SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 120,000 - 150,000 / annual
K2 Space is building the largest and highest-power satellites ever flown, backed by over $1 billion in total funding from leading investors including Altimeter Capital, ICONIQ, Kleiner Perkins, Lightspeed Venture Partners, Redpoint Ventures, and T. Rowe Price. The company has over $1 billion in signed contracts across commercial and US government customers and is mass-producing the highest-power satellite platforms ever built for missions from LEO to deep space. With multiple launches planned for 2027 and plans to scale to 100 satellites per year, K2 is a Series D-funded, high-growth aerospace company.
As a Security Engineer on the Identity & Access Management team, you will help build and operate the identity platform that governs authentication and authorization across K2's corporate, engineering, and mission environments. Identity is the perimeter at K2—every engineer, ground and mission system, SaaS tool, and automated pipeline depends on the right people and services holding exactly the access they need and nothing more.
You will work hands-on with the identity provider, SSO and federation, phishing-resistant MFA, lifecycle automation, and access reviews. You will work alongside senior identity engineers who will help you grow from executing well-defined work to owning identity problems end to end. This is a role for someone early in their security career who wants real-world impact: every application you onboard to SSO, every shared credential you retire, and every workflow you automate directly supports K2's ability to move fast, operate confidently, and deliver breakthrough satellite capabilities.
Key responsibilities include:
- Administer and support the enterprise identity platform, including the identity provider, single sign-on, and directory services across corporate, engineering, and mission environments
- Onboard SaaS and internal applications to SSO and automated provisioning using SAML, OIDC, and SCIM, retiring local accounts and shared credentials
- Operate and improve identity lifecycle workflows, including joiner, mover, and leaver processes, provisioning and deprovisioning, and access requests
- Help drive adoption of phishing-resistant MFA (FIDO2/WebAuthn) and support users through enrollment and rollout
- Maintain role-based access groups and entitlements under established least-privilege standards, and flag where access models need to evolve
- Support privileged access management operations, including administrator accounts, service accounts, and break-glass credential handling
- Assist with secrets management hygiene, including credential rotation for non-human accounts used by automated pipelines
- Help implement and monitor conditional access policies, and escalate anomalies in authentication
Note: This role requires U.S. Person status as defined by ITAR (U.S. citizens, lawful permanent residents, or certain protected individuals) or eligibility for a federally issued export control license, as the position will have access to information and items controlled by U.S. export control regulations.
Requirements: The posting does not explicitly state years of experience or specific technical certifications required. However, the role is described as suitable for someone "early in their security career" and emphasizes learning from senior identity engineers. The posting encourages applications even if candidates do not meet 100% of preferred skills, noting that non-traditional career paths are valued.