首席云安全工程师
查看雇主原标题
Principal Cloud Security EngineerRocket Lab · Long Beach, CA
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
职位描述
机器翻译关于 ROCKET LAB
Rocket Lab 是一家端到端太空公司,制造火箭、航天器以及关键子系统,让世界保持互联、受到保护,并将人类的足迹拓展至月球、火星乃至更远的地方。我们行动迅速,为有意义的任务打造真正的硬件,让不可能成为常态。来与我们一起塑造未来吧。
IT
Rocket Lab 的 IT 团队负责我们全球团队如何访问信息,以及如何在我们所有的计算机系统、网络和设备上开展运营。我们勤奋的 IT 团队是一群灵活的问题解决者,他们在快节奏的环境中工作,同时也在支持我们所有专有系统和人员(从财务到发射运营)的挑战中茁壮成长。
首席云安全工程师
该首席云安全工程师岗位驻于 Rocket Lab 位于加州长滩的办公室现场办公,必须展现出对云优先、自动化、API 驱动的安全以及统计风险概念与沟通的扎实掌握。他们将致力于保障 Rocket Lab 云资产各个方面的安全:各类供应商服务、部署到生产环境和非生产环境的代码流水线,以及执行各种业务关键操作的自动化。他们将向负有受托责任的业务伙伴提供分析,包括有关 IT 和网络安全风险的可量化统计信息。他们将支持 IT 组织开发一个安全、可靠且极其高效的平台,以助力 Rocket Lab 作为一家快速成长的跨国太空公司实现其目标。
你将有机会做的事情:
• 为混合云环境设计和实施安全控制并加以维护,包括基础设施即服务(IaaS)、平台即服务(PaaS)、软件即服务(SaaS)和函数即服务(FaaS)解决方案。
• 为实现网络团队目标而设计和开发定制自动化。
• 为与安全相关的内部和外部设计评审提供安全支持。
• 开展安全评估和风险分析,以识别漏洞,并为自动化基础设施(如公有云、CI/CD 流水线和智能体系统)制定缓解策略。
• 与基础设施运营团队合作,实施和管理身份与访问管理(IAM)解决方案,以控制对云资源和应用程序的访问。
• 为网络安全相关的平台改进编写文档、计划和概念验证。
• 配置并监控云安全工具和服务。
• 与开发团队协作,将安全最佳实践融入软件开发生命周期(SDLC)、DevOps 和 MLOps 流程。
• 维护相关系统,帮助团队及时了解与 DevSecOps/MLOps 相关的新兴威胁、漏洞和行业最佳实践,并建议采取主动措施以增强安全态势。
• 就安全相关事项向内部团队提供指导和支持,包括事件响应、合规和安全意识培训。
• 参与定期的安全审计、评估和合规审查,以确保符合监管要求和行业标准。
任职要求
• IT 和网络安全方面的教育与经验 • 12 年以上脚本语言(例如 Bash、PowerShell、Python)以及配置管理/基础设施即代码工具(例如 Puppet、Ansible、Terraform)方面的经验。
• 学士学位或同等年限的工作经验(总计 16 年以上工作经验)
• 云安全与架构专长 • 在主要云平台(AWS、Azure、Google Cloud)上拥有云安全架构、设计和实施方面的成熟经验。
• 具备云安全工具和服务的实操经验(例如 AWS Security Hub、Azure Security Center、Google Cloud Security Command Center)。
• 合规、漏洞管理与 IT 治理 • 具有在美国政府合规制度(例如 CMMC、NIST、DISA STIG)以及 ITIL/变更审查系统下工作的经验。
• 熟练掌握漏洞管理系统(例如 Tenable、Bringa)和 CLI 扫描工具(例如 Trivy、OpenSCAP)。
• 版本控制、网络与安全通信 • 拥有 git 驱动的版本控制系统(例如 GitHub、GitLab、Bitbucket)方面的丰富经验。
• 对网络概念、加密技术和安全通信协议有深入理解。
• 数据与分析专长 • 具有数据库(例如 PostgreSQL、SQLite)和数据格式(例如 Parquet、Arrow)方面的经验。
• 熟练掌握分析系统(例如 PowerBI、Jupyter)和供应商无关的评估引擎(例如 Cloud Custodian、Panther)。
• 由于项目要求,需要美国公民身份。
具备以下资格将更佳:
• 计算机科学、信息技术、网络安全或同等职业经验方面的高级学位
