← Back to results

Security Engineer, Identity and Access Management (IAM)

Join K2 Space as a junior Security Engineer to build and operate the identity platform for satellite missions.

Location
Los Angeles, CA
Compensation
$120k–$150k/yr
Level
junior
Type
full time

Posted by employer 1 week ago

First seen on Joblaze 2 days ago

Last verified on the company career page 20 hours ago

Apply at K2 Space → Save job Scanned from k2space.com

What you'll build

  • Administer and support the enterprise identity platform
  • Onboard SaaS and internal applications to SSO
  • Operate and improve identity lifecycle workflows
  • Help drive adoption of phishing-resistant MFA
  • Execute access review and certification campaigns

Must have

  • 1–3 years of experience in identity and access management
  • Hands-on experience with an enterprise identity provider
  • Foundational understanding of identity protocols and standards
  • Scripting experience in a modern language
  • Exposure to at least one major cloud provider
  • Bachelor's degree in cyber security, computer science, or related field

Nice to have

  • Entry-level security or identity certifications
  • Experience with infrastructure as code
  • Experience with secrets management tooling
  • Exposure to Active Directory or Kerberos
  • Familiarity with identity threat detection concepts
  • Personal projects or home labs in identity or security

Requirements

Experience
1–3 years
Education
Bachelor's degree

Not disclosed in this posting: work arrangement, visa sponsorship.

Benefits

Equity/Stock Options Paid Time Off Health Insurance Parental Leave

Joblaze summary

In this role, the Security Engineer for Identity and Access Management at K2 Space will focus on building and managing the identity platform that ensures secure authentication and authorization across various environments. Key skills include experience with identity providers, SSO, and familiarity with identity protocols like SAML and OIDC, alongside scripting abilities for automation. This position is ideal for early-career professionals with a background in security engineering or IT systems administration, looking to make a tangible impact in a fast-paced, high-growth aerospace company.

Joblaze insights

  • Listed 2 days ago — first seen on Joblaze September 19, 2026. Last confirmed on K2 Space's careers page September 21, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 36% of 11 comparable junior security roles in United States we track (median $130,000 across 6 companies).

Quick facts

What's the salary range?
K2 Space lists $120,000–$150,000 for this role.
How much experience is required?
1–3 years of relevant experience for this Security Engineer, Identity and Access Management (IAM) role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Azure, GCP, Go, Google Identity, LDAP.
What seniority level is this role?
K2 Space targets junior candidates for this position.
Is this full-time or contract?
Full-time for this Security Engineer, Identity and Access Management (IAM) role at K2 Space.

From the original posting

K2 is building the largest and highest-power satellites ever flown, unlocking performance levels previously out of reach across every orbit. Backed by over $1 billion in total funding from leading investors including Altimeter Capital, ICONIQ, Kleiner Perkins, Lightspeed Venture Partners, Redpoint Ventures, and T. Rowe Price — and with over $1 billion in signed contracts across commercial and US government customers, we're mass-producing the highest-power satellite platforms ever built for missions from LEO to deep space.

The Role

Identity is the perimeter at K2. Every engineer, every ground and mission system, every SaaS tool and automated pipeline depends on the right people and services holding exactly the access they need and nothing more. As a Security Engineer on the Identity & Access Management team, you'll help build and operate the identity platform that governs authentication and authorization across our corporate, engineering, and mission environments. You'll get hands-on with our identity provider, SSO and federation, phishing-resistant MFA, lifecycle automation, and access reviews, working alongside senior identity engineers who will help you grow from executing well-defined work to owning identity problems end to end. This is a role for someone early in their security career who wants real-world impact: every application you onboard to SSO, every shared credential you retire, and every workflow you automate directly supports our ability to move fast, operate confidently, and deliver breakthrough satellite capabilities.

Responsibilities

  • Administer and support the enterprise identity platform, including the identity provider, single sign-on, and directory services across corporate, engineering, and mission environments
  • Onboard SaaS and internal applications to SSO and automated provisioning using SAML, OIDC, and SCIM, retiring local accounts and shared credentials as you go
  • Operate and improve identity lifecycle workflows, including joiner, mover, and leaver processes, provisioning and deprovisioning, and access requests
  • Help drive adoption of phishing-resistant MFA (FIDO2/WebAuthn) and support users through enrollment and rollout
  • Maintain role-based access groups and entitlements under established least-privilege standards, and flag where access models need to evolve
  • Support privileged access management operations, including administrator accounts, service accounts, and break-glass credential handling
  • Assist with secrets management hygiene, including credential rotation for the non-human accounts used by automated pipelines
  • Help implement and monitor conditional access policies, and escalate anomalies in authentication patterns
  • Execute access review and certification campaigns and collect the evidence auditors and customers require
  • Write scripts and contribute to infrastructure as code that automate repetitive identity operations rather than resolving them ticket by ticket
  • Triage identity-related tickets and incidents, and partner with security operations on investigations involving credential abuse or MFA fatigue attacks
  • Contribute to identity documentation, runbooks, and standards, and keep them current as the environment changes

Qualifications

  • 1–3 years of experience in identity and access management, security engineering, IT systems administration, or a related technical role (internships and co-ops count)
  • Hands-on experience with an enterprise identity provider (e.g., Okta, Microsoft Entra ID, Ping, or Google Identity), including SSO, MFA, and user or group administration
  • Foundational understanding of identity protocols and standards such as SAML, OIDC, OAuth 2.0, SCIM, and LDAP, and a desire to go deep on them
  • Familiarity with least-privilege and role-based access concepts and why they matter
  • Scripting experience in a modern language such as Python, PowerShell, or Go, used to automate tasks or integrate systems
  • Exposure to at least one major cloud provider (AWS, Azure, or GCP) and its IAM model
  • Bachelor's degree in cyber security, computer science, information systems, engineering, or another STEM discipline; OR equivalent hands-on experience
  • Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate to the responsibilities
  • Strong attention to detail, clear written and verbal communication, and a genuine curiosity about how access systems work and break

Nice to Have

  • Entry-level security or identity certifications such as CompTIA Security+, Okta Certified Professional or Administrator, Microsoft SC-300, or equivalent hands-on experience
  • Experience with infrastructure as code (Terraform, CloudFormation, or CDK)
  • Experience with secrets management tooling such as HashiCorp Vault or cloud-native secret stores
  • Exposure to Active Directory, Kerberos, or hybrid on-premise and cloud identity environments
  • Familiarity with identity threat detection concepts (ITDR) or SIEM tooling
  • Personal projects, home labs, or CTF participation that demonstrate hands-on interest in identity or security
  • Prior experience or internship in a defense, aerospace, or other ITAR-regulated environment

Compensation and Benefits

  • Base salary range for this role is $120,000 – $150,000 and equity in the company
  • Salary will be based on several factors including, but not limited to: knowledge and skills, education, and experience level
  • Comprehensive benefits package including paid time off, medical/dental/vision coverage, life insurance, paid parental leave, and many other perks

If you don’t meet 100% of the preferred skills and experience, we encourage you to still apply! Building a spacecraft unlike any other requires a team unlike any other and non-traditional career twists and turns are encouraged!

Standard company text repeated across K2 Space's postings is omitted here.

Similar positions

K2 Space
Verkada
Senior+ IAM Engineer
Verkada · San Mateo, CA United States
Okta
Staff Identity Engineer
Okta · Bellevue, Washington; Chicago, Illinois; Washington, DC
Okta
Manager, Engineering
Okta · Bengaluru, India