Senior Security Engineer, Identity and Access Management (IAM)

Los Angeles, CA·Posted 1mo ago
cybersecuritysaaspythongorustawsgcpterraform
<div class="content-intro"><p data-renderer-start-pos="41">K2 is building the largest and highest-power satellites ever flown, unlocking performance levels previously out of reach across every orbit. Backed by over $1 billion in total funding from leading investors including Altimeter Capital, ICONIQ, Kleiner Perkins, Lightspeed Venture Partners, Redpoint Ventures, and T. Rowe Price — and with over $1 billion in signed contracts across commercial and US government customers, we're mass-producing the highest-power satellite platforms ever built for missions from LEO to deep space.</p> <p data-renderer-start-pos="570">The rise of heavy-lift launch vehicles is shifting the industry from an era of mass constraint to one of mass abundance, and we believe this new era demands a fundamentally different class of spacecraft. Engineered to survive the harshest radiation environments and to fully capitalize on today's and tomorrow's massive rockets, K2 satellites deliver unmatched capability at constellation scale and across multiple orbits.</p> <p data-renderer-start-pos="994">With multiple launches in 2027 and plans to scale to 100 satellites a year, we're Building Bigger — helping develop the solar system and build toward a Kardashev Type II (K2) civilization. If you are a motivated individual who thrives in a fast-paced environment and you're excited about contributing to the success of a high-growth Series D-funded company, we'd love for you to apply.</p></div><p><strong><span data-contrast="none">The Role</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}">&nbsp;</span></p> <p><span data-contrast="auto">Identity is the perimeter at K2. Every engineer, every ground and mission system, every SaaS tool and automated pipeline depends on the right people and services holding exactly the access they need and nothing more. This role owns that problem end to end:&nbsp;you’ll&nbsp;design, build, and run the identity platform that governs authentication and authorization across our corporate, engineering, and mission environments.&nbsp;You’ll&nbsp;be deeply hands-on with our identity provider, SSO and federation, phishing-resistant MFA, lifecycle automation, privileged access, and secrets management, and&nbsp;you’ll&nbsp;retire the standing access and shared credentials that accumulate in any fast-growing company. This is a role for someone who thrives on real-world impact: making least privilege the default without slowing down the&nbsp;teams&nbsp;building spacecraft. Every access path you close and every workflow you automate directly supports our ability to move fast,&nbsp;operate&nbsp;confidently, and deliver breakthrough satellite capabilities.</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}">&nbsp;</span></p> <p><strong><span data-contrast="none">Responsibilities</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}">&nbsp;</span></p> <ul> <li><span data-contrast="auto">Own and mature the enterprise identity platform, including the identity provider, single sign-on, federation, and directory services across corporate, engineering, and mission environments</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Design and implement authentication standards using modern protocols such as SAML, OIDC, OAuth 2.0, and SCIM, and drive adoption of phishing-resistant MFA including FIDO2 and&nbsp;WebAuthn</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Build and automate identity lifecycle management, including joiner, mover, and leaver workflows, provisioning and deprovisioning, and just-in-time access</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Design and&nbsp;maintain&nbsp;role-based and attribute-based access models, entitlement structures, and least-privilege standards for corporate and engineering systems</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Implement and&nbsp;operate&nbsp;privileged access management for administrators, service accounts, and break-glass credentials</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Manage machine and workload identity, including secrets management, credential rotation, and the non-human accounts used by automated pipelines and mission systems</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Onboard SaaS and internal applications to SSO and automated provisioning using SCIM, REST APIs, and webhooks, retiring local accounts and shared credentials as you go</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Implement conditional access and risk-based authentication policies, then tune them against real access patterns</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Build and run access review and certification campaigns, producing the evidence auditors and customers&nbsp;require</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Harden cloud IAM across AWS, Azure, or GCP, including roles, trust policies, and permission boundaries</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Write code and infrastructure as code to automate identity operations rather than resolving them ticket by ticket</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Partner with security operations on identity threat detection and response, including credential abuse, session hijacking, and MFA fatigue attacks, and support investigations involving identity</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Serve as the identity subject matter expert in architecture and design reviews, acting as a liaison between the security team and engineering</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="auto">Maintain