Back to jobs
New

Security Engineer, Identity and Access Management (IAM)

Los Angeles, CA

K2 is building the largest and highest-power satellites ever flown, unlocking performance levels previously out of reach across every orbit. Backed by over $1 billion in total funding from leading investors including Altimeter Capital, ICONIQ, Kleiner Perkins, Lightspeed Venture Partners, Redpoint Ventures, and T. Rowe Price — and with over $1 billion in signed contracts across commercial and US government customers, we're mass-producing the highest-power satellite platforms ever built for missions from LEO to deep space.

The rise of heavy-lift launch vehicles is shifting the industry from an era of mass constraint to one of mass abundance, and we believe this new era demands a fundamentally different class of spacecraft. Engineered to survive the harshest radiation environments and to fully capitalize on today's and tomorrow's massive rockets, K2 satellites deliver unmatched capability at constellation scale and across multiple orbits.

With multiple launches in 2027 and plans to scale to 100 satellites a year, we're Building Bigger — helping develop the solar system and build toward a Kardashev Type II (K2) civilization. If you are a motivated individual who thrives in a fast-paced environment and you're excited about contributing to the success of a high-growth Series D-funded company, we'd love for you to apply.

The Role 

Identity is the perimeter at K2. Every engineer, every ground and mission system, every SaaS tool and automated pipeline depends on the right people and services holding exactly the access they need and nothing more. As a Security Engineer on the Identity & Access Management team, you'll help build and operate the identity platform that governs authentication and authorization across our corporate, engineering, and mission environments. You'll get hands-on with our identity provider, SSO and federation, phishing-resistant MFA, lifecycle automation, and access reviews, working alongside senior identity engineers who will help you grow from executing well-defined work to owning identity problems end to end. This is a role for someone early in their security career who wants real-world impact: every application you onboard to SSO, every shared credential you retire, and every workflow you automate directly supports our ability to move fast, operate confidently, and deliver breakthrough satellite capabilities. 

Responsibilities 

  • Administer and support the enterprise identity platform, including the identity provider, single sign-on, and directory services across corporate, engineering, and mission environments 
  • Onboard SaaS and internal applications to SSO and automated provisioning using SAML, OIDC, and SCIM, retiring local accounts and shared credentials as you go 
  • Operate and improve identity lifecycle workflows, including joiner, mover, and leaver processes, provisioning and deprovisioning, and access requests 
  • Help drive adoption of phishing-resistant MFA (FIDO2/WebAuthn) and support users through enrollment and rollout 
  • Maintain role-based access groups and entitlements under established least-privilege standards, and flag where access models need to evolve 
  • Support privileged access management operations, including administrator accounts, service accounts, and break-glass credential handling 
  • Assist with secrets management hygiene, including credential rotation for the non-human accounts used by automated pipelines 
  • Help implement and monitor conditional access policies, and escalate anomalies in authentication patterns 
  • Execute access review and certification campaigns and collect the evidence auditors and customers require 
  • Write scripts and contribute to infrastructure as code that automate repetitive identity operations rather than resolving them ticket by ticket 
  • Triage identity-related tickets and incidents, and partner with security operations on investigations involving credential abuse or MFA fatigue attacks 
  • Contribute to identity documentation, runbooks, and standards, and keep them current as the environment changes 

Qualifications 

  • 1–3 years of experience in identity and access management, security engineering, IT systems administration, or a related technical role (internships and co-ops count) 
  • Hands-on experience with an enterprise identity provider (e.g., Okta, Microsoft Entra ID, Ping, or Google Identity), including SSO, MFA, and user or group administration 
  • Foundational understanding of identity protocols and standards such as SAML, OIDC, OAuth 2.0, SCIM, and LDAP, and a desire to go deep on them 
  • Familiarity with least-privilege and role-based access concepts and why they matter 
  • Scripting experience in a modern language such as Python, PowerShell, or Go, used to automate tasks or integrate systems 
  • Exposure to at least one major cloud provider (AWS, Azure, or GCP) and its IAM model 
  • Bachelor's degree in cyber security, computer science, information systems, engineering, or another STEM discipline; OR equivalent hands-on experience 
  • Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate to the responsibilities 
  • Strong attention to detail, clear written and verbal communication, and a genuine curiosity about how access systems work and break 

Nice to Have 

  • Entry-level security or identity certifications such as CompTIA Security+, Okta Certified Professional or Administrator, Microsoft SC-300, or equivalent hands-on experience 
  • Experience with infrastructure as code (Terraform, CloudFormation, or CDK) 
  • Experience with secrets management tooling such as HashiCorp Vault or cloud-native secret stores 
  • Exposure to Active Directory, Kerberos, or hybrid on-premise and cloud identity environments 
  • Familiarity with identity threat detection concepts (ITDR) or SIEM tooling 
  • Personal projects, home labs, or CTF participation that demonstrate hands-on interest in identity or security 
  • Prior experience or internship in a defense, aerospace, or other ITAR-regulated environment 

 

Compensation and Benefits 

  • Base salary range for this role is $120,000 – $150,000 and equity in the company 
  • Salary will be based on several factors including, but not limited to: knowledge and skills, education, and experience level 
  • Comprehensive benefits package including paid time off, medical/dental/vision coverage, life insurance, paid parental leave, and many other perks 

If you don’t meet 100% of the preferred skills and experience, we encourage you to still apply! Building a spacecraft unlike any other requires a team unlike any other and non-traditional career twists and turns are encouraged!

If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.

Export Compliance

As defined in the ITAR, “U.S. Persons” include U.S. citizens, lawful permanent residents (i.e., Green Card holders), and certain protected individuals (e.g., refugees/asylees, American Samoans). Please consult with a knowledgeable advisor if you are unsure whether you are a “U.S. Person.”

The person hired for this role will have access to information and items controlled by U.S. export control regulations, including the export control regulations outlined in the International Traffic in Arms Regulation (ITAR). The person hired for this role must therefore either be a “U.S. person” as defined by 22 C.F.R. § 120.15 or otherwise eligible for a federally issued export control license.

Equal Opportunity

K2 Space is an Equal Opportunity Employer; employment with K2 Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

Create a Job Alert

Interested in building your career at K2 Space ? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State. Learn more about ITAR here.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in K2 Space ’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.