Mission Security Engineer

Apex Technology, Inc.Los Angeles, CA
$162,000 - $198,000Onsite

About The Position

In this position, you will own the authorization posture of two systems: a space vehicle with a multi-decade operational life, and a classified cloud mission operations environment that changes daily and cannot miss a pass, hosting command and control, telemetry, mission planning, flight dynamics, and payload processing. You will contribute to cyber engineering and produce RMF authorization documentation, build and sustain authorization packages, own the plan of action and milestones day to day, and run continuous monitoring. This is mission systems work throughout, not traditional enterprise IT security. We are open to candidates from ISSE, SSE, ISSM, or ISSO backgrounds, and are hiring across levels: from new and recent graduates through senior engineering, officer, and manager experience.

Requirements

  • U.S. Citizenship (must possess the ability to access export-controlled data)
  • Active Top Secret clearance with SCI access and SAP eligibility strongly preferred
  • Experience with technical tooling: reading pipeline output, querying an API, interpreting scanner and configuration state
  • Bachelor, master's, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field
  • Clear experience with hands-on building via coursework, internships, research code, personal projects, CTFs, a co-op, or an early role and/or some exposure to RMF, security compliance, cloud, or software engineering
  • Willingness to learn RMF from the ground up, with a demonstrated ability to pick up a complicated technical domain quickly and hold a lot of detail without losing the thread
  • Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows
  • Strong experience in embedded/space systems or cloud infrastructure
  • Multiple systems taken to authorization in national security or DoD environments, with fluency in RMF as practiced: categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers
  • Ability to speak concretely about categorization, tailoring, assessment, and authorization, and to design, document, or test a report and determine whether it constitutes evidence that a control is satisfied
  • Direct experience with at least one accredited cloud environment and one non-traditional system such as embedded, weapons, platform IT, industrial, or space
  • Skilled in Python, Go, or equivalent, in CI/CD, infrastructure-as-code, and Git-based workflows

Nice To Haves

  • OSCAL, eMASS APIs, Xacta, controls-as-code, or continuous-controls-monitoring implementation experience
  • Experience with continuous authorization, ongoing authorization, or cATO
  • Experience building with AI-assisted development
  • Understanding of Mission Operations including satellite command and control, mission planning, flight dynamics, telemetry processing, or multi-mission ground segments
  • Embedded or safety-critical background in space, automotive, or industrial control
  • SPARTA, NIST IR 8270 or IR 8401, CCSDS security standards, Space Platform Overlay, NASA/Space Force system protection standards, or space-system threat modeling
  • Classified cloud accreditation at IL5/IL6 or IC equivalents, or accreditation under JSIG or ICD 703
  • Qualified, or able to qualify, under DoDM 8140.03 for a systems security engineering, security architecture, or Information Systems Security Manager work role. CISSP, CISSP-ISSEP, CISM, and SecurityX map well.

Responsibilities

  • Build and sustain authorization packages for both boundaries: system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, assessment coordination, and the residual risk picture carried to the AO.
  • Get assessors engaged early on our evidence-generation approach so generated artifacts are trusted before a package depends on them.
  • Own the POA&M.
  • Maintain the authorization system of record (eMASS or equivalent).
  • Own the authorization boundary determination for the flight segment and the rationale that survives assessor scrutiny.
  • Categorize under CNSSI 1253 and defend overlay selection, treating the Space Platform Overlay as the starting place it is rather than a finished answer — pushing back where our onboard security capability exceeds what the published tailoring assumes.
  • Tailor the control baseline with per-control rationale, using Aerospace's Space Segment Cybersecurity Profile (TOR-2023-02161 Rev A) and SPARTA-linked tailoring, including arguing controls back in where our onboard capability exceeds what those baselines assumed.
  • Define the type-authorization for the bus and design how each vehicle off the line generates its own conformance evidence so fleet growth does not mean linear growth in assessment labor.
  • Derive verifiable security requirements from threat using SPARTA TTPs as the traceability key, owned by the software and mission integration engineers who will build and test against them.
  • Translate verification and production artifacts into assessment evidence and tell engineering early when what they produce will not satisfy an assessor.
  • Own the continuous monitoring story for a fielded fleet: security audit downlinked across contact windows, configuration drift across vehicles, and on-orbit software update as a recurring authorization event.
  • Define and document the authorization boundary for mission systems in classified cloud (AWS, Azure classified regions, or equivalent), including impact-level scoping and the seam with ground stations and the RF edge.
  • Own the control and evidence story for operator command authority: identity, role separation, least privilege, two-person integrity, non-repudiation, and complete audit of every command that reaches the vehicle.
  • Build and defend the control inheritance model and prove the customer-responsible set with live evidence rather than assertion, validating what the cloud service provider and the platform satisfy versus what remains customer responsibility for the mission-unique applications.
  • Implement controls as code, so infrastructure-as-code, policy-as-code, and pipeline configuration serve as the implementation and the evidence at once.
  • Make change control and continuous monitoring work at operations tempo, never putting a contact window at risk, positioned for the DoD transition toward the Cybersecurity Risk Management Construct (CSRMC) and continuous authorization.
  • Manage security incident reporting and coordination for the boundary.
  • Define what evidence you need and in what form.
  • Design the OSCAL-based evidence data model and the mapping layer that resolves a property assertion to control identifiers across 800-53, CNSSI 1253 baselines, overlays, and program-unique control sets.
  • Build the pipeline that renders SSP sections, assessment evidence, POA&M items, and continuous monitoring reports deterministically from pinned evidence snapshots.
  • Integrate with the authorization system of record (eMASS or equivalent) programmatically, so generated artifacts land where assessors actually look.
  • Use AI-assisted drafting and crosswalk tooling for control narratives, framework mappings, and monitoring summaries, with human review on anything an AO reads and full traceability from every statement to a source record.
  • Push toward controls whose satisfaction is demonstrated by system state rather than by narrative.

Benefits

  • Receive equity in Apex, letting you benefit from the work you create
  • 100% company-paid medical, dental, and vision for you and your dependents
  • $100k life insurance at no cost
  • 15 days vacation, growing to 20+ days annually
  • 10 paid holidays
  • Competitive 401(k) plan with generous matching - 100% match on first 3%, 50% on next 2%
  • 8 weeks paid parental leave
  • childcare reimbursement up to $350/day for work-related travel
  • Daily catered lunch
  • unlimited snacks
  • Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family
  • Your dream desk setup and all the tools you need to be your most productive self
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service