• 参与社区网络安全组织
• AWS GovCloud / Azure GCC High
• CI/CD 流水线安全
• 二级云供应商
• 混合云工程
• SAST 和 DAST 测试
• 机密管理 / 保险库 / HSM
• 云事件响应 / 取证
• 日志聚合器,如 Graylog、ELK 或 Splunk
该职位可能需要长时间坐着、站立、行走、进行计算机工作,并偶尔在生产区域接触中等水平的噪音、粉尘和烟雾。 加入全球增长最快的太空公司之一,并拥有它的一部分。除了具有竞争力的基本薪资外,你还将获得公司股票作为总薪酬方案的一部分,让你直接分享我们的成功。随着我们扩展到新的发射场、开创性的任务和全球市场,你的所有权有机会与公司一同增长。
我们全面的福利方案包括行业领先的员工股票购买计划(公司股票 15% 折扣)、顶级医疗计划(HMO、PPO,以及零费用 HDHP 选项并附带可观的 HSA 公司缴款)、牙科和视力保险、带薪休假和病假、11 个带薪假日、灵活支出和受抚养人照护账户、带薪育儿假、残疾和人寿保险,以及公司匹配的 401(k) 退休计划。
其他福利包括补贴的电动汽车充电、现场健身中心(如可用)、健身房会员折扣、免费零食和饮料、我们热门周边商店的员工 50% 折扣,以及各种其他员工折扣。
职级和基本薪资将根据具体情况确定,并可能因以下因素而有所不同:与工作相关的知识和技能、教育和经验。
薪资
$152,300 — $165,000 USD
你将体验到什么
我们的使命是释放太空的潜力,以改善地球上的生活,但这并非易事。它需要努力工作、决心、不懈创新、团队合作、毅力,以及坚定不移地致力于实现他人常常认为不可能的事情。我们的员工思考更胜一筹、工作更加努力、节奏更快。我们以彼此支持、放下自我、无论任务大小都撸起袖子加油干而自豪。我们在压力下茁壮成长,在紧迫的期限内工作,我们的关注点始终是我们如何交付,而不是纠结于阻碍我们的挑战。
重要信息:
仅适用于希望在美国办公室工作的候选人:
为遵守美国政府太空技术出口法规,包括《国际武器贸易条例》(ITAR),Rocket Lab 员工必须是美国公民、合法的美国永久居民(即当前绿卡持有者),或作为难民合法入境美国或获得庇护,或符合资格获得美国国务院和/或美国商务部(如适用)所需授权。在此处了解有关 ITAR 的更多信息。
Rocket Lab 为所有员工和求职者提供平等的就业机会,并禁止任何类型的歧视和骚扰,不论种族、肤色、宗教、年龄、性别、国籍、残疾状况、遗传信息、受保护的退伍军人身份、性取向、性别认同或表达,或任何其他受联邦、州或地方法律保护的特征。本政策适用于 Rocket Lab 的所有雇佣条款和条件,包括招聘、录用、安置、晋升、解雇、裁员、召回、调动、休假、薪酬和培训。
在美国申请职位时,因申请/面试流程需要合理便利的申请人,请联系 Giulia Johnson,邮箱 g.biow@rocketlabusa.com。此专用资源仅用于帮助因残疾而无法申请/面试的残障求职者。仅会考虑为此目的留下的信息。对您请求的回复可能需要最多两个工作日。
仅适用于希望在新西兰办公室工作的候选人:
出于安全原因,在向申请人发出任何录用通知之前,将进行背景调查。这些调查将包括国籍核查,因为该职位要求您有资格访问受美国《国际武器贸易条例》管制的设备和数据。
根据这些条例,如果您不持有澳大利亚、日本、新西兰、瑞士、欧盟或北约成员国的公民身份,或者如果您持有不符合资格的双重公民身份或国籍,您可能不符合该职位的资格。有关这些条例的更多信息,请点击此处 ITAR Regulations。
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
ABOUT ROCKET LAB
Rocket Lab is the end-to-end space company building rockets, spacecraft, and critical subsystems that keep the world connected, protected, expand humanity’s reach to the Moon, Mars, and beyond. We move fast, build real hardware for meaningful missions, and make the impossible routine. Come shape the future with us.
