Security Engineer (Vulnerability Management)
SpaceX · Starbase, TX
About this role
**Security Engineer (Vulnerability Management)** SpaceX is looking for a **Security Engineer** to join our **Information Security** department to help protect and drive the SpaceX mission. Information drives our business, and we must protect the **confidentiality, integrity, and availability** of systems and processes across the enterprise—while also guarding our **reputation and brand**. This role is focused on defending against loss of control or confidence in our systems to maximize the probability of success. As a member of the **SpaceX Vulnerability Management** team, you will act as a trusted partner to application software development teams. You’ll identify, assess, and remediate vulnerabilities and threats while developing and maintaining internal security tools. The role includes hands-on work triaging bug reports, conducting **Purple and Red Team** activities, and continuous threat hunting. Strong communication skills are essential—especially the ability to turn technical findings into practical, actionable guidance. --- ## Responsibilities - Develop tools, processes, and guidance that make security easier to adopt without slowing delivery - Conduct software code reviews to identify insecure patterns and help teams remediate issues - Perform web application security testing using established frameworks and tools - Triage and validate Bugcrowd reports, coordinate with researchers, and work with internal teams on remediation and disclosure - Perform Purple Team exercises to test controls, improve detection, and close identified gaps - Contribute to Red Team operations or simulations (scoping, execution support, and post-exercise analysis) - Build and operate vulnerability communication processes for timely, actionable alerts on new threats - Conduct continuous threat assessment by incorporating threat intelligence, emerging vulnerabilities, and attack trends into scanning coverage, notifications, and prioritization - Partner with other security sub-teams (detection/response, compliance, application security, infrastructure) to keep efforts consistent and reduce duplication - Escalate critical or time-sensitive issues promptly while offering practical mitigation options - Document findings, produce metrics, and provide regular risk summaries to leadership --- ## Basic Qualifications - Bachelor’s degree in computer science or another STEM discipline; **or** 2+ years of professional experience in security software development in lieu of a degree - Experience with **Python**, **GO**, **C#**, **C/C++**, or **Rust** - Experience designing and implementing security solutions for operating systems, distributed systems, or other enterprise/large-scale infrastructure --- ## Preferred Skills and Experience - Experience identifying, assessing, and remediating vulnerabilities (applications, infrastructure, or cloud) - Experience working directly with engineering teams to close findings - Scripting/automation experience (Python, Bash, PowerShell, or similar) and ability to develop internal tools - Strong networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls) and how they relate to vulnerability exposure - Reverse engineering or vulnerability development experience - Experience triaging or working reports from bug bounty platforms (Bugcrowd, HackerOne, or similar) - Hands-on participation in Purple Team or Red Team exercises - OT Security experience - Experience with continuous threat assessment, threat intelligence, or risk-based v
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.