RefolkCandidates
Open nowEngineeringOperations, Strategy, & Administrative

Enterprise Security Architect

Apex Space · Los Angeles, California

Location
Los Angeles, California , United States
Employment
Full time
Posted
2 months ago

About this role

Spacecraft represent the most pressing unmet need across the entire aerospace industry. As more launch vehicles come online and the cost to orbit decreases, more companies launching payloads to space continue to emerge.

For the first time in history, this influx of payload companies combined with reduced launch costs has resulted in a massive increase in need for commercial spacecraft platforms, known as satellite buses. These buses hold the payloads of our customers and are flown on launch vehicles.

Apex manufactures these satellite buses at scale using a combination of software, vertical integration, and hardware that is designed for manufacturing. Our spacecraft enable the future of society: ranging from earth observation to communications and more.

We’d love for you to join us on our mission of providing humankind access to the galaxy beyond our planet.

About the Role

The Enterprise Security Architect is responsible for designing, implementing, and maintaining secure enterprise architectures, systems, applications, networks, and cloud environments. This role provides technical leadership in cybersecurity strategy, risk management, security engineering, and compliance initiatives while ensuring Apex's information assets are protected against evolving cyber threats.

The ideal candidate combines deep technical expertise with strong business acumen to develop security solutions that align with organizational objectives, regulatory requirements, and industry best practices.

Essential Duties and Responsibilities

Security Architecture & Design

  • Design and maintain enterprise-wide cybersecurity architecture aligned with business and technology strategies.

  • Develop secure architectures for cloud, on-premises, hybrid, and multi-cloud environments.

  • Create and maintain security standards, reference architectures, and technical design

  • documents.

  • Perform threat modeling and security architecture reviews for new systems, applications, and infrastructure.

  • Evaluate emerging technologies and recommend security controls and solutions.

Security Engineering & Implementation

  • Design, implement, and optimize security controls across networks, systems, endpoints, applications, and cloud platforms.

  • Lead deployment and integration of security technologies including SIEM, IDS/IPS, DLP, EDR/XDR, IAM, and vulnerability management platforms.

  • Develop and automate security processes using scripting and infrastructure-as-code methodologies.

  • Collaborate with infrastructure, application development, and cloud engineering teams to embed security into technology solutions.

Risk Management & Compliance

  • Conduct security risk assessments, vulnerability assessments, and security audits.

  • Identify security gaps and develop remediation strategies.

  • Ensure compliance with applicable regulatory and industry frameworks, including:

    • NIST 800-53

    • NIST 800-171/172

    • ISO 27001

    • CIS Controls

    • SOC 2

  • Support governance, risk, and compliance (GRC) initiatives.

  • Incident Response & Security Operations

    • Provide architectural guidance during cybersecurity incidents and investigations.

    • Support incident response, threat hunting, and forensic analysis activities.

    • Review security events and identify opportunities to strengthen defensive capabilities.

    • Assist in developing cyber resilience and business continuity strategies.

    Leadership & Collaboration

    • Serve as a cybersecurity subject matter expert for technical and business stakeholders.

    • Mentor junior cybersecurity engineers, analysts, and administrators.

    • Present security recommendations, risk assessments, and strategic initiatives to leadership.

    • Partner with IT, engineering, operations, legal, and compliance teams to support enterprise security objectives.

    Education Requirements

    Required

    Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, or a related technical field.

    Preferred

    Master's degree in Cybersecurity, Information Security, Computer Science, or related

    discipline.

    Professional Certifications (Preferred)

    One or more of the following:

    • CISSP (Certified Information Systems Security Professional)

    • CISM (Certified Information Security Manager)

    • CCSP (Certified Cloud Security Professional)

    • SABSA Security Architecture Certification

    • AWS Certified Security - Specialty

    • Microsoft Azure Security Engineer Associate

    • GIAC Security Certifications (GIAC, GSEC, GDSA, etc.)

    Experience Requirements

    • 7 - 10+ years of experience in cybersecurity, information security, network security, cloud security, or related IT disciplines.

    • 3 - 5+ years of experience designing security architectures or leading cybersecurity engineering initiatives.

    • Experience implementing enterprise security controls and security frameworks.

    • Experience securing cloud platforms such as AWS, Azure, or Google Cloud Platform.

    Required Technical Skills

    Security Architecture

    • Enterprise Security Architecture

    • Zero Trust Architecture

    • Secure-by-Design Principles

    • Threat Modeling

    • Security Control Design

    • Security Roadmap Development

    Network & Infrastructure Security

    • Firewalls

    • IDS/IPS

    • VPN Technologies

    • Network Segmentation

    • DNS Security

    • TCP/IP Protocols

    • Secure Network Design

    Cloud Security

    • AWS Security Services

    • Microsoft Azure Security Services

    • Google Cloud Security

    • Container Security

    • Kubernetes Security

    • Infrastructure as Code (Terraform, CloudFormation)

    Identity & Access Management

    • Active Directory

    • Entra ID (Azure AD)

    • Single Sign-On (SSO)

    • Multi-Factor Authentication (MFA)

