Logos Space Logo

Logos Space

Lead Security Architect – Cloud Platform & Network Security

Posted 9 Days Ago
Be an Early Applicant
In-Office
Mountain View, CA, USA
220K-270K Annually
Expert/Leader
In-Office
Mountain View, CA, USA
220K-270K Annually
Expert/Leader
Lead security architecture for a LEO satellite network spanning multi-region cloud, ground stations, and edge nodes. The role owns zero-trust workload identity, SDN and control-plane hardening, runtime defense, policy enforcement, cryptographic key ceremonies, PKI, HSM and TPM architecture, secrets management, security telemetry, and anomaly detection. It translates federal and defense cybersecurity mandates into resilient technical designs and collaborates with platform, ground-segment, and spacecraft teams.
The summary above was generated by AI

Lead Security Architect – Cloud Platform & Network Security

Logos Space is a Low Earth Orbit (LEO) satellite system purpose-built to serve the connectivity needs of the commercial enterprise users and government users. We will help fill an important gap in the market, providing resilient, high-performance satellite-based connectivity services to enterprise and government customers worldwide. Business customers have contracts with agreed-upon performance standards for their broadband, and Logos will build these capabilities into the system from the beginning. Speed and reliability are the foundation of the system. Logos is designed to extend cloud and data center network connectivity anywhere in the world to fixed, seaborne, and airborne terminals.

Logos is led by a team of highly experienced engineers with proven track records in the networking and satellite industries.

The Product and Data Link Security team at Logos Space Engineering is responsible for ensuring the success of our network by providing unique levels of security and authentication in space communications. This position is a critical driver of the architecture, overseeing development efforts specific to the security architecture, as well as working with other teams like ground segment and spacecraft systems.

We are seeking engineers who can thrive in a fast-moving environment, comfortable taking vague design ideas and turning them into concrete, testable architecture and secure solutions.

The Role:

We are seeking an experienced Lead Security Architect – Cloud Platform & Network Security to spearhead the security architecture for our LEO satellite network infrastructure.

While our DevSecOps team owns software supply chain security and CI/CD vulnerability scanning, this role owns the runtime threat resistance, zero-trust network topology, cryptographic key management, and distributed systems defense across our multi-region cloud, ground stations, and edge software nodes.

Working closely with the Lead, Cloud Platform Software, you will define how our Kubernetes clusters, telemetry pipelines, and SDN control planes withstand real-world cyber threats in hostile or degraded operating environments.

Key Responsibilities:

Zero-Trust Workload Identity: Architect and implement identity frameworks (e.g., SPIFFE/SPIRE, mTLS, Service Mesh) to establish cryptographically verified identity for microservices operating across cloud, ground segment nodes, and hybrid edge hardware.

SDN & Control Plane Hardening: Conduct threat modeling and design runtime security controls for our Software-Defined Networking (SDN) stack, protecting routing protocols, control messages, and telemetry streams from spoofing, tampering, and denial-of-service (DoS) attacks.

Runtime Defense & Policy Enforcement: Deploy eBPF-based runtime monitoring (e.g., Tetragon, Falco, Cilium) and policy-as-code admission controllers (OPA/Gatekeeper) to detect and neutralize zero-day exploits, container breakouts, and unauthorized process executions in real time.

Key Ceremonies & PKI Governance: Design, orchestrate, and execute formal cryptographic key ceremonies (multi-party key generation, root CA creation, and secret splitting) to establish trust anchors for root certificate authorities, satellite communication keys, and cloud/ground HSM clusters

Hardware-Backed Key & Cryptographic Management: Oversee the architecture for root-of-trust, Hardware Security Modules (HSMs), TPMs, and Vault clusters managing satellite communications keys, TLS certificates, and secrets lifecycle.

Security Telemetry & Anomaly Detection: Collaborate with the Platform team to embed security observability into high-throughput logging and telemetry pipelines (Kafka, Prometheus, SIEM/SOAR) for automated threat detection and incident response.

Defense & Federal Compliance: Translate rigorous federal and defense cybersecurity mandates (e.g., NIST SP 800-53, CMMC Level 3+, FedRAMP High, DoD IL5/IL6) into technical security designs without compromising platform agility or speed.

Basic Qualifications

Education: Bachelor’s degree in Computer Science, Cybersecurity, Computer Engineering, or equivalent practical experience.

Experience: 10+ years in cybersecurity, software engineering, or infrastructure security, with 5+ years architecting security for distributed cloud platform software.

Technical Expertise:

Deep understanding of Kubernetes architecture, container isolation, Linux kernel security, and eBPF technology.

Hands-on experience with modern networking protocols, zero-trust architectures, service meshes (Istio/Cilium), and mTLS.

Proficiency writing software or tooling in Go, Rust, or Python.

Hands-on architectural experience with HSMs, TPMs, and enterprise secrets management (e.g., HashiCorp Vault).

Clearance: Ability and willingness to obtain and maintain a Top Secret Clearance.

Preferred Qualifications

Experience securing carrier-grade telecom, aerospace, satellite ground stations, or critical defense network infrastructure.

Demonstrated experience handling threat modeling (STRIDE/ATT&CK) for real-time distributed routing or control plane systems.

Deep knowledge of public cloud security guardrails across AWS, GCP, or Azure alongside hybrid/on-prem deployments.

Similar Jobs

15-20 Hourly
Junior
eCommerce • Fashion • Retail • Sales • Wearables • Design
Provides customer service and sales support in a luxury retail store. Responsibilities include welcoming clients, operating POS and cash wrap, suggesting products, processing shipments and transfers, maintaining stock levels, replenishing the sales floor, executing visual merchandising updates, supporting social media engagement, and following housekeeping and loss-prevention procedures. Requires flexible availability, physical ability to handle stockroom and sales-floor tasks, and strong communication and organizational skills.
Top Skills: InternetIpadLaptopMobile PosPosWalkie-Talkie
3 Hours Ago
In-Office
99K-162K Annually
Senior level
99K-162K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Develop and execute ASIC, FPGA, and SoC design verification activities using simulation, SystemVerilog, UVM, coverage analysis, debugging, requirements traceability, reusable verification infrastructure, and UVCs. Support integration and system-level investigations, contribute to coverage closure, communicate risks and dependencies, and progressively own verification scope of moderate complexity. Level II engineers develop independence, while Level III engineers independently manage assigned verification scope.
Top Skills: AsicFpgaOopRtlSimulationSocSystemverilogUvcUvm
3 Hours Ago
In-Office
99K-162K Annually
Mid level
99K-162K Annually
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Designs and supports ASIC, FPGA, and mixed digital systems for aerospace and defense programs. Responsibilities include requirements development, architecture support, HDL/RTL development, simulation, debugging, synthesis, FPGA implementation, timing analysis, verification collaboration, integration, troubleshooting, and technical status communication. The role may involve owning functional blocks, supporting subsystem efforts, and contributing to cross-functional technical leadership depending on experience level.
Top Skills: AsicClock-Domain Crossing (Cdc)FpgaHdlRtlSocStatic Timing AnalysisVlsi

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account