SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Apex manufactures satellite buses at scale—spacecraft platforms that hold customer payloads and enable earth observation, communications, and other critical missions. The company combines software, vertical integration, and hardware design to serve the rapidly growing commercial space industry.
You will own or contribute to the authorization posture of two systems: a space vehicle and a classified cloud mission operations environment. This is mission systems cybersecurity work, not traditional enterprise IT security. You will engage in cyber engineering, produce RMF (Risk Management Framework) authorization documentation, build and sustain authorization packages, own the plan of action and milestones (POA&M), and run continuous monitoring.
Key responsibilities include:
**Authorization Ownership**: Build and sustain authorization packages covering system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, and assessment coordination. Own the POA&M and maintain the authorization system of record (eMASS or equivalent).
**Space Vehicle Segment**: Own authorization boundary determination for the flight segment. Categorize under CNSSI 1253 and defend overlay selection using the Space Platform Overlay as a starting point. Tailor the control baseline with per-control rationale using Aerospace's Space Segment Cybersecurity Profile and SPARTA-linked tailoring. Define type-authorization for the bus and design how each vehicle generates conformance evidence. Derive verifiable security requirements from threat using SPARTA TTPs. Translate verification and production artifacts into assessment evidence. Own the continuous monitoring story for a fielded fleet, including security audit downlink, configuration drift detection, and on-orbit software updates as recurring authorization events.
**Classified Cloud Mission Operations Environment**: Define and document the authorization boundary for mission systems in classified cloud (AWS, Azure classified regions, or equivalent), including impact-level scoping and seams with ground stations and RF edge. Own the control and evidence story for operator command authority: identity, role separation, least privilege, two-person integrity, non-repudiation, and complete audit of every command. Build and defend the control inheritance model and prove the customer-responsible set with live evidence. Implement controls as code so infrastructure-as-code, policy-as-code, and pipeline configuration serve as implementation and evidence. Make change control and continuous monitoring work at operations tempo. Manage security incident reporting and coordination.
**Automation and Generation**: Define evidence needs and form. Design the OSCAL-based evidence data model and mapping layer. Build the pipeline that renders SSP sections, assessment evidence, POA&M items, and continuous monitoring reports deterministically. Integrate with eMASS or equivalent programmatically. Use AI-assisted drafting and crosswalk tooling for control narratives, framework mappings, and monitoring summaries. Push toward controls whose satisfaction is demonstrated by system state rather than narrative.
The company is open to candidates from ISSE, SSE, ISSM, or ISSO backgrounds and is hiring across levels from new graduates through senior engineering, officer, and manager experience.
**REQUIREMENTS**
At Every Level:
- U.S. Citizenship (must possess ability to access export-controlled data)
- Active Top Secret clearance with SCI access and SAP eligibility strongly preferred
- Experience with technical tooling: reading pipeline output, querying an API, interpreting scanner and configuration state
Entry Level (1–3+ Years):
- Bachelor's, master's, or PhD in systems engineering, computer science, cybersecurity, aerospace, or related field
- Clear hands-on building experience via coursework, internships, research code, personal projects, CTFs, co-op, or early role; and/or some exposure to RMF, security compliance, cloud, or software engineering
- Willingness to learn RMF from the ground up with demonstrated ability to pick up complicated technical domains quickly and hold detail without losing the thread
Senior Level (5–10+ Years):
- Strong experience in embedded/space systems or cloud infrastructure
- Multiple systems taken to authorization in national security or DoD environments, with fluency in RMF as practiced: categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers
- Ability to speak concretely about categorization, tailoring, assessment, and authorization; design, document, or test a report; and determine whether it constitutes evidence that a control is satisfied
- Direct experience with at least one accredited cloud environment and one non-traditional system such as embedded, weapons, platform IT, industrial, or space
Preferred Qualifications:
- Experience with OSCAL, eMASS APIs, Xacta, controls-as-code, or continuous-controls-monitoring implementation
- Skilled in Python, Go, or equivalent; in CI/CD, infrastructure-as-code, and Git-based workflows
- Experience with continuous authorization, ongoing authorization, or cATO
- Experience building with AI-assisted development
- Understanding of Mission Operations including satellite command and control, mission planning, flight dynamics, telemetry processing, or multi-mission ground segments
- Embedded or safety-critical background in space, automotive, or industrial control
- Experience with SPARTA, NIST IR 8270 or IR 8401, CCSDS security standards, Space Platform Overlay, NASA/Space Force system protection standards, or space-system threat modeling
- Experience with classified cloud accreditation at IL5/IL6 or IC equivalents, or accreditation under JSIG or ICD 703
- Qualified or able to qualify under DoDM 8140.03 for systems security engineering, security architecture, or Information Systems Security Manager work role. CISSP, CISSP-ISSEP, CISM, and SecurityX map well.