IT
Rocket Lab’s IT team is responsible for how our global teams access information and run operations across our computer systems, networks, and devices. Our hardworking IT team is a group of flexible problem-solvers working in a fast-paced environment but who also thrive under the challenge of supporting all of our proprietary systems and people, from finance to launch operations.
PRINCIPAL CLOUD SECURITY ENGINEER
Based onsite at Rocket Lab's office in Long Beach, CA the Principal Cloud Security Engineer must demonstrate a firm grasp of cloud-first, automated, API-driven security and statistical risk concepts and communication. They will work on securing all facets of Rocket Lab’s cloud presence: the wide array of vendor services, code pipelines deploying into prod and non-prod environments, and automation performing an assortment of business-critical operations. They will provide analyses including quantifiable statistical information regarding IT and Cybersecurity risk to business partners with fiduciary responsibility. They will support the IT organization to develop a secure, reliable, and fiercely efficient platform to empower the Rocket Lab’s objectives as a rapidly growing multinational space company.
WHAT YOU’LL GET TO DO:
• Design, implement, and maintain security controls for hybrid cloud-based environments, including infrastructure as a service (IaaS), platform as a service (PaaS), software as a service (SaaS), and function as a service (FaaS) solutions.
• Design and develop custom automation in pursuit of cyber team objectives.
• Provide security support for internal and external design reviews related to security.
• Conduct security assessments and risk analyses to identify vulnerabilities and develop mitigation strategies for automated infrastructure such as public cloud, CI/CD pipelines, and agentic systems.
• Work with Infrastructure Operations to Implement and manage identity and access management (IAM) solutions to control access to cloud resources and applications.
• Develop documentation, plans, and proofs of concept for cybersecurity-related platform improvements.
• Configure and monitor cloud security tools and services.
• Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC), DevOps, and MLOps processes.
• Maintain systems to help the team stay up-to-date on emerging threats, vulnerabilities, and industry best practices related to DevSecOps/MLOps and recommend proactive measures to enhance security posture.
• Provide guidance and support to internal teams on security-related matters, including incident response, compliance, and security awareness training.
• Participate in regular security audits, assessments, and compliance reviews to ensure adherence to regulatory requirements and industry standards.
任职要求
• Education and Experience in IT and Cybersecurity • 12+ years of experience in scripting languages (e.g., Bash, PowerShell, Python) and configuration management/infrastructure as code tools (e.g., Puppet, Ansible, Terraform).
• Bachelor’s degree or equivalent years of work experience (16+ years of total work experience)
• Cloud Security and Architecture Expertise • Proven experience in cloud security architecture, design, and implementation across major cloud platforms (AWS, Azure, Google Cloud).
• Hands-on experience with cloud security tools and services (e.g., AWS Security Hub, Azure Security Center, Google Cloud Security Command Center).
• Compliance, Vulnerability Management, and IT Governance • Experience working under US Government compliance regimes (e.g., CMMC, NIST, DISA STIG) and ITIL/Change Review systems.
• Proficiency in vulnerability management systems (e.g., Tenable, Bringa) and CLI scanning tools (e.g., Trivy, OpenSCAP).
