SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Apex manufactures satellite buses at scale for the commercial space industry, enabling earth observation, communications, and other critical missions. The company combines software, vertical integration, and hardware-focused manufacturing to serve an expanding ecosystem of payload companies as launch costs decrease and access to orbit becomes more democratized.
We seek a Senior Cloud Security Engineer to design, implement, and maintain secure cloud environments supporting U.S. government, DoD, and intelligence community missions. This role is central to protecting classified and sensitive data across AWS GovCloud, Azure, and hybrid/multi-cloud infrastructures while ensuring compliance with NIST 800-53, FedRAMP, RMF, and DoD Impact Levels (IL-4/IL-5).
Key responsibilities include:
- Design and implement secure cloud architectures across AWS GovCloud, Azure, and Google Cloud, applying least privilege, encryption, network segmentation, and data protection best practices.
- Implement and maintain cloud security frameworks ensuring compliance with NIST 800-53 Rev. 5, FedRAMP, DoD IL-2/4/5, RMF, and SCCA requirements.
- Configure and manage IAM, RBAC, JIT access, Key Vaults, and Zero Trust Architecture principles.
- Engineer, deploy, and optimize cloud-native security tools including Microsoft Defender for Cloud, Azure Sentinel, AWS GovCloud security services, CSPM/CWPP solutions, and SIEM platforms.
- Conduct vulnerability assessments, penetration testing simulations, and security configuration reviews against STIGs, CIS benchmarks, and NIST controls.
- Develop and maintain System Security Plans, Security Assessment Reports, Plans of Action & Milestones, and compliance reporting.
- Identify, analyze, and respond to security incidents and threat intelligence; perform root-cause analysis and implement preventive controls.
- Collaborate with DevSecOps, infrastructure, and development teams to integrate security into CI/CD pipelines and support secure cloud migrations.
- Assess cloud architectures, propose security improvements, and serve as a subject-matter expert on cloud security tools and best practices.
- Develop, enforce, and maintain cloud security policies, standards, and automated guardrails supporting secure CI/CD and infrastructure-as-code practices.
- Provide guidance and training to engineering teams on secure cloud design patterns.
Required: U.S. citizenship, Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field (or 5+ years equivalent professional experience). 5–9+ years hands-on cloud security engineering experience with AWS GovCloud, Azure, Google GCP, or multi-cloud environments. Strong analytical, problem-solving, communication, and collaboration skills. Deep knowledge of cloud platforms, IAM/RBAC, encryption, network security, and cloud-native security services. Familiarity with SIEM, vulnerability scanners, threat intelligence, and automation tools (Terraform, Python scripting). Experience with compliance frameworks (NIST, FedRAMP, RMF) and tools like Azure Sentinel, NESSUS, BURP SUITE, Microsoft Defender, or AWS equivalents. Deep understanding of network security, encryption, logging/monitoring, and container/Kubernetes security. Experience with infrastructure-as-code, scripting (Python, PowerShell), and security automation tools. Preferred certifications: CISSP, AWS Certified Security-Specialty, AWS Certified Solutions Architect, Microsoft Certified: Security.
On-site requirement: 5 days per week at Playa Vista, CA office.