EngineerJobs.io
← Back to all jobs

Job Description

Apex Technology, Inc. builds mission-focused security for classified space and cloud operations, with a team environment rooted in deep technical expertise and real-world delivery. This onsite role in Los Angeles gives you ownership over authorization posture for a space vehicle and a classified cloud mission operations environment, with opportunities to work alongside experts across aerospace and new space.

You will help produce and sustain RMF authorization packages, automate evidence generation using OSCAL and the authorization system of record, and keep authorization current through continuous monitoring. Pay is USD 162,000 - 198,000 per year.

Responsibilities

  • Build and sustain authorization packages for both boundaries, including system description, boundary definition, categorization, control selection and tailoring rationale, implementation statements, assessment coordination, and the residual risk picture carried to the AO.
  • Engage assessors early to align on evidence-generation approach so artifacts are trusted before downstream package dependencies.
  • Own the POA&M and maintain the authorization system of record (eMASS or equivalent).
  • Own the authorization boundary determination for the flight segment, including the rationale that survives assessor scrutiny.
  • Categorize under CNSSI 1253 and defend overlay selection, treating the Space Platform Overlay as the starting point and pushing back where onboard security capability exceeds published tailoring assumptions.
  • Tailor the control baseline with per-control rationale using Aerospace Space Segment Cybersecurity Profile (TOR-2023-02161 Rev A) and SPARTA-linked tailoring, including re-arguing controls back in where onboard capability exceeds baseline assumptions.
  • Define type-authorization for the bus and design how each vehicle generates off-the-line conformance evidence so fleet growth does not translate into linear assessment labor.
  • Derive verifiable security requirements from threat using SPARTA TTPs as the traceability key, owned by software and mission integration engineers building and testing against them.
  • Translate verification and production artifacts into assessment evidence, and notify engineering early when outputs will not satisfy assessor needs.
  • Own continuous monitoring for a fielded fleet, including security audit downlinked across contact windows, configuration drift across vehicles, and on-orbit software update as a recurring authorization event.
  • Define and document the authorization boundary for mission systems in classified cloud (AWS, Azure classified regions, or equivalent), including impact-level scoping and the seam with ground stations and the RF edge.
  • Own the control and evidence story for operator command authority: identity, role separation, least privilege, two-person integrity, non-repudiation, and complete audit of every command reaching the vehicle.
  • Build and defend the control inheritance model and prove the customer-responsible set with live evidence rather than assertion, validating cloud service provider and platform coverage versus customer responsibility for mission-unique applications.
  • Implement controls as code so infrastructure-as-code, policy-as-code, and pipeline configuration serve as implementation and evidence simultaneously.
  • Make change control and continuous monitoring work at operations tempo, positioned for the DoD transition toward CSRMC and continuous authorization.
  • Manage security incident reporting and coordination for the boundary.
  • Define what evidence is needed and in what form.
  • Design the OSCAL-based evidence data model and mapping layer resolving a property assertion to control identifiers across 800-53, CNSSI 1253 baselines, overlays, and program-unique control sets.
  • Build the pipeline that deterministically renders SSP sections, assessment evidence, POA&M items, and continuous monitoring reports from pinned evidence snapshots.
  • Integrate programmatically with the authorization system of record (eMASS or equivalent) so generated artifacts land where assessors look.
  • Use AI-assisted drafting and crosswalk tooling for control narratives, framework mappings, and monitoring summaries, with human review on anything an AO reads and full traceability from every statement to a source record.
  • Push toward control satisfaction demonstrated by system state rather than narrative.

Requirements

  • U.S. Citizenship (must possess the ability to access export-controlled data).
  • Active Top Secret clearance with SCI access and SAP eligibility strongly preferred.
  • Experience with technical tooling: reading pipeline output, querying an API, interpreting scanner and configuration state.
  • Bachelor's, master's, or PhD in systems engineering, computer science, cybersecurity, aerospace, or a related field.
  • Clear experience with hands-on building through coursework, internships, research code, personal projects, CTFs, a co-op, or an early role, with exposure to RMF, security compliance, cloud, or software engineering.
  • Willingness to learn RMF from the ground up, with demonstrated ability to pick up a complicated technical domain quickly while holding detail without losing the thread.
  • Strong experience in embedded/space systems or cloud infrastructure.
  • Multiple systems taken to authorization in national security or DoD environments, with fluency in RMF as practiced: categorization under CNSSI 1253, overlay selection, tailoring rationale, assessment coordination, POA&M management, continuous monitoring, and reauthorization triggers.
  • Ability to speak concretely about categorization, tailoring, assessment, and authorization, and to design, document, or test a report to determine whether it constitutes evidence that a control is satisfied.
  • Direct experience with at least one accredited cloud environment and one non-traditional system such as embedded, weapons, platform IT, industrial, or space.

Technologies

  • eMASS, OSCAL, SPARTA, CNSSI 1253, 800-53
  • AWS, Azure (classified regions)
  • TOR-2023-02161 Rev A, SPARTA TTPs
  • Xacta, Python, Go
  • CI/CD, infrastructure-as-code, policy-as-code, Git-based workflows
  • SSP, POA&M, CSRMC
  • DoD transition toward the Cybersecurity Risk Management Construct (CSRMC) and continuous authorization

Benefits

  • Receive equity in Apex.
  • 100% company-paid medical, dental, and vision for you and your dependents.
  • $100k life insurance at no cost.
  • Comprehensive PTO package starting at 15 days vacation, growing to 20+ days annually, plus 10 paid holidays.
  • Competitive 401(k) plan with generous matching: 100% match on first 3%, 50% on next 2%.
  • 8 weeks paid parental leave plus childcare reimbursement up to $350/day for work-related travel.
  • Daily catered lunch and unlimited snacks.
  • Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family.
  • Your dream desk setup and all the tools you need to be your most productive self.
  • World-class Playa Vista office with in-person collaboration and flexibility to integrate work and life.
  • Work alongside experts from aerospace, new space, and other cutting-edge industries to make a lasting difference.

Similar Jobs