Senior Software Security Engineer
About Loft Federal
Loft Federal is committed to delivering the U.S. national security space community a fast, affordable, and streamlined pathway to orbit. As a wholly owned U.S. subsidiary of Loft Orbital Solutions, Inc., we specialize in providing mission-ready space infrastructure with unmatched efficiency.
At Loft, we empower our team with autonomy, ownership, and bold problem-solving opportunities while fostering a tight-knit, supportive environment. We believe that diversity, inclusivity, and community are the foundation of an open and innovative culture. We value kind, collaborative, and mission-driven teammates who excel in problem-solving and communication—because great solutions come from great teams.
Are you ready to embark on this exciting journey with us?
We are seeking a Senior Software Security Engineer to lead the design, implementation, and assessment of the security architecture for our flight and ground software systems. This is not a traditional IT compliance role; you are a hands-on software engineer first, with a deep passion for building security into the core of a product. You will be responsible for everything from hands-on coding of security services to integrating automated controls into our CI/CD pipelines and ensuring our architecture meets the stringent requirements for a government Authority to Operate (ATO).
You will spend your time writing code, hardening our infrastructure, participating in threat modeling, and mentoring our talented software engineers in secure development practices. You will be the team's expert on balancing cutting-edge security with the very real constraints of embedded systems and the compliance demands of NIST and CMMC frameworks.
What You'll Do
- Architect & Design: Design, develop, and contribute to the Zero Trust security architecture for our flight software, including services for authentication/authorization, cryptographic key management, secure data storage, and secure transport. Lead the research and evaluation of security features, protocols, and third-party tools to make data-driven architectural decisions.
- Harden Mission Infrastructure: Collaborate with infrastructure teams to secure our onboard flight software platform, including hardening embedded Linux systems, segmenting spacecraft network enclaves, configuring onboard IAM policies, and mitigating operational cybersecurity risks across the asset lifecycle.
- Implement Security Controls in the SDLC: Work with the DevOps team to integrate and automate security controls directly into our CI/CD pipelines, including Static/Dynamic Application Security Testing (SAST/DAST), Software Composition Analysis (SCA), SBOM generation, and container vulnerability scanning using tools like SonarQube.
- Lead Compliance Efforts: Serve as the technical expert for designing and implementing security controls required by NIST SP 800-53 / 800-171 such as encryption, access control, and secure logging. Participate in security architecture reviews, code audits, and threat modeling sessions to identify and remediate vulnerabilities like API weaknesses and supply chain risks. Collaborate with security team and ISSM to prepare systems and documentation for ATO approval.
What We're Looking For
Required Skills:
- 5+ years of professional experience in software development, with at least 3 years in a security-focused role.
- Deep understanding of modern security principles, including DevSecOps, Zero Trust, container security, and common threats.
- Demonstrable expertise in one or more of the following security domains: network security, application security, or cryptography.
- Technical experience implementing and assessing controls for frameworks such as NIST SP 800-53 / 800-171.
- Hands-on experience with scripting and programming languages (e.g., Python, Bash, C++).
- Strong understanding of Linux systems security and hardening.
- Experience with container security (Docker, k3s) and vulnerability scanning tools.
- One or more current, relevant security certifications such as Security+, CySA+, GSEC, CASP, or CISSP.
- Active security clearance required.
Desired Skills (The more of these you have, the better):
- Experience with embedded Linux environments and the challenges of resource-constrained systems (CPU, memory).
- Hands-on experience with service-oriented or message-oriented architectures.
- Experience in the aerospace, defense, or another high-assurance industry. Particularly those who have written flight software for spacecraft, robotics, and/or autonomous vehicles.
- Experience with Infrastructure as Code (IaC) tools (Terraform, Helm, Ansible).
Why You'll Want to Work Here
- High-Impact Mission: Your work will directly contribute to the security of critical national space assets.
- Greenfield Opportunity: You will have the authority and autonomy to build a modern security architecture from the ground up, the "right way."
- Expert Team: You will be a senior member of a small, highly skilled team where your expertise will be valued and your contributions will be immediately visible.
- Modern Tech Stack: We are using a modern, cloud-native-inspired stack (k3s, NATS, CI/CD) to solve aerospace's most challenging problems.
If you are a software engineer who is passionate about security and wants to build trusted systems for a mission that matters, we encourage you to apply.
Salary Range
$130,000 - $180,000 USD
Equal Employment Opportunity & Affirmative Action
Loft Federal is an Equal Employment Opportunity and Affirmative Action Employer. We consider all qualified applicants for employment without regard to race, color, age, religion, sex, gender identity or expression, sexual orientation, marital status, national origin, ancestry, veteran status, genetic information, disability, pregnancy, or any other legally protected status.
Accessibility & Accommodations
If you require a reasonable accommodation due to a disability when applying for an open position, please contact us at recruiting@loftfederal.com for assistance.
We Hire for Talent, Not Just Resumes
Research shows that while men apply for jobs when they meet about 60% of the qualifications, women and other underrepresented groups tend to apply only when they meet 100% of the listed criteria. At Loft Federal, we value diverse perspectives, respectful debate, and people who challenge assumptions. If you’re excited about a role but don’t meet every requirement, we strongly encourage you to apply.
Third-Party Recruiters & Agencies
No outside recruiters, please. Loft Federal does not accept unsolicited resumes from headhunters, staffing agencies, or third-party recruiters. We will not pay fees for candidates submitted without a signed agreement in place.Create a Job Alert
Interested in building your career at Loft Federal? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field

