Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer (Vulnerability Management)

SpaceX

Security Engineer (Vulnerability Management) SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal ofenabling human life on Mars.

SECURITY ENGINEER (VULNERABILITY MANAGEMENT)

SpaceX is looking for a Security Engineer to join our Information Security department to help protect and drive the SpaceX mission. Information drives our business and we must protect the confidentiality, integrity, and availability of systems and processes across the enterprise. As a highly visible and dynamic organization, we must also value and guard against damage to our reputation and brand. It is paramount that we defend against loss of control or confidence in our systems, to guarantee the highest probability of success. As a member of the SpaceX Vulnerability Management team, the Security Engineer will act as a trusted partner to application software development teams. This role focuses on identifying, assessing, and remediating vulnerabilities and threats while developing and maintaining internal security tools. The role also includes hands‑on work triaging bug reports, conducting Purple and Red Team activities, and continuous threat hunting. Strong communication skills and the ability to turn technical findings into practical, actionable guidance are essential.

RESPONSIBILITIES:

Development of tools, processes, and guidance that make security easier to adopt without slowing delivery. Conduct software code reviews to identify insecure patterns and help teams remediate issues. Perform web application security testing using established frameworks and tools. Triage and validate Bugcrowd reports, coordinate with researchers, and work directly with internal teams on remediation and disclosure. Perform Purple Team exercises to test controls, improve detection, and close identified gaps. Contribute to Red Team operations or simulations, including scoping, execution support, and post-exercise analysis. Build and operate emerging vulnerability communication processes so teams receive timely, actionable alerts on new threats. Conduct continuous threat assessment by folding threat intelligence, emerging vulnerabilities, and attack trends into scanning coverage, notifications, and prioritization. Partner with other security sub‑teams (detection/response, compliance, application security, infrastructure) to keep efforts consistent and reduce duplication. Escalate critical or time‑sensitive issues promptly while offering practical mitigation options. Document findings, produce metrics, and provide regular risk summaries to leadership.

BASIC QUALIFICATIONS:

Bachelor's degree in computer science or another STEM discipline; OR 2+ years of professional experience in security software development in lieu of a degree. Experience with the Python programming language, GO, C#, C/C++, or Rust. Experience designing and implementing security solutions for operating systems, distributed systems, or other enterprise/large-scale infrastructure.

PREFERRED SKILLS AND EXPERIENCE:

Experience identifying, assessing, and remediating vulnerabilities (applications, infrastructure, or cloud). Experience working directly with engineering teams to close findings. Scripting/automation experience (Python, Bash, PowerShell, or similar) and the ability to develop internal tools. Strong understanding of networking fundamentals (TCP/IP, DNS, firewalls) and how they relate to vulnerability exposure. Reverse engineering or vulnerability development experience. Experience triaging or working reports from bug bounty platforms (Bugcrowd, HackerOne, or similar). Hands‑on participation in Purple Team or Red Team exercises. OT Security Experience. Experience with continuous threat assessment, threat intelligence, or risk‑based vulnerability prioritization. Experience developing internal security tools, dashboards, or automation pipelines (production‑quality code, integrations, etc.). Experience with web application testing frameworks and tools. Experience performing software code reviews for security issues. Experience improving developer experience around security tooling and processes. Knowledge of network segmentation principles and implementation. Experience with asset discovery or inventory processes. Experience building or operating emerging vulnerability notification/alerting workflows. Familiarity with AI/LLMs and MCPs. Familiarity with cloud environments (AWS, Azure, GCP) and their native security/vulnerability features. Experience with configuration management, patching, or infrastructure‑as‑code. Knowledge of threat modeling, risk scoring (e.g., CVSS), and prioritization frameworks. Familiarity with enterprise security controls and best practices for Windows, Linux, and macOS. Strong communication skills with the ability to translate technical findings into business impact and concrete remediation steps. Relevant certifications (e.g., OSCP, GSEC, or equivalent) or demonstrated equivalent experience. Demonstrable problem‑solving skills and ability to quickly determine root causes of issues.

ADDITIONAL REQUIREMENTS:

Must be willing to work extended hours and/or weekends as needed. This role requires you to be onsite. Hybrid or remote work will not be considered. To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status. Applicants wishing to view a copy of SpaceX’s Aff... or ... should reach out to View email address on click.appcast.io. Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file. As set forth in SpaceX’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law. If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows: A \"disabled veteran\" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service‑connected disability. A \"recently separated veteran\" means any veteran during the three‑year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service. An \"active duty wartime or campaign badge veteran\" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense. An \"Armed forces service medal veteran\" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985. #J-18808-Ljbffr SpaceX

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Security Engineer (Vulnerability Management) in Eastern, KY vacancy
  • SpaceX is seeking a Security Engineer in Vulnerability Management to protect systems and enable secure delivery across SpaceX programs. You will partner with software teams to identify, assess, and remediate vulnerabilities, while building internal security tooling and... 
    Suggested

    SpaceX

    Eastern, KY
    1 day ago
  • Command Post Technologies, Inc. (CPT) seeks a Senior Security Engineer to support the NCRC RM program with senior-level development...  ...for designated product scrum teams. The role emphasizes vulnerability management, governance, risk & compliance, and security... 
    Suggested

    Command Post Technologies

    Eastern, KY
    8 hours ago
  • BetaNXT Inc. is creating a senior security role to backfill a resigning Senior Associate, Information...  .... The Lead Associate / Cybersecurity Engineer will own day-to-day execution of BetaNXT's Vulnerability & Exposure Management program and contribute to PKI/CLM and DLP/data... 
    Suggested

    BetaNXT Inc.

