← Back to results

Security Engineer (Vulnerability Management)

Join SpaceX as a Security Engineer focusing on vulnerability management to protect critical systems and support the mission to enable human life on Mars.

Location
Starbase, TX, United States
Compensation
Not disclosed
Level
mid
Type
full time · On-site

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

What you'll build

  • Develop tools and processes for security adoption
  • Conduct software code reviews
  • Perform web application security testing
  • Triage and validate Bugcrowd reports
  • Conduct continuous threat assessment

Must have

  • Bachelor's degree in computer science or STEM discipline
  • 2+ years of professional experience in security software development
  • Experience with Python, GO, C#, C/C++, or Rust
  • Experience designing and implementing security solutions

Nice to have

  • Experience identifying, assessing, and remediating vulnerabilities
  • Scripting/automation experience
  • Strong understanding of networking fundamentals
  • Reverse engineering or vulnerability development experience
  • Experience with web application testing frameworks

Practical constraints

  • Must be willing to work extended hours and/or weekends as needed
  • This role requires you to be onsite

Requirements

Experience
2+ years
Education
Bachelor's degree
Visa
No sponsorship (stated in posting)

Not disclosed in this posting: compensation.

Joblaze summary

In the role of Security Engineer focused on Vulnerability Management at SpaceX, the individual will engage in daily tasks such as identifying and remediating security vulnerabilities while collaborating closely with software development teams. Proficiency in programming languages like Python and experience with security solutions for large-scale systems are crucial for success. This position is well-suited for candidates with a solid background in security engineering and hands-on experience in vulnerability assessment. The role emphasizes strong communication skills to translate technical findings into actionable insights.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 26, 2026. Last confirmed on SpaceX's careers page September 26, 2026.
  • Python appears in 43.5% of 193 comparable mid security roles in United States; Bugcrowd appears in 0.5% of 193 comparable mid security roles in United States.

Quick facts

Is the Security Engineer (Vulnerability Management) role remote?
No — this is an on-site role in Starbase, TX, United States.
How much experience is required?
At least 2 years of relevant experience for this Security Engineer (Vulnerability Management) role.
Where is the role based?
SpaceX is hiring for this position in Starbase, TX, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Azure, Bugcrowd, C++, C/C++, GCP.
What seniority level is this role?
SpaceX targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Security Engineer (Vulnerability Management) role at SpaceX.

From the original posting

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.

SECURITY ENGINEER (VULNERABILITY MANAGEMENT)

SpaceX is looking for a Security Engineer to join our Information Security department to help protect and drive the SpaceX mission.

Information drives our business and we must protect the confidentiality, integrity, and availability of systems and processes across the enterprise. As a highly visible and dynamic organization, we must also value and guard against damage to our reputation and brand. It is paramount that we defend against loss of control or confidence in our systems, to guarantee the highest probability of success.

As a member of the SpaceX Vulnerability Management team, the Security Engineer will act as a trusted partner to application software development teams. This role focuses on identifying, assessing, and remediating vulnerabilities and threats while developing and maintaining internal security tools. The role also includes hands-on work triaging bug reports, conducting Purple and Red Team activities, and continuous threat hunting. Strong communication skills and the ability to turn technical findings into practical, actionable guidance are essential.

RESPONSIBILITIES:

  • Development of tools, processes, and guidance that make security easier to adopt without slowing delivery.
  • Conduct software code reviews to identify insecure patterns and help teams remediate issues.
  • Perform web application security testing using established frameworks and tools.
  • Triage and validate Bugcrowd reports, coordinate with researchers, and work directly with internal teams on remediation and disclosure.
  • Perform Purple Team exercises to test controls, improve detection, and close identified gaps.
  • Contribute to Red Team operations or simulations, including scoping, execution support, and post-exercise analysis.
  • Build and operate emerging vulnerability communication processes so teams receive timely, actionable alerts on new threats.
  • Conduct continuous threat assessment by folding threat intelligence, emerging vulnerabilities, and attack trends into scanning coverage, notifications, and prioritization.
  • Partner with other security sub-teams (detection/response, compliance, application security, infrastructure) to keep efforts consistent and reduce duplication.
  • Escalate critical or time-sensitive issues promptly while offering practical mitigation options.
  • Document findings, produce metrics, and provide regular risk summaries to leadership.

BASIC QUALIFICATIONS:

  • Bachelor's degree in computer science or another STEM discipline; OR 2+ years of professional experience in security software development in lieu of a degree.
  • Experience with the Python programming language, GO, C#, C/C++, or Rust.
  • Experience designing and implementing security solutions for operating systems, distributed systems, or other enterprise/large-scale infrastructure.

PREFERRED SKILLS AND EXPERIENCE:

  • Experience identifying, assessing, and remediating vulnerabilities (applications, infrastructure, or cloud).
  • Experience working directly with engineering teams to close findings.
  • Scripting/automation experience (Python, Bash, PowerShell, or similar) and the ability to develop internal tools.
  • Strong understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, firewalls) and how they relate to vulnerability exposure.
  • Reverse engineering or vulnerability development experience.
  • Experience triaging or working reports from bug bounty platforms (Bugcrowd, HackerOne, or similar).
  • Hands-on participation in Purple Team or Red Team exercises.
  • OT Security Experience.
  • Experience with continuous threat assessment, threat intelligence, or risk-based vulnerability prioritization.
  • Experience developing internal security tools, dashboards, or automation pipelines (production-quality code, integrations, etc.).
  • Experience with web application testing frameworks and tools.
  • Experience performing software code reviews for security issues.
  • Experience improving developer experience around security tooling and processes.
  • Knowledge of network segmentation principles and implementation.
  • Experience with asset discovery or inventory processes.
  • Experience building or operating emerging vulnerability notification/alerting workflows.
  • Familiarity with AI/LLMs and MCPs.
  • Familiarity with cloud environments (AWS, Azure, GCP) and their native security/vulnerability features.
  • Experience with configuration management, patching, or infrastructure-as-code.
  • Knowledge of threat modeling, risk scoring (e.g., CVSS), and prioritization frameworks.
  • Familiarity with enterprise security controls and best practices for Windows, Linux, and macOS.
  • Strong communication skills with the ability to translate technical findings into business impact and concrete remediation steps.
  • Relevant certifications (e.g., OSCP, GSEC, or equivalent) or demonstrated equivalent experience.
  • Demonstrable problem-solving skills and ability to quickly determine root causes of issues.

ADDITIONAL REQUIREMENTS:

  • Must be willing to work extended hours and/or weekends as needed.
  • This role requires you to be onsite. Hybrid or remote work will not be considered.

ITAR REQUIREMENTS:

Standard company text repeated across SpaceX's postings is omitted here.

Similar positions

SpaceX
Security Engineer (Red Team)
SpaceX · Starbase, TX, United States
SpaceX
Security Engineer
SpaceX · Cape Canaveral, FL
SpaceX
Security Engineer
SpaceX · Hawthorne, CA
SpaceX
Security Engineer (Blue Team)
SpaceX · Redmond, WA
SpaceX