Aalyria Logo

Aalyria

Senior Security Engineer

Posted 5 Hours Ago
Remote
Hiring Remotely in United States
170K-200K Annually
Senior level
Remote
Hiring Remotely in United States
170K-200K Annually
Senior level
Own cloud and network security, identity and PKI systems, and compliance for cloud and hybrid environments. Design secure cloud networking, manage NGFW/IDS/IPS, implement IAM/PAM/MFA, operate PKI and cryptography, maintain SIEM/EDR, and implement controls for CMMC L2, FedRAMP, and NIST 800-171. Support audits, documentation, risk assessments, and automation for compliance evidence and hardening standards.
The summary above was generated by AI
About Aalyria:

Aalyria is a leading technology company that supplies laser communications technology and temporospatial software-defined networking platforms to the aerospace industry. With technology acquired from Google, Aalyria is at the forefront of innovation in satellite and airborne mesh networks, as well as cislunar and deep-space communications. We are revolutionizing the orchestration and management of planetary mesh networks using any radio or optical spectrum, any orbit, and any hardware across land, sea, air, and space.

Role Overview:


We are looking for an experienced Senior Security Engineer to join our team. The ideal candidate is a skilled infrastructure and cloud security professional who can own cloud and network security, compliance operations, and identity systems for our products and environments. You will serve as the technical security expert responsible for securing our cloud infrastructure, network architecture, and access control systems supporting defense and federal customers.


This role requires a security professional with deep experience in cloud infrastructure, network security, and federal compliance frameworks. You will work closely with the Director of Security & IT to secure our cloud environments and systems in alignment with CMMC L2, FedRAMP, and NIST 800-171 requirements. Some of the kinds of responsibilities you may have are listed below.

Key Responsibilities:

Cloud Infrastructure Security

  • Design, implement, and manage secure cloud networking architectures including VPCs, subnets, peering, and transit gateways across GCP, AWS, or Azure
  • Configure and maintain cloud-native firewall rules, security groups, network ACLs, and perimeter controls to enforce least-privilege traffic policies
  • Implement and manage cloud security posture management (CSPM) tooling and continuously remediate misconfigurations across cloud environments
  • Design and operate network segmentation and micro-segmentation strategies aligned with zero trust architecture principles
  • Manage and harden cloud IAM, including role definitions, service account policies, privileged access controls, and just-in-time access

Firewall & Network Security

  • Manage next-generation firewall (NGFW) platforms, including policy development, rule lifecycle management, and traffic inspection configurations
  • Implement and maintain IDS/IPS, DNS security, and network monitoring solutions to detect and respond to threats
  • Design and enforce network access control (NAC) policies and segmentation for both cloud and on-premises environments
  • Conduct regular firewall rule reviews and access path analysis to identify and remediate overly permissive configurations

PKI & Identity Management

  • Design, implement, and operate PKI infrastructure including certificate authorities, certificate lifecycle management, and trust store management
  • Manage certificates for device identity, mutual TLS (mTLS), VPN authentication, and code signing in compliance with federal requirements
  • Administer and enforce access control policies across identity providers (IdPs), directory services (Active Directory / LDAP), and SSO platforms
  • Implement and maintain multi-factor authentication (MFA), privileged access management (PAM), and role-based access control (RBAC) systems
  • Ensure cryptographic implementations meet FIPS 140-2/140-3 requirements and federal standards

Compliance & Risk Management

  • Implement and maintain technical controls mapped to CMMC Level 2, FedRAMP, and NIST 800-171 control families
  • Develop and manage system security plans (SSPs), security assessment reports (SARs), and plans of action and milestones (POA&Ms)
  • Conduct continuous monitoring, log review, and evidence collection to support compliance audits and third-party assessments
  • Perform risk assessments and vulnerability management across cloud and on-premises infrastructure in accordance with NIST RMF
  • Maintain configuration baselines and enforce hardening standards (DISA STIGs, CIS Benchmarks) across systems and cloud resources

