Sr. Network Security Engineer

SpaceX

Hawthorne (CA)

On-site

USD 140,250 - 189,750

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SpaceX is seeking a Sr. Network Security Engineer to lead enterprise remote access VPN design, deployment, and ongoing security.

You will own end-to-end remote access infrastructure, implement zero-trust strategies, and automate deployments across multiple platforms including Windows, macOS, Linux, iOS, and Android. Strong Linux, Python, and Go skills are required, with a focus on reliability and scalable security.

Qualifications

  • Bachelor's degree in a STEM field or equivalent experience.
  • 5+ years of network security experience with VPNs.

Responsibilities

  • Provide SME guidance on network security, firewalls, zero-trust architectures, and VPN technologies.
  • Architect, design, deploy, and secure enterprise remote access VPN solutions end-to-end.
  • Own the full lifecycle of remote access infrastructure from design to ongoing management.
  • Configure and support VPN clients across Windows, macOS, Linux, iOS, and Android.
  • Manage Linux-based infrastructure and security systems with end-to-end ownership.
  • Develop automation and CI/CD workflows to streamline deployment and monitoring.
  • Implement and support zero-trust remote access architectures; manage firewall policies.
  • Collaborate cross-functionally to gather requirements and communicate best practices.
  • Monitor VPN performance and security posture; drive resolutions and changes.

Skills

Remote access VPN
Zero-trust architectures
Python scripting
Go programming
Linux administration
CI/CD automation

Education

Bachelor's degree in STEM field

Tools

Tailscale
WireGuard
IPsec
SSL-based VPN

Job description

SR. NETWORK SECURITY ENGINEER

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.

RESPONSIBILITIES
  • Provide subject matter expertise on network security, firewalls, zero-trust architectures, and industry best practices, with primary focus on modern remote access VPN technologies.
  • Architect, design, deploy, and secure enterprise remote access VPN solutions end-to-end (including supporting components such as routers, exit nodes, and connectors), with strong emphasis on Tailscale, WireGuard, IPsec, and SSL-based implementations.
  • Own the full lifecycle of remote access infrastructure from initial design and ground-up implementation through ongoing management, policy definition, client distribution, and performance optimization.
  • Configure, deploy, and support VPN clients across multiple platforms (Windows, macOS, Linux, iOS, Android) while performing advanced troubleshooting of complex connectivity and performance issues.
  • Manage Linux-based infrastructure and network security systems with end-to-end ownership of configuration, custom tooling, and operational reliability.
  • Develop automation and CI/CD workflows (Python or similar) to streamline deployment, policy enforcement, monitoring, and maintenance of remote access and security systems.
  • Implement and support zero-trust remote access architectures; manage firewall policies and network security appliances with tight integration of VPN solutions.
  • Serve as an escalation point for complex network security and remote connectivity challenges; collaborate cross-functionally with engineering and operations teams to gather requirements, design secure solutions, and communicate best practices.
  • Monitor VPN performance, logs, and overall security posture; proactively identify issues, drive resolutions, and formalize processes and change management for remote access infrastructure.
  • Apply system patches, perform periodic maintenance, and continuously improve the reliability and security of the remote access environment.
BASIC QUALIFICATIONS
  • Bachelor's degree in a STEM field and 5+ years of network security experience; OR 8+ years of network security experience in lieu of a degree.
  • 3+ years of experience securing networks, IT infrastructure, applications, endpoints, and/or APIs.
PREFERRED SKILLS AND EXPERIENCE
  • Proven experience leading the design, deployment, and operation of enterprise remote access VPN solutions (Tailscale, WireGuard, or comparable SSL/IPsec/WireGuard-based platforms) in large-scale, multi-site or multi-region environments with high reliability requirements.
  • Deep hands-on expertise with modern remote access platforms, including client management, access policies, split-tunneling, performance tuning, and complex troubleshooting across diverse operating systems.
  • Strong systems engineering foundation: deep networking knowledge, experience managing Linux infrastructure, and the ability to design and implement solutions from the ground up rather than solely administer existing systems.
  • Demonstrated automation and software skills in Python for building custom tooling, services, and CI/CD workflows, with strong system design thinking to evaluate second- and third-order effects and build resilient systems.
  • Comfortable reading and reviewing Go code, particularly in the context of understanding upstream changes in projects.
  • Experience with dynamic routing (eBGP, iBGP, OSPF, SD-WAN), network segmentation, logging/alerting with SIEMs, and zero-trust architectures.
  • Ability to diagnose low-level connectivity and performance issues and to work effectively with stakeholders and end users.
  • Self-starter with excellent time-management, communication (written and verbal), and collaboration skills; mid-career professional who has successfully owned similar infrastructure or remote-access initiatives.
ADDITIONAL REQUIREMENTS
  • This role requires you to be onsite. Hybrid or remote work will not be considered.
  • Willingness to work extended hours and weekends as needed.
COMPENSATION AND BENEFITS

Pay Range: Level 3: $165,000.0

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Network Security Engineer
Sr. Network Security Engineer

SpaceX • Town of Texas (WI)

On-site
USD 140,000 - 210,000
Sr. Network Security Engineer
Sr. Network Security Engineer

InvestedintheMission • Town of Texas (WI)

On-site
USD 140,000 - 200,000
Sr. Network Security Engineer
Sr. Network Security Engineer

InvestedintheMission • Bastrop (TX)

On-site
USD 150,000 - 190,000
Sr. Network Security Engineer
Sr. Network Security Engineer

SpaceX • Brownsville (TX)

On-site
USD 140,000 - 190,000
Sr. Network Security Engineer
Sr. Network Security Engineer

SPACE EXPLORATION TECHNOLOGIES CORP • Hawthorne (CA)

On-site
USD 165,000 - 235,000
Stock options
Comprehensive medical/dental/vision
401(k) retirement plan
Sr. Network Security Engineer
Sr. Network Security Engineer

SpaceX • Bastrop (TX)

On-site
USD 140,000 - 170,000
Sr. Network Security Engineer
Sr. Network Security Engineer

SpaceX • Union Hill-Novelty Hill (WA)

On-site
USD 165,000 - 235,000
Stock options
Long-term incentives
Medical coverage
+7
Sr. Network Security Engineer
Sr. Network Security Engineer

SPACE EXPLORATION TECHNOLOGIES CORP • United States

On-site
USD 140,000 - 210,000
Sr. Network Security Engineer
Sr. Network Security Engineer

InvestedintheMission • Redmond (WA)

On-site
USD 165,000 - 235,000
Stock options
Comprehensive medical, vision, dental
Sr. Network Security Engineer
Sr. Network Security Engineer

SPACE EXPLORATION TECHNOLOGIES CORP • Bastrop (TX)

On-site
USD 140,000 - 210,000