development, including training, conferences, and skill development aligned with your career goals.

  • Caltech's benefits program offers a highly competitive benefits package, an exceptional 403(b) defined contribution plan, and access to campus facilities including the athletic center, libraries, on-site daycare, and Athenaeum club membership.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security and Network Engineer
Security and Network Engineer

Caltech • Pasadena (CA)

Hybrid
Security and Network Engineer
Security and Network Engineer

University of California • Pasadena (CA)

Hybrid
USD 65,780 - 85,755
Security and Network Engineer
Security and Network Engineer

California-Institute-of-Technology • Pasadena (CA)

Hybrid
Network Engineer
Network Engineer

California Institute of Technology • Pasadena (CA)

On-site
USD 136,823,232 - 178,371,648
Health, dental, vision insurance
Competitive compensation
Retirement savings plans
+2
Network Engineer
Network Engineer

Caltech • Pasadena (CA)

Hybrid
Security & Network Engineer — Federal Compliance & Infra
Security & Network Engineer — Federal Compliance & Infra

California Institute of Technology • Pasadena (CA)

On-site
USD 120,000 - 180,000
Remote work up to 1 day per week
Security & Network Architect for Space Data Pipelines
Security & Network Architect for Space Data Pipelines

Caltech • Pasadena (CA)

Hybrid
Application Developer
Application Developer

California Institute of Technology • Pasadena (CA)

On-site
Health, dental, and vision insurance
Retirement savings plans
Generous paid time off
+2
Security & Network Engineer, Space Systems
Security & Network Engineer, Space Systems

California-Institute-of-Technology • Pasadena (CA)

Hybrid
Research Technician
Research Technician

California-Institute-of-Technology • Pasadena (CA)

On-site
USD 41,000 - 54,000
Benefits package
403(b) plan
On-site daycare
+1