Lead Security Architect – Cloud Platform & Network Security
Logos Space- Location
- Mountain View · San Diego
- Workplace
- —
- Employment
- Full Time
- Salary
- —
Posted 21d ago
Lead Security Architect – Cloud Platform & Network Security
Logos Space is a Low Earth Orbit (LEO) satellite system purpose-built to serve the connectivity needs of the commercial enterprise users and government users. We will help fill an important gap in the market, providing resilient, high-performance satellite-based connectivity services to enterprise and government customers worldwide. Business customers have contracts with agreed-upon performance standards for their broadband, and Logos will build these capabilities into the system from the beginning. Speed and reliability are the foundation of the system. Logos is designed to extend cloud and data center network connectivity anywhere in the world to fixed, seaborne, and airborne terminals.
Logos is led by a team of highly experienced engineers with proven track records in the networking and satellite industries.
The Product and Data Link Security team at Logos Space Engineering is responsible for ensuring the success of our network by providing unique levels of security and authentication in space communications. This position is a critical driver of the architecture, overseeing development efforts specific to the security architecture, as well as working with other teams like ground segment and spacecraft systems.
We are seeking engineers who can thrive in a fast-moving environment, comfortable taking vague design ideas and turning them into concrete, testable architecture and secure solutions.
The Role
We are seeking an experienced Lead Security Architect – Cloud Platform & Network Security to spearhead the security architecture for our LEO satellite network infrastructure.
While our DevSecOps team owns software supply chain security and CI/CD vulnerability scanning, this role owns the runtime threat resistance, zero-trust network topology, cryptographic key management, and distributed systems defense across our multi-region cloud, ground stations, and edge software nodes.
Working closely with the Lead, Cloud Platform Software, you will define how our Kubernetes clusters, telemetry pipelines, and SDN control planes withstand real-world cyber threats in hostile or degraded operating environments.
Key Responsibilities
Zero-Trust Workload Identity
Architect and implement identity frameworks (e.g., SPIFFE/SPIRE, mTLS, Service Mesh) to establish cryptographically verified identity for microservices operating across cloud, ground segment nodes, and hybrid edge hardware.
SDN & Control Plane Hardening
Conduct threat modeling and design runtime security controls for our Software-Defined Networking (SDN) stack, protecting routing protocols, control messages, and telemetry streams from spoofing, tampering, and denial-of-service (DoS) attacks.
Runtime Defense & Policy Enforcement
Deploy eBPF-based runtime monitoring (e.g., Tetragon, Falco, Cilium) and policy-as-code admission controllers (OPA/Gatekeeper) to detect and neutralize zero-day exploits, container breakouts, and unauthorized process executions in real time.
Key Ceremonies & PKI Governance
Design, orchestrate, and execute formal cryptographic key ceremonies (multi-party key generation, root CA creation, and secret splitting) to establish trust anchors for root certificate authorities, satellite communication keys, and cloud/ground HSM clusters
Hardware-Backed Key & Cryptographic Management
Oversee the architecture for root-of-trust, Hardware Security Modules (HSMs), TPMs, and Vault clusters managing satellite communications keys, TLS certificates, and secrets lifecycle.
Security Telemetry & Anomaly Detection
Collaborate with the Platform team to embed security observability into high-throughput logging and telemetry pipelines (Kafka, Prometheus, SIEM/SOAR) for automated threat detection and incident response.
Defense & Federal Compliance
Translate rigorous federal and defense cybersecurity mandates (e.g., NIST SP 800-53, CMMC Level 3+, FedRAMP High, DoD IL5/IL6) into technical security designs without compromising platform agility or speed.
Basic Qualifications
Education
Bachelor’s degree in Computer Science, Cybersecurity, Computer Engineering, or equivalent practical experience.
Experience
10+ years in cybersecurity, software engineering, or infrastructure security, with 5+ years architecting security for distributed cloud platform software.
Technical Expertise
Deep understanding of Kubernetes architecture, container isolation, Linux kernel security, and eBPF technology.
Hands-on experience with modern networking protocols, zero-trust architectures, service meshes (Istio/Cilium), and mTLS.
Proficiency writing software or tooling in Go, Rust, or Python.
Hands-on architectural experience with HSMs, TPMs, and enterprise secrets management (e.g., HashiCorp Vault).
Clearance
Ability and willingness to obtain and maintain a Top Secret Clearance.
Preferred Qualifications
Experience securing carrier-grade telecom, aerospace, satellite ground stations, or critical defense network infrastructure.
Demonstrated experience handling threat modeling (STRIDE/ATT&CK) for real-time distributed routing or control plane systems.
Deep knowledge of public cloud security guardrails across AWS, GCP, or Azure alongside hybrid/on-prem deployments.
Skills
- Kubernetes
- mTLS
- PKI
- HashiCorp Vault
- TLS
- Kafka
- Prometheus
- SIEM
- NIST
- FedRAMP
- Linux
- Istio
- Go
- Rust
- Python
- AWS
- GCP
- Azure
More jobs at Logos Space
All 10Senior Control Plane Software Engineer
Logos Space · Mountain View, CA · 9d ago
Lead Security Engineering - Terminals
Logos Space · Mountain View · San Diego · 29d ago
Lead, Control Plane Software
Logos Space · Mountain View, CA · 3mo ago
Sr. Space Vehicle Autonomy Engineer
Logos Space · Mountain View · San Diego · 3mo ago
Senior Flight Software Engineer
Logos Space · Mountain View, CA · 3mo ago
Similar roles
Information Systems Security Manager, Space
Anduril Industries · Costa Mesa, California, United States · USD 146,000–194,000/yr · today
Senior Principal Cyber Information Systems Security Engineer
Saic · San Diego, CA, United States · Charleston, SC, United States · Norfolk, VA, United States · today
Senior Security Engineer, Detection & Response
Flexport · San Francisco, California, United States · USD 206,181–252,000/yr · today
Senior Security Engineer, Detection & Response
Flexport · United States · USD 206,181–252,000/yr · today
Cybersecurity Engineer III
Trace3 · Linthicum Heights, MD · today
Mission Security Engineer
Apex Technology · Los Angeles · today