SpaceX→
Application Security Engineer at SpaceX in Hawthorne, CA
Entry LevelOn-siteFull-timeHawthorne, CA$130k–$150k/yr
Skills
information securitynetworkingsystems administrationsecure code developmentpythongoc#rustlinux system internalswindows system internalsmac system internalsthreat modelingsecure architecture designcloud security awscloud security azurecloud security gcpweb api developmenthttp-rpcrestautomation/scripting pythonautomation/scripting bashautomation/scripting powershelloswe certificationoscp certificationgwapt certificationenterprise security controls
Job Description
Summary: SpaceX is actively developing technologies to enable human life on Mars. The Application Security Engineer will serve as a trusted partner to development and business teams, ensuring security is integrated into the development process without hindering delivery timelines.
Responsibilities:
- Serving as a primary point of contact between Security Engineering and development teams for security reviews
- Supporting developers in understanding and implementing secure design practices
- Ensuring security findings are communicated in a way that is clear, actionable, and aligned to business objectives
- Partnering with other security sub-teams (e.g., compliance, infrastructure, detection/response) to maintain consistency across security initiatives
- Building productive relationships with stakeholders across SpaceX to foster a culture of security awareness and shared responsibility
- Perform comprehensive security reviews of applications and services developed across SpaceX
- Evaluate architecture, authentication/authorization flows, data handling, and exposure to external entities
- Document findings with actionable recommendations for remediation
- Collaborate with development teams to ensure issues are understood and addressed before release
- Escalate critical risks to leadership promptly while providing balanced options for mitigation
- Participate in peer review of security assessments to maintain quality and consistency
- Provide input on improving team processes, documentation, and standards
- Share lessons learned from reviews and projects to help scale security knowledge across SpaceX
Required Qualifications:
- Bachelor's degree in information systems, information security, computer science, or computer engineering and 1+ years of information security, networking and/or systems administration experience (internships and co-ops may qualify); or 4+ years of information security experience without a degree
- Experience with secure code development practices
- Experience with common programming languages (e.g., Python, GO, C#, or Rust) and the ability to identify insecure coding practices
- Experience with Linux, Windows, and Mac system internals
- Must be willing to work extended hours and/or weekends
- This role is based in Hawthorne, CA and will require you to be onsite. Remote or hybrid work will not be considered
Preferred Qualifications:
- Experience with threat modeling and secure architecture design
- Familiarity with cloud environments (AWS, Azure, GCP) and their native security controls
- Familiarity with developing web-based APIs, HTTP-RPC, and REST
- Knowledge of automation/scripting (Python, Bash, PowerShell) to streamline assessments and reporting
- Strong communication skills, with the ability to translate technical findings into business impacts
- Relevant certifications (OSWE, OSCP, GWAPT, or equivalent)
- Familiarity with enterprise security controls and security best practices for Windows, Linux, and Mac systems
- Effective problem-solving skills, and ability to quickly determine root-causes of issues
- Familiarity with macOS and Windows code-signing and deployment of enterprise applications
Required Skills: Information Security, Networking, Systems Administration, Secure Code Development, Python, Go, C#, Rust, Linux System Internals, Windows System Internals, Mac System Internals, Threat Modeling, Secure Architecture Design, Cloud Security AWS, Cloud Security Azure, Cloud Security GCP, Web API Development, HTTP-RPC, REST, Automation/Scripting Python, Automation/Scripting Bash, Automation/Scripting PowerShell, OSWE Certification, OSCP Certification, GWAPT Certification, Enterprise Security Controls
Benefits: Long-term incentives, in the form of company stock, stock options, or long-term cash awards, Potential discretionary bonuses, The ability to purchase additional stock at a discount through an Employee Stock Purchase Plan, Comprehensive medical, vision, and dental coverage, Access to a 401(k) retirement plan, Short and long-term disability insurance, Life insurance, Paid parental leave, Various other discounts and perks, 3 weeks of paid vacation, 10 or more paid holidays per year, Paid sick leave pursuant to Company policy which satisfies or exceeds the accrual, carryover, and use requirements of the law
Benefits
Long-term incentives, in the form of company stock, stock options, or long-term cash awards
Potential discretionary bonuses
The ability to purchase additional stock at a discount through an Employee Stock Purchase Plan
Comprehensive medical, vision, and dental coverage
Access to a 401(k) retirement plan
Short and long-term disability insurance
Life insurance
Paid parental leave
Various other discounts and perks
3 weeks of paid vacation
10 or more paid holidays per year
Paid sick leave pursuant to Company policy which satisfies or exceeds the accrual, carryover, and use requirements of the law