{"id":1810932,"url":"https://alion.io/job/spacex-security-engineer-vulnerability-management","title":"Security Engineer (Vulnerability Management)","company":{"id":66,"name":"SpaceX","domain":"spacex.com","url":"https://alion.io/company/spacex","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"A","score":95,"open_postings":20,"ghost_share":0,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":106,"computed_at":"2026-10-04T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":null,"work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":78000,"max_usd":158000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":37},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"C#","optional":false},{"name":"C++","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"Rust","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"Bash","optional":true},{"name":"CVSS","optional":true},{"name":"DNS","optional":true},{"name":"GCP","optional":true},{"name":"Linux","optional":true},{"name":"PowerShell","optional":true},{"name":"TCP/IP","optional":true},{"name":"Threat Modeling","optional":true},{"name":"Windows","optional":true}],"status":"live","first_seen_at":"2026-09-25T17:01:48Z","employer_posted_date":"2026-09-29","last_verified_at":"2026-10-04T22:27:43Z","board_verified":true,"closed_at":null,"days_open":9,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":9},"description":"SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.\nSECURITY ENGINEER (VULNERABILITY MANAGEMENT)\nSpaceX is looking for a Security Engineer to join our Information Security department to help protect and drive the SpaceX mission.\nInformation drives our business and we must protect the confidentiality, integrity, and availability of systems and processes across the enterprise. As a highly visible and dynamic organization, we must also value and guard against damage to our reputation and brand. It is paramount that we defend against loss of control or confidence in our systems, to guarantee the highest probability of success.\nAs a member of the SpaceX Vulnerability Management team, the Security Engineer will act as a trusted partner to application software development teams. This role focuses on identifying, assessing, and remediating vulnerabilities and threats while developing and maintaining internal security tools. The role also includes hands-on work triaging bug reports, conducting Purple and Red Team activities, and continuous threat hunting. Strong communication skills and the ability to turn technical findings into practical, actionable guidance are essential.\nRESPONSIBILITIES:\nDevelopment of tools, processes, and guidance that make security easier to adopt without slowing delivery.\nConduct software code reviews to identify insecure patterns and help teams remediate issues.\nPerform web application security testing using established frameworks and tools.\nTriage and validate Bugcrowd reports, coordinate with researchers, and work directly with internal teams on remediation and disclosure.\nPerform Purple Team exercises to test controls, improve detection, and close identified gaps.\nContribute to Red Team operations or simulations, including scoping, execution support, and post-exercise analysis.\nBuild and operate emerging vulnerability communication processes so teams receive timely, actionable alerts on new threats.\nConduct continuous threat assessment by folding threat intelligence, emerging vulnerabilities, and attack trends into scanning coverage, notifications, and prioritization.\nPartner with other security sub-teams (detection/response, compliance, application security, infrastructure) to keep efforts consistent and reduce duplication.\nEscalate critical or time-sensitive issues promptly while offering practical mitigation options.\nDocument findings, produce metrics, and provide regular risk summaries to leadership.\nBASIC QUALIFICATIONS:\nBachelor's degree in computer science or another STEM discipline; OR 2+ years of professional experience in security software development in lieu of a degree.\nExperience with the Python programming language, GO, C#, C/C++, or Rust.\nExperience designing and implementing security solutions for operating systems, distributed systems, or other enterprise/large-scale infrastructure.\nPREFERRED SKILLS AND EXPERIENCE:\nExperience identifying, assessing, and remediating vulnerabilities (applications, infrastructure, or cloud).\nExperience working directly with engineering teams to close findings.\nScripting/automation experience (Python, Bash, PowerShell, or similar) and the ability to develop internal tools.\nStrong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls) and how they relate to vulnerability exposure.\nReverse engineering or vulnerability development experience.\nExperience triaging or working reports from bug bounty platforms (Bugcrowd, HackerOne, or similar).\nHands-on participation in Purple Team or Red Team exercises.\nOT Security Experience.\nExperience with continuous threat assessment, threat intelligence, or risk-based vulnerability prioritization.\nExperience developing internal security tools, dashboards, or automation pipelines (production-quality code, integrations, etc.).\nExperience with web application testing frameworks and tools.\nExperience performing software code reviews for security issues.\nExperience improving developer experience around security tooling and processes.\nKnowledge of network segmentation principles and implementation.\nExperience with asset discovery or inventory processes.\nExperience building or operating emerging vulnerability notification/alerting workflows.\nFamiliarity with AI/LLMs and MCPs.\nFamiliarity with cloud environments (AWS, Azure, GCP) and their native security/vulnerability features.\nExperience with configuration management, patching, or infrastructure-as-code.\nKnowledge of threat modeling, risk scoring (e.g., CVSS), and prioritization frameworks.\nFamiliarity with enterprise security controls and best practices for Windows, Linux, and macOS.\nStrong communication skills with the ability to translate technical findings into business impact and concrete remediation steps.\nRelevant certifications (e.g., OSCP, GSEC, or equivalent) or demonstrated equivalent experience.\nDemonstrable problem-solving skills and ability to quickly determine root causes of issues.\nADDITIONAL REQUIREMENTS:\nMust be willing to work extended hours and/or weekends as needed.\nThis role requires you to be onsite. Hybrid or remote work will not be considered.\nITAR REQUIREMENTS:\nTo conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. \nSpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.\nApplicants wishing to view a copy of SpaceX’s Affirmative Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to .","description_format":"text","description_chars":6374,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Endpoint Security","Information Security","Vulnerability Management","Space & Aerospace"],"lifecycle":[{"event":"open","at":"2026-10-03T20:47:19Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":8,"expected_fill_days":106,"reasons":["conf:1","win:early","comp:junior,brand"],"computed_at":"2026-10-04T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/spacex-security-engineer-vulnerability-management","json_url":"https://alion.io/job/spacex-security-engineer-vulnerability-management.json","meta":{"generated_at":"2026-10-05T00:05:07Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":18,"day_limit":5000,"remaining_today":4982,"minute_limit":60,"resets_at":"2026-10-06T00:00:00Z"}}}