    Eastern, KY
    3 days ago
  • Samsara is hiring a Staff Application Security Engineer to lead the vulnerability management program across cloud, firmware/IoT, and corporate systems. You’ll drive strategy, define the end‑to‑end process, and scale security tooling for a global, AI‑forward operations... 
    Suggested
    Remote work

    Samsara

    Eastern, KY
    2 days ago
  • $10k

     ...Partners is seeking an Information Systems Security Engineer (ISSE) to support the design,...  ...ensuring information assurance, risk management, security compliance, and secure system...  ...technical security assessments to identify vulnerabilities, compliance gaps, and security risks.... 
    Suggested
    Contract work
    Temporary work
    For contractors
    Local area

    Columbia Technology Partners

    Eastern, KY
    3 days ago
  • $130k - $150k

     ...Zachary Piper Solutions is seeking a Product Security Engineer to support a company focused on missile defense, command and control...  ...Engineer will support cybersecurity engineering, vulnerability management, and security validation efforts for a critical defense... 

    Zachary Piper Solutions

    Eastern, KY
    3 days ago
  • SpaceX is seeking a Security Engineer to join our Information Security team to protect the SpaceX mission and drive vulnerability management across the enterprise. You will work with software development teams, triage bug reports, and conduct Purple and Red Team activities... 

    Linuxconfig

    Eastern, KY
    3 days ago
  • $170k - $230k

    About the Role NinjaOne’s Application Security Engineering team is looking for a Senior Software...  ...an AI platform that discovers vulnerabilities in production code, validates findings...  ...orchestration, durable execution, context management, evaluation, and cost control. Your work... 
    Full time
    Remote work
    Work from home
    Relocation
    Flexible hours

    Jobvite

    Eastern, KY
    8 hours ago
  • $180k - $230k

     ...mortgage servicing business managing $110+ billion in loans. This...  ...regulated industries and beyond. Security at Valon Our customers...  ...partners closely with Product and Engineering to design and deliver secure...  ...to identify exploitable vulnerabilities Manage and implement... 
    Local area
    Remote work
    Flexible hours

    Apply

    Eastern, KY
    2 days ago
  •  ...Iru Iru is the AI-powered security & IT platform used by the world...  ...access, endpoint security & management, and compliance automation—...  ...Senior Product Security Engineer for a 6-month contract (40 hours...  ...to prioritize and remediate vulnerabilities. Review authentication,... 
    Contract work
    Remote work

    Iru, Inc.

    Eastern, KY
    3 days ago
  • $10k

     ...Description The Information Systems Security Engineer (ISSE) conducts and reviews technical...  ...of computing environments to identify vulnerabilities, ensure compliance with Information Assurance...  ...planning, risk analysis, risk management, and certification activities across... 
    Contract work
    Temporary work
    For contractors
    Local area

    Columbia Technology Partners

    Eastern, KY
    3 days ago
  • $180k - $190k

    Akima Data Management (ADM) is seeking a highly skilled and mission‑driven Information System Security Engineer (ISSE) to design, engineer, and validate cybersecurity capabilities...  ...and system accreditation. Conduct vulnerability analyses, threat modeling, and security... 
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Local area
    Remote work

    NANA Regional Corp

    Eastern, KY
    3 days ago
  • $180k - $200k

     ...CEO, Tyler Smith here! Purpose: The purpose of the Security Engineering Manager is to build and lead SkySlope's dedicated security engineering...  ...secret scanning), centralized logging and detection, vulnerability disclosure, and AI governance. # Sequence and... 

    SkySlope

    Eastern, KY
    3 days ago
  •  ...What You'll Be Doing The Cloud Security Engineer is responsible for designing, implementing...  ...identify and address potential security vulnerabilities and continuously improves the security...  ...infrastructure. Build, deploy, and manage security tools and services. Design... 