• Version Control, Networking, and Secure Communication • Extensive experience with git-driven version control systems (e.g., GitHub, GitLab, Bitbucket).
• Strong understanding of networking concepts, encryption techniques, and secure communication protocols.
• Data and Analytics Expertise • Experience with databases (e.g., PostgreSQL, SQLite) and data formats (e.g., Parquet, Arrow).
• Proficiency in analytics systems (e.g., PowerBI, Jupyter) and vendor-agnostic assessment engines (e.g., Cloud Custodian, Panther).
• U.S. citizenship is required, due to program requirements.
THESE QUALIFICATIONS WOULD BE NICE TO HAVE:
• Advanced degree in computer science, information technology, cybersecurity, or equivalent career experience
• Involvement with community cybersecurity organizations
• AWS GovCloud / Azure GCC High
• CI/CD pipeline security
• Tier 2 cloud vendors
• Hybrid cloud engineering
• SAST and DAST testing
• Secrets management / vaults / HSMs
• Cloud incident response / forensics
• Log aggregators like Graylog, ELK, or Splunk
This position may require prolonged periods of sitting, standing, walking, computer work, and occasional exposure to moderate levels of noise, dust, and fumes in production areas. Join one of the world's fastest-growing space companies and own a piece of it. In addition to competitive base pay, you'll receive company stock as part of your total compensation package , giving you a direct stake in our success. As we expand to new launch sites, groundbreaking missions, and global markets, your ownership has the opportunity to grow alongside the company.
Our comprehensive benefits package includes our industry-leading Employee Stock Purchase Program (with a 15% discount on company stock), top-tier medical plans (HMO, PPO, and a zero cost HDHP option with a significant HSA company contribution), dental and vision coverage, paid vacation and sick time, 11 paid holidays, flexible spending and dependent care accounts, paid parental leave, disability and life insurance, and a 401(k) retirement plan with company match.
Additional perks include subsidized EV charging, onsite fitness centers (where available), discounted gym memberships, complimentary snacks and beverages, 50% employee discount on our popular merch store, and a variety of other employee discounts.
Level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience.
薪资
$152,300 — $165,000 USD
WHAT TO EXPECT
We’re on a mission to unlock the potential of space to improve life on Earth, but that’s not an easy task. It takes hard work, determination, relentless innovation, teamwork, grit, and an unwavering commitment to achieving what others often deem impossible. Our people out-think, out-work, and out-pace. We pride ourselves on having each other’s backs, checking our egos at the door, and rolling up our sleeves on all tasks big and small. We thrive under pressure, work to tight deadlines, and our focus is always on how we can deliver, rather than dwelling on the challenges that stand in the way.
Important information:
FOR CANDIDATES SEEKING TO WORK IN US OFFICES ONLY:
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR), Rocket Lab Employees must be a U.S. citizen, lawful U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum, or be eligible to obtain the required authorizations from the U.S. Department of State and/or the U.S. Department of Commerce, as applicable. Learn more about ITAR here .
Rocket Lab provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This policy applies to all terms and conditions of employment at Rocket Lab, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Applicants requiring a reasonable accommodation for the application/interview process for a job in the United States should contact Giulia Johnson at g.biow@rocketlabusa.com. This dedicated resource is intended solely to assist job seekers with disabilities whose disability prevents them from being able to apply/interview. Only messages left for this purpose will be considered. A response to your request may take up to two business days.
FOR CANDIDATES SEEKING TO WORK IN NEW ZEALAND OFFICES ONLY:
For security reasons, background checks will be undertaken prior to any employment offers being made to an applicant. These checks will include nationality checks as it is a requirement of this position that you be eligible to access equipment and data regulated by the United States' International Traffic in Arms Regulations.
Under these Regulations, you may be ineligible for this role if you do not hold citizenship of Australia, Japan, New Zealand, Switzerland, the European Union, or a country that is part of NATO, or if you hold ineligible dual citizenship or nationality. For more information on these Regulations, click here ITAR Regulations.