Security Engineer (Vulnerability Management)

Spacex

Northern (KY)

Hybrid

USD 120,000 - 180,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

SpaceX is seeking a Security Engineer in Vulnerability Management to protect systems and enable secure delivery across SpaceX programs. You will partner with software teams to identify, assess, and remediate vulnerabilities, while building internal security tooling and participating in Purple and Red Team activities.

The role emphasizes turning findings into actionable guidance, threat intelligence integration, and cross-team coordination to reduce risk and improve detection across the

Qualifications

  • Bachelor's degree or 2+ years security software development experience.
  • Experience with Python, Go, C#, C/C++, or Rust.
  • Experience designing and implementing security solutions for enterprise infrastructure.

Responsibilities

  • Develop tools, processes, and guidance to simplify security adoption without slowing delivery.
  • Conduct web app security testing using established frameworks and tools.
  • Triage Bugcrowd reports and coordinate remediation with internal teams.
  • Perform Purple Team exercises and contribute to Red Team operations.
  • Build and operate vulnerability notification and threat intel processes.

Skills

Python
Go
C/C++
Rust
Security solutions design
Networking fundamentals
Bug bounty platforms
Purple/Red Team
Threat hunting

Education

Bachelor's degree in computer science or STEM
2+ years security software development experience

Tools

Bugcrowd
HackerOne
Cloud security tooling

Job description

Security Engineer (Vulnerability Management)

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal ofenabling human life on Mars.

SECURITY ENGINEER (VULNERABILITY MANAGEMENT)

SpaceX is looking for a Security Engineer to join our Information Security department to help protect and drive the SpaceX mission.

Information drives our business and we must protect the confidentiality, integrity, and availability of systems and processes across the enterprise. As a highly visible and dynamic organization, we must also value and guard against damage to our reputation and brand. It is paramount that we defend against loss of control or confidence in our systems, to guarantee the highest probability of success.

As a member of the SpaceX Vulnerability Management team, the Security Engineer will act as a trusted partner to application software development teams. This role focuses on identifying, assessing, and remediating vulnerabilities and threats while developing and maintaining internal security tools. The role also includes hands‑on work triaging bug reports, conducting Purple and Red Team activities, and continuous threat hunting. Strong communication skills and the ability to turn technical findings into practical, actionable guidance are essential.

RESPONSIBILITIES:
  • Development of tools, processes, and guidance that make security easier to adopt without slowing delivery.
  • Conduct software code reviews to identify insecure patterns and help teams remediate issues.
  • Perform web application security testing using established frameworks and tools.
  • Triage and validate Bugcrowd reports, coordinate with researchers, and work directly with internal teams on remediation and disclosure.
  • Perform Purple Team exercises to test controls, improve detection, and close identified gaps.
  • Contribute to Red Team operations or simulations, including scoping, execution support, and post-exercise analysis.
  • Build and operate emerging vulnerability communication processes so teams receive timely, actionable alerts on new threats.
  • Conduct continuous threat assessment by folding threat intelligence, emerging vulnerabilities, and attack trends into scanning coverage, notifications, and prioritization.
  • Partner with other security sub‑teams (detection/response, compliance, application security, infrastructure) to keep efforts consistent and reduce duplication.
  • Escalate critical or time‑sensitive issues promptly while offering practical mitigation options.
  • Document findings, produce metrics, and provide regular risk summaries to leadership.
BASIC QUALIFICATIONS:
  • Bachelor's degree in computer science or another STEM discipline; OR 2+ years of professional experience in security software development in lieu of a degree.
  • Experience with the Python programming language, GO, C#, C/C++, or Rust.
  • Experience designing and implementing security solutions for operating systems, distributed systems, or other enterprise/large-scale infrastructure.
PREFERRED SKILLS AND EXPERIENCE:
  • Experience identifying, assessing, and remediating vulnerabilities (applications, infrastructure, or cloud).
  • Experience working directly with engineering teams to close findings.
  • Scripting/automation experience (Python, Bash, PowerShell, or similar) and the ability to develop internal tools.
  • Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls) and how they relate to vulnerability exposure.
  • Reverse engineering or vulnerability development experience.
  • Experience triaging or working reports from bug bounty platforms (Bugcrowd, HackerOne, or similar).
  • Hands‑on participation in Purple Team or Red Team exercises.
  • OT Security Experience.
  • Experience with continuous threat assessment, threat intelligence, or risk‑based vulnerability prioritization.
  • Experience developing internal security tools, dashboards, or automation pipelines (production‑quality code, integrations, etc.).
  • Experience with web application testing frameworks and tools.
  • Experience performing software code reviews for security issues.
  • Experience improving developer experience around security tooling and processes.
  • Knowledge of network segmentation principles and implementation.
  • Experience with asset discovery or inventory processes.
  • Experience building or operating emerging vulnerability notification/alerting workflows.
  • Familiarity with AI/LLMs and MCPs.
  • Familiarity with cloud environments (AWS, Azure, GCP) and their native security/vulnerability features.
  • Experience with configuration management, patching, or infrastructure‑as‑code.
  • Knowledge of threat modeling, risk scoring (e.g., CVSS), and prioritization frameworks.
  • Familiarity with enterprise security controls and best practices for Windows, Linux, and macOS.
  • Strong communication skills with the ability to translate technical findings into business impact and concrete remediation steps.
  • Relevant certifications (e.g., OSCP, GSEC, or equivalent) or demonstrated equivalent experience.
  • Demonstrable problem‑solving skills and ability to quickly determine root causes of issues.
ADDITIONAL REQUIREMENTS:
  • Must be willing to work extended hours and/or weekends as needed.
  • This role requires you to be onsite. Hybrid or remote work will not be considered.
  • To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here .

SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

Applicants wishing to view a copy of SpaceX’s Aff... or ... should reach out to EEOCompliance@spacex.com.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in SpaceX’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A \"disabled veteran\" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service‑connected disability.

A \"recently separated veteran\" means any veteran during the three‑year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An \"active duty wartime or campaign badge veteran\" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An \"Armed forces service medal veteran\" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Security Analyst
Sr. Security Analyst

SPACE EXPLORATION TECHNOLOGIES CORP • Redmond (WA), Northern (KY)

On-site
USD 130,000 - 195,000
Stock options
Long-term incentives
Comprehensive medical, vision, and 7
+4
Security Engineer (Vulnerability Management)
Security Engineer (Vulnerability Management)

SpaceX • Town of Texas (WI)

On-site
USD 140,000 - 180,000
Security Engineer (Vulnerability Management)
Security Engineer (Vulnerability Management)

SpaceX • Starbase (TX)

On-site
USD 140,000 - 190,000
Security Engineer (Vulnerability Management)
Security Engineer (Vulnerability Management)

Starlink • Town of Texas (WI)

On-site
USD 120,000 - 180,000
Security Engineer (Vulnerability Management)
Security Engineer (Vulnerability Management)

SpaceX • Brownsville (TX)

On-site
USD 130,000 - 185,000
Sr. IT Systems Administrator, Mission Systems
Sr. IT Systems Administrator, Mission Systems

Spacex • California (MO), Northern (KY)

Hybrid
USD 95,000 - 150,000
Sr. Industrial Security Analyst (MDSO)
Sr. Industrial Security Analyst (MDSO)

Spacex • Northern (KY)

Hybrid
USD 117,000 - 195,000
Stock options
Annual bonuses
Comprehensive benefits
AI Security Software Engineer (Starshield)
AI Security Software Engineer (Starshield)

Spacex • Hawthorne (CA)

On-site
USD 130,000 - 195,000
Stock options
Medical, dental, vision coverage
401(k) retirement plan
+1
Software Engineer, Manufacturing Infrastructure
Software Engineer, Manufacturing Infrastructure

Spacex • Northern (KY)

Hybrid
USD 120,000 - 180,000
Full Stack Software Engineer, Manufacturing Systems
Full Stack Software Engineer, Manufacturing Systems

Spacex • Northern (KY)

Hybrid
USD 130,000 - 180,000