    Stifel Financial

    Eastern, KY
    3 days ago
  •  ...Overview The Senior Security Engineer supports and leads plant-wide technical security operations...  ...annual security plans and budgets, managing technical security controls, leading...  ...as required. Perform security and vulnerability assessments for network, server, and IT... 
    Work at office
    Local area

    MOBIS Alabama LLC

    Eastern, KY
    3 days ago
  • $165k - $200k

     ...safety features, and everyday family management in one connected experience. Designed...  ...experienced and motivated Staff Product Security Engineer to join our growing Security team....  ...PSIRT Operations by triaging incoming vulnerability reports, leading technical... 
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours
    Day shift

    Owl Ventures, LP

    Eastern, KY
    3 days ago
  • $140k - $170k

    ## Senior Cloud Security EngineerApply: Remote, United States: Full...  ...expertise in property management, investment management, development...  ...**The Senior Cloud Security Engineer is Greystar's hands-on...  ...Actively work down the CSPM and vulnerability backlog - rewriting... 
    Full time
    Local area
    Immediate start
    Remote work

    Greystar

    Eastern, KY
    3 days ago
  • $10 per hour

     ...our critical SaaS applications. Own security configuration for the SaaS tools hundreds...  ...corporate, enterprise, or IT security engineering — we care more about what you've...  ...Hands-on experience with modern endpoint management and EDR tooling (Jamf, Kandji, Intune,... 
    Work at office
    Immediate start
    Flexible hours

    Flexport

    Eastern, KY
    3 days ago
  • $300k - $320k

     ...growing group of committed researchers, engineers, policy experts, and business leaders...  ...AI systems. About the Team The Security Engineering team's mission is to safeguard...  ...novel attack vectors and chaining vulnerabilities creatively ~ Experience conducting adversarial... 
    Visa sponsorship

    EngineersOfAI

    Eastern, KY
    18 hours ago
  •  ...company advancing the diagnosis and management of coronary artery disease, the #1 cause...  ...are looking for a Senior Application Security Engineer to work with our engineering team to...  ...software developers throughout the vulnerability remediation lifecycle. Perform secure... 
    Work at office
    Local area
    Worldwide
    Relocation
    3 days per week

    HeartFlow

    Eastern, KY
    8 hours ago
  • We’re looking for a seasoned Security Engineer who has started applying that expertise to AI/ML systems. This role is a natural next step...  ...to streamline procurement, budgeting, payments, and grants‑management for public sector and government organizations. Euna’s AI‑powered... 
    Local area
    Remote work
    Flexible hours
    Weekend work

    Eunasolutions

    Eastern, KY
    3 days ago
  •  ...Skechers is hiring a Cybersecurity Analyst to join our global security team in Manhattan Beach. You will lead investigations, triage alerts, and support threat intelligence and vulnerability management initiatives. The role emphasizes incident handling, proactive security... 

    Skechers U.S.A.

    Eastern, KY
    4 days ago
  • Harvey is seeking a Software Engineer for the Security Engineering team to build and operate foundational security services for both our customer...  ...and internal systems. You’ll cover identity and access management, secrets, and privileged access while ensuring security is... 

    AI Chopping Block

    Eastern, KY
    3 days ago
  • Rumos Group in Palo Alto, CA is seeking a security engineer to help maintain and optimize security infrastructures, focusing on run operations, policy management, and incident response. You will implement security rules across Palo Alto and Fortinet devices, apply micro... 

    Rumos Group

    Eastern, KY
    1 day ago
  • $95 - $100 per hour

     ...better future! Job Details Cyber Exposure Management Engineer Dallas,TX Posted:9/15/2026 Job ID#: 64911 Job Category: Cyber Security Engineer Position Type: Contract...  ...engineer integrates attack surface discovery, vulnerability insights, misconfiguration analysis,... 
    Contract work
    Remote work

    Stefanini

    Eastern, KY
    3 days ago
  • $285k - $295k

    ## Principal Information Security Engineer, Identity Security EngineeringApply: Remote: Charlotte, NC: Full time: Posted Today: REQ535631*...  ...delivering global Identity Provider (IdP) and privileged access management controls. The role will provide knowledge, guidance, and... 
    Daily paid
    Full time
    Local area
    Remote work

    Jones Lang LaSalle Incorporated

    Eastern, KY
    8 hours ago
  • RPMGlobal seeks a Cloud Security Engineer 3 to secure, harden, and maintain compliance of cloud platforms across multiple secure networks...  ...for cloud and cloud-native environments, perform vulnerability management, and integrate security into CI/CD pipelines. Requires TS... 

    RPMGlobal

    Eastern, KY
    3 days ago
  • Senior Security Consultant (Mainframe Penetration Tester) Job Category : Services...  ...across 50+pentesttypes, attack surface management, and vulnerability prioritization. The NetSPI platform...  ...a focus on IT, Computer Science, Engineering or Math or equivalent experience 3-5... 
    Full time
    Remote work
    Worldwide

    NetSPI

    Eastern, KY
    3 days ago
  • # Senior Security Engineer - Penetration TesterTruistFull-timeAtlanta, Georgia, USA, Charlotte...  ...enterprise. If you enjoy finding vulnerabilities before adversaries do, proposing better...  ...teams, app teams, and various levels of management.Assist with standards, procedures,... 
    Shift work

    MainframeMaster

    Eastern, KY
    8 hours ago
  • depthfirst is seeking an experienced Research Engineer to join our team in building and training AI agents for vulnerability discovery and remediation. We are crafting a...  ...use. This role emphasizes practical impact in security and AI at scale. #J-18808-Ljbffr depthfirst... 

    depthfirst Inc.

    Eastern, KY
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer (Vulnerability Management). Be the first to apply!