Senior Security Engineer, Identity and Access Management (IAM)
at K2 Space · 101-250 employees
- Seniority
- Senior
- Location
- Los Angeles, CA
- Posted
- 5d ago
at K2 Space · 101-250 employees
K2 Space is a manufacturer of large, high-power satellites.
<div class="content-intro"><p class="p1">K2 is building the largest and highest-power satellites ever flown, unlocking performance levels previously out of reach across every orbit. Backed by <a href="https://www.forbes.com/sites/aliciapark/2025/12/11/this-startup-is-building-huge-satellites-for-an-underused-interstellar-sweet-spot/?ctpv=searchpage">$450M</a> from leading investors including Altimeter Capital, Redpoint Ventures, T. Rowe Price, Lightspeed Venture Partners, Alpine Space Ventures, and others <span class="s1">– </span>with an additional $500M in signed contracts across commercial and US government customers – we’re mass-producing the highest-power satellite platforms ever built for missions from LEO to deep space.<span class="Apple-converted-space"> </span></p> <p class="p1">The rise of heavy-lift launch vehicles is shifting the industry from an era of mass constraint to one of mass abundance, and we believe this new era demands a fundamentally different class of spacecraft. Engineered to survive the harshest radiation environments and to fully capitalize on today’s and tomorrow’s massive rockets, K2 satellites deliver unmatched capability at constellation scale and across multiple orbits.<span class="Apple-converted-space"> </span></p> <p class="p1">With multiple launches planned through 2026 and 2027, we're Building Bigger to develop the solar system and become a Kardashev Type II (K2) civilization. <span class="TextRun SCXW79998266 BCX0" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW79998266 BCX0">If you are a motivated individual who thrives in a fast-paced environment and </span><span class="NormalTextRun SCXW79998266 BCX0">you're</span><span class="NormalTextRun SCXW79998266 BCX0"> excited about contributing to the success of a groundbreaking Series C</span><span class="NormalTextRun SCXW79998266 BCX0"> space startup, </span><span class="NormalTextRun SCXW79998266 BCX0">we’d</span><span class="NormalTextRun SCXW79998266 BCX0"> love for you to apply.</span></span><span class="EOP SCXW79998266 BCX0" data-ccp-props="{"335559738":240,"335559739":240}"> </span></p></div><p><strong><span data-contrast="none">The Role</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <p><span data-contrast="auto">Identity is the perimeter at K2. Every engineer, every ground and mission system, every SaaS tool and automated pipeline depends on the right people and services holding exactly the access they need and nothing more. This role owns that problem end to end: you’ll design, build, and run the identity platform that governs authentication and authorization across our corporate, engineering, and mission environments. You’ll be deeply hands-on with our identity provider, SSO and federation, phishing-resistant MFA, lifecycle automation, privileged access, and secrets management, and you’ll retire the standing access and shared credentials that accumulate in any fast-growing company. This is a role for someone who thrives on real-world impact: making least privilege the default without slowing down the teams building spacecraft. Every access path you close and every workflow you automate directly supports our ability to move fast, operate confidently, and deliver breakthrough satellite capabilities.</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <p><strong><span data-contrast="none">Responsibilities</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <ul> <li><span data-contrast="auto">Own and mature the enterprise identity platform, including the identity provider, single sign-on, federation, and directory services across corporate, engineering, and mission environments</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Design and implement authentication standards using modern protocols such as SAML, OIDC, OAuth 2.0, and SCIM, and drive adoption of phishing-resistant MFA including FIDO2 and WebAuthn</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Build and automate identity lifecycle management, including joiner, mover, and leaver workflows, provisioning and deprovisioning, and just-in-time access</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Design and maintain role-based and attribute-based access models, entitlement structures, and least-privilege standards for corporate and engineering systems</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Implement and operate privileged access management for administrators, service accounts, and break-glass credentials</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Manage machine and workload identity, including secrets management, credential rotation, and the non-human accounts used by automated pipelines and mission systems</span><span data-ccp-props="{"134233117":false,"1342331