Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
KS
Karman Space & Defense
Senior Cybersecurity Engineer
Job Description
Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.
This role strengthens identity security, privileged access, vulnerability management, and technical remediation across Karmans multi-site environment. You will engineer and continuously improve security controls across Microsoft platforms, endpoints, servers, cloud environments, site technologies, and specialized assets. Working closely with Infrastructure, Business Systems, site teams, and service providers, you will ensure clear ownership, reliable evidence, and sustainable remediation that supports regulated aerospace and defense requirements.
ResponsibilitiesEngineers and improves identity security across Active Directory, Microsoft Entra ID, Microsoft 365 GCC High, cloud platforms, business applications, and related services.
Strengthens identity lifecycle processes, access provisioning, privileged access, multifactor authentication (MFA), conditional access, role-based access control, and non-human identity protections.
Operates and matures enterprise vulnerability management, ensuring authenticated scanning, asset coverage, data quality, prioritization, remediation coordination, and validated closure.
Partners with Infrastructure to enhance endpoint, server, and cloud security through patching, encryption, device management, configuration baselines, detection capabilities, and Microsoft security tools.
Reviews new Microsoft 365, SoftwareasaService (SaaS), cloud, and AI-enabled capabilities for identity, access, logging, and data-handling requirements.
Administers assigned security tools and investigates identity, endpoint, email-security, vulnerability, and logging alerts; supports containment, evidence preservation, and post-incident hardening.
Implements, validates, and documents technical controls supporting CMMC Level 2, NIST SP 800171, DFARS, Controlled Unclassified Information (CUI), and SarbanesOxley (SOX) Information Technology General Controls (ITGC).Supports technical remediation of assessment findings, audit gaps, Plans of Action and Milestones (POA\&Ms), and control failures and participates in walkthroughs, reviews, and assessments.
Reviews technology projects, integrations, deployments, SaaS services, vendor solutions, and M\&A activities for identity, vulnerability, endpoint, and data-exposure risks.
Maintains technical procedures, configurations, remediation guides, metrics, and automation opportunities and mentors IT and security teams to strengthen operating capability.
Required QualificationsBachelors degree in cybersecurity, information technology, computer science, engineering, or a related field; equivalent relevant experience may be considered.7+ years of progressive experience in cybersecurity engineering, identity and access management, vulnerability management, endpoint security, infrastructure security, or related roles.
Hands-on experience with Active Directory, Microsoft Entra ID, Microsoft 365, MFA, conditional access, single sign-on (SSO), privileged access, identity lifecycle processes, and non-human identities.
Experience operating enterprise vulnerabilitymanagement tools, establishing scan coverage, prioritizing risk, coordinating remediation, and validating closure.
Experience with endpoint protection, hardening, patching, device compliance, security monitoring, and the Microsoft security ecosystem.
Working knowledge of Windows endpoint and server security, cloud and network security, segmentation, secure configuration, logging, and incident response.
Experience producing technical control evidence and supporting audits, assessments, or regulated control environments.
Strong troubleshooting, documentation, communication, and cross-functional coordination skills in a fast-paced, multi-site environment.
Preferred QualificationsExperience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
Direct experience with CMMC Level 2, NIST
Experience with Microsoft 365 GCC High and tools such as Defender, Intune, Entra ID, Purview, Sentinel, Tenable, Qualys, Rapid7, or Defender Vulnerability Management.
Experience with privileged access management, password vaulting, security information and event management (SIEM), endpoint detection and response (EDR), email security, and security orchestration.
Experience with mergers and acquisitions (M\&A), site onboarding, identity consolidation, endpoint standardization, and post-acquisition remediation.
Familiarity with firewalls, virtual private networks (VPN), network segmentation, Zero Trust, Center for Internet Security (CIS) benchmarks, specialized assets, and compensatingcontrol design.
Security+, Cybersecurity Analyst (CySA+), Systems Security Certified Practitioner (SSCP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Security Essentials Certification (GSEC), GIAC Certified Incident Handler (GCIH), Microsoft Security, Azure Security Engineer, or comparable certification.
This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.
BenefitsMedical, dental, and vision insurance401(k) with company matchPaid time offHealth Savings Account (HSA) with company contributionFlexible Spending Accounts (FSA)Companypaid life and AD\&D insuranceShort and longterm disability coverageTuition reimbursementKarman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.