    • OAuth

    • SAML

    • Privileged Access Management (PAM)

    Security Operations

    • SIEM Platforms (Elastic,Splunk)

    • Endpoint Detection & Response (EDR/XDR)

    • Vulnerability Management

    • Security Monitoring

    • Threat Intelligence

    • Incident Response

    Application Security

    • Secure SDLC

    • DevSecOps

    • Application Security Testing (SAST/DAST)

    • API Security

    • OWASP Top 10

    • Secure Coding Practices

    Programming & Automation

    • Python

    • PowerShell

    • Bash/Shell Scripting

    • REST APIs

    • Security Automation

    Required Soft Skills

    • Strategic thinking and problem-solving

    • Strong analytical and risk assessment capabilities

    • Excellent written and verbal communication skills

    • Ability to communicate complex technical concepts to non-technical audiences

    • Leadership and mentoring skills

    • Project and stakeholder management

    • Cross-functional collaboration

    • Decision-making under pressure

    • Strong documentation and presentation skills

    Preferred Qualifications

    • Experience with large-scale enterprise environments.

    • Experience in regulated industries (financial services, healthcare, government, aerospace, defense, etc.).

    • Experience with cloud-native security and DevSecOps practices.

    • Knowledge of MITRE ATT&CK framework and threat intelligence methodologies.

    • Experience supporting security audits and compliance assessments.

    • Experience designing resilient and highly available security architectures.

    Why Join Apex?

    Apex believes in creating a work environment that you look forward to embracing every day. Our employees love working at Apex, and we want you to love it too. We're a fast-growing startup that has raised more than $500M in funding, and we invest heavily in our people from day one.

    What We Offer For Full-time Employees:

    • Shared upside: Receive equity in Apex, letting you benefit from the work you create

    • Best-in-class healthcare: 100% company-paid medical, dental, and vision for you and your dependents, plus $100k life insurance at no cost

    • Comprehensive PTO package to reset and recharge - starting at 15 days vacation, growing to 20+ days annually, plus 10 paid holidays

    • Competitive 401(k) plan with generous matching - 100% match on first 3%, 50% on next 2%

    • 8 weeks paid parental leave plus childcare reimbursement up to $350/day for work-related travel

    • Daily catered lunch and unlimited snacks to keep you fueled throughout the day

    • Vibrant community: Monthly office socials, pickleball tournaments, run club, and gatherings for you and your family

    • Your dream desk setup and all the tools you need to be your most productive self

    • World-class Playa Vista office with the benefit of in-person collaboration with amazing coworkers and flexibility to integrate work and life

    • Real impact opportunity: Work alongside experts from aerospace, new space, and other cutting-edge industries to make a lasting difference

    Ready to join a team where your contributions matter and your future is bright? Let's build something extraordinary together.

    Equal Opportunity Employer

    Apex Technology, Inc. is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. Candidates and employees are always evaluated based on merit, qualifications, and performance. We will never discriminate on the basis of race, color, gender, national origin, ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability, or any other legally protected status.

    As published by Apex Space. Applications are handled on their site.

    Skills this posting mentions

    Cloud ServicesGRCCompliance

    About Apex Space

    Apex was founded to solve one of the space industry’s biggest challenges: the satellite production bottleneck. While reusable launch vehicles have solved many orbital access challenges, scaled satellite manufacturing remains a critical bottleneck to constellation deployment. Apex’s solution: productized, configurable spacecraft designed for manufacturing and delivered at scale. Our three product lines - Aries, Nova, and Comet - serve a broad range of customer missions through configurable designs optimized for operations from LEO to GEO. These platforms will ensure the U.S. and its allies maintain a strategic advantage in the New Space Race, providing the foundation for today’s most critical constellations and tomorrow’s next-generation architectures. ‍ Today, Apex is delivering standardized satellite buses at scale by blending traditional aerospace techniques with new space mentalities and lessons from high-rate terrestrial manufacturing. Since our founding, our focus remains the same: short lead times, constellation-scale production, and highly reliable spacecraft. We can’t wait to see what you build on Apex’s platforms. Let's get to orbit.

    All 84 openings at Apex Space

    One click, then it is written

    Apply to Apex Space with a resume written for this role.

    Queue Enterprise Security Architect and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Apex Space’s form for you.

    1. 01Drop your resume

      A PDF or a LinkedIn URL. About a minute, once.

    2. 02I rank the openings

      Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

    3. 03Each one is written up

      Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

    • 25 sent a week, free
    • No card
    • Nothing sent until you say so

    More roles at Apex Space

    See all

    Similar roles elsewhere

    See more

    Put this to work

    Paste your career in once. Every application after that is written for you.

    Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

    1. 01Drop your resume

      A PDF or a LinkedIn URL. About a minute, once.

    2. 02I rank the openings

      Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

    3. 03Each one is written up

      Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

    • New matches ranked and written before you are up.
    • Every bullet stays inside what your history supports. Nothing invented.
    • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

    500 free credits on sign-up. No card. Nothing is sent until you say so.

    Listed from the job board Apex Space publishes. Refolk is not the employer and does not handle their hiring. Applications go to Apex Space directly.