Security Operations & Documentation

  • Maintain and tune SIEM integrations, security logging pipelines, and alerting rules for cloud and network infrastructure
  • Manage endpoint detection and response (EDR) and vulnerability scanning tools across the infrastructure fleet
  • Build and maintain automation for compliance evidence collection, configuration auditing, and security reporting
  • Document security architecture, network diagrams, access control matrices, and
Required Qualifications:
  • 5+ years of experience in cloud infrastructure security, network security, or IT systems engineering with a security focus
  • Hands-on experience securing cloud environments in GCP, AWS, or Azure, including networking, IAM, and logging controls (GCP strongly preferred)
  • Demonstrated experience designing and managing cloud network security controls: firewalls, security groups, VPC/VNet architecture, and traffic inspection
  • Proficiency with next-generation firewalls (e.g., Palo Alto, Fortinet, or cloud-native equivalents) including policy management and traffic analysis
  • Working knowledge of PKI concepts, certificate lifecycle management, and cryptographic protocols (TLS, mTLS, FIPS 140-2/3)
  • Hands-on experience implementing and managing IAM, PAM, MFA, RBAC, and SSO systems in enterprise or federal environments
  • Direct experience implementing technical controls for CMMC L2, FedRAMP, or NIST 800-171 compliance programs
  • Strong understanding of zero trust architecture principles and practical implementation across hybrid environments
  • Experience with SIEM platforms, log aggregation, and security monitoring for infrastructure and network event data
  • Excellent communication skills with ability to explain security architecture and compliance posture to both technical teams and leadership
Preferred Qualifications:
  • Active Secret or Top Secret clearance, or ability to obtain
  • Experience designing and operating PKI infrastructure at scale, including enterprise or government CA hierarchies
  • Familiarity with FIPS 140-2/140-3 validated cryptographic modules and their deployment in federal environments
  • Experience with cloud security platforms such as Wiz, AWS Security Hub, GCP Security Command Center, or Azure Defender
  • Proficiency with infrastructure-as-code tools (Terraform, Ansible) for automating security configurations and compliance baselines
  • Knowledge of DISA STIGs, CIS Benchmarks, and hardening standards for Linux, Windows, and cloud platforms
  • Experience with network access control (NAC), SD-WAN, or SASE platforms in enterprise or federal environments
  • Background in IT systems engineering, network engineering, or systems administration with a transition to security
  • Familiarity with hardware security modules (HSMs) and their integration into PKI or secrets management workflows
  • Security certifications such as CISSP, CCSP, CompTIA Security+, GCP Professional Cloud Security Engineer, or equivalent
What We Offer:
  • Innovative Environment: Work at a cutting-edge company shaping the future of aerospace communications.
  • Impactful Work: Directly contribute to critical national security programs and initiatives.
  • Growth Opportunities: Expand your career with opportunities for professional development and advancement.
  • Inclusive Culture: Be part of a collaborative, supportive, and inclusive workplace where your contributions matter.
  • Flexibility: Flexible working arrangements including hybrid remote/in-office schedules.
  • Compensation and Equity: Competitive salary, comprehensive benefits (401(k), dental, vision, health, life insurance), paid time off, and equity options.
ITAR/EAR Requirements:

This position involves access to export-controlled information. To comply with U.S. government export regulations, applicants must meet one of the following criteria:


(A) Qualify as a U.S. person, which includes:

  • U.S. citizen or national
  • U.S. lawful permanent resident (green card holder)
  • Refugee under 8 U.S.C. 1157
  • Asylee under 8 U.S.C. 1158

(B) Be eligible to access export-controlled information without requiring an export authorization.


(C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency.


The company reserves the right to decline pursuing an export licensing process for legitimate business-related reasons.

Equal Opportunity Employer Statement:

Aalyria is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability status, genetic information, protected veteran status, or any other characteristic protected by law. Qualified applicants from all backgrounds are encouraged to apply.



Similar Jobs

5 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
167K-227K Annually
Senior level
167K-227K Annually
Senior level
Real Estate • Sales • Software • PropTech
Design, implement, and maintain security controls across cloud (AWS) and on-prem systems. Lead vulnerability management, incident response, and remediation. Serve as SME for SIEM, SAST/DAST, IAM. Embed security in SDLC, support SOC 2/ISO 27001 audit readiness, mentor junior engineers, and recommend control improvements.
Top Skills: AgileAWSDastIamIso 27001On-PremSaaSSastSIEMSoc 2Vulnerability Management
3 Days Ago
In-Office or Remote
83K-116K Annually
Senior level
83K-116K Annually
Senior level
Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
Design and implement multi-cloud security controls, build policy-as-code and IaC guardrails integrated into CI/CD, harden container and Kubernetes workloads, perform vulnerability analysis and remediation, support incident response and forensics, provide audit evidence for compliance frameworks, mentor other security engineers, and participate in on-call incident rotations to improve remediation and response processes.
Top Skills: Admission ControllersAWSAws OrganizationsAzureBashCi/CdContainer Image ScanningContainer Runtime DetectionContainersDependency Vulnerability ScanningEdrGCPIamInfrastructure As Code (Iac)JavaScriptKubernetesNaclsNetwork PoliciesPod Security StandardsPolicy As CodePythonSecurity GroupsService Control Policies (Scps)Vpc
14 Days Ago
Easy Apply
Remote or Hybrid
Lafayette, CO, USA
Easy Apply
110K-130K Annually
Senior level
110K-130K Annually
Senior level
Automotive • Greentech • HR Tech • Sales • Software
Lead KPA's enterprise security platforms and technical security initiatives across cloud, identity, endpoints, network, and DevOps. Own vulnerability management, incident response, SOC 2 compliance, vendor security assessments, and security automation. Partner with IT and DevOps to embed security in CI/CD, IaC, containers, and cloud workloads while improving posture through detection engineering, automation, and governance.
Top Skills: Amazon SesAuth0AWSAws Identity CenterAzureChatgpt EnterpriseCi/CdCisco DuoCisco MerakiCisco UmbrellaClaudeConditional AccessContainersCrowdstrikeDastDkimDmarcInfrastructure As CodeKnowbe4KubernetesMcpMicrosoft 365Microsoft Entra IdMicrosoft GraphPimPowershellPythonRapid7 InsightappsecRapid7 InsightidrRapid7 InsightvmRapid7 MdrRest ApisSastScimSendgridSnykSpfSsoVpn

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account