This role strengthens identity security, privileged access, vulnerability management, and technical remediation across Karmans multi-site environment. You will engineer and continuously improve security controls across Microsoft platforms, endpoints, servers, cloud environments, site technologies, and specialized assets. Working closely with Infrastructure, Business Systems, site teams, and service providers, you will ensure clear ownership, reliable evidence, and sustainable remediation that supports regulated aerospace and defense requirements.
ResponsibilitiesEngineers and improves identity security across Active Directory, Microsoft Entra ID, Microsoft 365 GCC High, cloud platforms, business applications, and related services.
Strengthens identity lifecycle processes, access provisioning, privileged access, multifactor authentication (MFA), conditional access, role-based access control, and non-human identity protections.
Operates and matures enterprise vulnerability management, ensuring authenticated scanning, asset coverage, data quality, prioritization, remediation coordination, and validated closure.
Partners with Infrastructure to enhance endpoint, server, and cloud security through patching, encryption, device management, configuration baselines, detection capabilities, and Microsoft security tools.
Reviews new Microsoft 365, SoftwareasaService (SaaS), cloud, and AI-enabled capabilities for identity, access, logging, and data-handling requirements.
Administers assigned security tools and investigates identity, endpoint, email-security, vulnerability, and logging alerts; supports containment, evidence preservation, and post-incident hardening.
Implements, validates, and documents technical controls supporting CMMC Level 2, NIST SP 800171, DFARS, Controlled Unclassified Information (CUI), and SarbanesOxley (SOX) Information Technology General Controls (ITGC).Supports technical remediation of assessment findings, audit gaps, Plans of Action and Milestones (POA\&Ms), and control failures and participates in walkthroughs, reviews, and assessments.
Reviews technology projects, integrations, deployments, SaaS services, vendor solutions, and M\&A activities for identity, vulnerability, endpoint, and data-exposure risks.
Maintains technical procedures, configurations, remediation guides, metrics, and automation opportunities and mentors IT and security teams to strengthen operating capability.
Required QualificationsBachelors degree in cybersecurity, information technology, computer science, engineering, or a related field; equivalent relevant experience may be considered.7+ years of progressive experience in cybersecurity engineering, identity and access management, vulnerability management, endpoint security, infrastructure security, or related roles.
Hands-on experience with Active Directory, Microsoft Entra ID, Microsoft 365, MFA, conditional access, single sign-on (SSO), privileged access, identity lifecycle processes, and non-human identities.
Experience operating enterprise vulnerabilitymanagement tools, establishing scan coverage, prioritizing risk, coordinating remediation, and validating closure.
Experience with endpoint protection, hardening, patching, device compliance, security monitoring, and the Microsoft security ecosystem.
Working knowledge of Windows endpoint and server security, cloud and network security, segmentation, secure configuration, logging, and incident response.
Experience producing technical control evidence and supporting audits, assessments, or regulated control environments.
Strong troubleshooting, documentation, communication, and cross-functional coordination skills in a fast-paced, multi-site environment.
Preferred QualificationsExperience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
Direct experience with CMMC Level 2, NIST
SP 800171, DFARS, CUI, SOX ITGC, GCC
High, or exportcontrolled environments.Experience with Microsoft 365 GCC High and tools such as Defender, Intune, Entra ID, Purview, Sentinel, Tenable, Qualys, Rapid7, or Defender Vulnerability Management.
Experience with privileged access management, password vaulting, security information and event management (SIEM), endpoint detection and response (EDR), email security, and security orchestration.
Experience with mergers and acquisitions (M\&A), site onboarding, identity consolidation, endpoint standardization, and post-acquisition remediation.
Familiarity with firewalls, virtual private networks (VPN), network segmentation, Zero Trust, Center for Internet Security (CIS) benchmarks, specialized assets, and compensatingcontrol design.
Security+, Cybersecurity Analyst (CySA+), Systems Security Certified Practitioner (SSCP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Security Essentials Certification (GSEC), GIAC Certified Incident Handler (GCIH), Microsoft Security, Azure Security Engineer, or comparable certification.
This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.
BenefitsMedical, dental, and vision insurance401(k) with company matchPaid time offHealth Savings Account (HSA) with company contributionFlexible Spending Accounts (FSA)Companypaid life and AD\&D insuranceShort and longterm disability coverageTuition reimbursementKarman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$132,304 / year median in California
-4% projected decline