Principal Security Design Engineer

Iridium Satellite, LLC•Redwood City, CA
•Hybrid

About The Position

Iridium is building security-critical infrastructure for a new service currently in low-visibility proof-of-concept engagements with prospective partners. We are seeking a Principal Security Engineer to join at the earliest stage and ensure security is designed correctly from the start. This role provides deep adversarial and architectural expertise, identifying how this service could be attacked and guiding how we defend it. You will work as a principal-level technical peer to engineering, influence early design decisions, drive red-team style assessments, and serve as a tier-2 subject-matter expert in select partner and customer conversations. As one of the first security specialists on the team, you will help establish early security practices and a threat-modeling culture that will scale as the team grows.

Requirements

  • 10+ years of experience in network and information security, with demonstrated depth in offensive or adversarial security; red team experience strongly preferred.
  • Strong applied expertise in AWS security fundamentals (IAM, VPC architecture, common cloud misconfigurations and exploitation patterns).
  • Solid hands on understanding of modern identity and access protocols (SAML, OIDC, OAuth 2.0, WebAuthn, CTAP), including how these flows can be attacked or strengthened.
  • Demonstrated ability to communicate security risk clearly to both engineers and non technical stakeholders, including customers and partners.
  • Experience operating as an individual contributor in a high ambiguity, high trust, small team environment.
  • Excellent communication skills, with the ability to convey products, deliverables, analyses, and/or issues clearly and confidently, and recognize and adapt to different communication techniques.
  • Can easily build meaningful relationships with others, including senior leadership outside of your own department, and comfortable providing constructive feedback to your team members and management.
  • Be able to analyze a situation or problem, generate effective solutions, and see those solutions through to completion.
  • Must possess the creativity and resourcefulness needed to make reliable decisions and determine methods on new assignments.
  • Can thrive in a dynamic environment by handling multiple tasks and managing shifting priorities.
  • Be proactive in sharing knowledge you’ve learned with others.
  • U.S. citizen

Nice To Haves

  • Experience with hardware root-of-trust, secure elements, or embedded device attestation concepts.
  • Experience in regulated or compliance-sensitive industries (financial services, gaming/gambling, critical infrastructure).
  • Industry certifications (OSCP, CISSP, or similar) are welcome but not a substitute for demonstrated hands-on depth.
  • Ability to obtain and maintain an active security clearance is a plus.

Responsibilities

  • Analyze our AWS-based cloud infrastructure, APIs, and supporting services to identify realistic attack paths and translate findings into clear defensive priorities.
  • Advise engineering leadership on secure design decisions across cloud infrastructure, application logic, and device/key-management touchpoints early in the development lifecycle.
  • Develop and maintain service-specific threat models and guide an emerging threat-modeling culture for a small, fast-moving pre-launch engineering team.
  • Conduct or commission red-team style assessments spanning network, application, cloud configuration, identity flows, and adjacent supply-chain vectors.
  • Communicate security findings in terms of business impact, driving pragmatic prioritization and informed decision-making.
  • Evaluate how Iridium’s service integrates into partner identity and access systems (SAML, OIDC, OAuth 2.0, WebAuthn, CTAP).
  • Identify how these integrations could be attacked, misused, or strengthened, particularly in step-up authentication and assurance contexts.
  • Serve as a tier-2 security SME in select partner or prospective-customer conversations where deep technical expertise is required beyond sales engineering capabilities.
  • Collaborate closely with engineering, product, and partner-facing teams to ensure security decisions are incorporated throughout the service architecture.
  • Help establish early security practices, lightweight processes, and technical standards appropriate for a pre-launch product environment.
  • Provide mentorship and guidance to engineers and future security team members as the capability grows.

Benefits

  • medical, dental, and vision insurance coverage
  • 401(k) retirement plan options
  • paid time off and paid holidays
  • paid parental leave
  • company stock
  • annual bonus
  • other discounts and perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service