identity documentation, runbooks, and standards, and mentor junior team members on identity engineering practices</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> </ul> <p><strong><span data-contrast="none">Qualifications</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}">&nbsp;</span></p> <ul> <li><span data-contrast="none">5+ years of experience in identity and access management, security engineering, or infrastructure engineering, preferably in a fast-paced startup or technology environment</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Hands-on experience administering an enterprise identity provider (e.g., Okta, Microsoft Entra ID, Ping, or Google Identity), including SSO, MFA, and conditional access</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Strong working knowledge of identity protocols and standards, including SAML, OIDC, OAuth 2.0, SCIM, LDAP, and Kerberos</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience designing and implementing identity lifecycle automation, RBAC or ABAC access models, and access review processes</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience with privileged access management and secrets management for both human and machine identities, such as&nbsp;HashiCorp&nbsp;Vault or equivalent</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience with cloud IAM in AWS, Azure, or GCP, including least-privilege role and policy design</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">2+ years of development experience with any modern programming language (including but not limited to Python, Go, C++, Rust) used to automate identity workflows and integrations, in lieu of a degree; OR a bachelor’s degree in security engineering, cyber security, computer science, engineering, math, or other STEM discipline</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Comfortable working with mission critical and sensitive systems, with a sense of urgency&nbsp;appropriate with&nbsp;responsibilities</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Due to the high visibility of this position, excellent interpersonal skills, attention to detail, and problem-solving skills</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> </ul> <p><strong><span data-contrast="none">Nice to Have</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Bachelor’s degree (or equivalent) in computer science or engineering</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Identity certifications such as Okta Certified Administrator, Microsoft Identity and Access Administrator (SC-300), or CISSP, or equivalent hands-on experience</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience managing identity resources with infrastructure as code (Terraform, CloudFormation, or CDK)</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience with policy-as-code frameworks such as OPA or Cedar</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience with identity threat detection and response (ITDR) and building identity-focused detections</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience integrating modern identity with legacy or&nbsp;on-premise&nbsp;systems, including Active Directory modernization</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Experience with identity and access control for engineering, manufacturing, OT, or mission and ground segment environments</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Prior experience in a defense, aerospace, or other ITAR-regulated environment</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> </ul> <p><strong><span data-contrast="none">Compensation and Benefits:</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Base salary range for this role is&nbsp;$150,000 - $220,000&nbsp;and equity in the company</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Salary will be based on several factors including, but not limited&nbsp;to:&nbsp;knowledge and skills, education, and experience level</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> <li><span data-contrast="none">Comprehensive benefits package including paid time off, medical/dental/vision coverage, life insurance, paid parental leave, and many other&nbsp;perks</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}">&nbsp;</span></li> </ul><div class="content-conclusion"><p>If you don’t meet 100% of the preferred skills and experience, we encourage you to still apply! Building a spacecraft unlike any other requires a team unlike any other and non-traditional career twists and turns are encouraged!</p> <p>If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.</p> <p><strong>Export Compliance</strong></p> <p>As defined in the ITAR, “U.S. Persons” include U.S. citizens, lawful permanent residents (i.e., Green Card holders), and certain protected individuals (e.g., refugees/asylees, American Samoans). Please consult with a knowledgeable advisor if you are unsure whether you are a “U.S. Person.”</p> <p>The person hired for this role will have access to information and items controlled by U.S. export control regulations, including the export control regulations outlined in the International Traffic in Arms Regulation (ITAR). The person hired for this role must therefore either be a “U.S. person” as defined by&nbsp;<a class="c-link" href="https://www.law.cornell.edu/cfr/text/22/120.15" target="_blank">22 C.F.R. § 120.15</a> or otherwise eligible for a federally issued export control license.</p> <p><strong>Equal Opportunity</strong></p> <p>K2 Space is an Equal Opportunity Employer; employment with K2 Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.</p></div>