
Senior Software Security Engineer at Loft Federal
Golden, ColoradoFull-timeSoftwarePosted 30 days ago
Apply with PipelineAbout the Role
<div class="content-intro"><div>
<p class="p1"><strong>About Loft Federal</strong></p>
<p class="p3">Loft Federal is committed to delivering the<span class="Apple-converted-space"> </span>U.S. national security space community<span class="Apple-converted-space"> </span>a<span class="Apple-converted-space"> </span>fast, affordable, and streamlined<span class="Apple-converted-space"> </span>pathway to orbit. As a<span class="Apple-converted-space"> </span>wholly owned U.S. subsidiary<span class="Apple-converted-space"> </span>of Loft Orbital Solutions, Inc., we specialize in providing mission-ready space infrastructure with unmatched efficiency.</p>
<p class="p3">At Loft, we empower our team with<span class="Apple-converted-space"> </span>autonomy, ownership, and bold problem-solving opportunities<span class="Apple-converted-space"> </span>while fostering a<span class="Apple-converted-space"> </span>tight-knit, supportive environment. We believe that<span class="Apple-converted-space"> </span>diversity, inclusivity, and community<span class="Apple-converted-space"> </span>are the foundation of an open and innovative culture. We value<span class="Apple-converted-space"> </span>kind, collaborative, and mission-driven teammates<span class="Apple-converted-space"> </span>who excel in<span class="Apple-converted-space"> </span>problem-solving and communication—because great solutions come from great teams.</p>
</div>
<div><strong>Are you ready to embark on this exciting journey with us? </strong></div></div><p><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun" data-ccp-charstyle-defn="{"ObjectId":"ac0262f4-8a9e-5820-b908-2d943c5f7113|1","ClassId":1073872969,"Properties":[201342446,"1",201342447,"5",201342448,"1",201342449,"1",469777841,"Aptos",469777842,"",469777843,"Aptos",469777844,"Aptos",201341986,"1",469769226,"Aptos",268442635,"24",469775450,"normaltextrun",201340122,"1",134233614,"true",469778129,"normaltextrun",335572020,"1",469778324,"Default Paragraph Font"]}">We are seeking a Senior Software Security Engineer to lead the design, implementation, and assessment of the security architecture for our flight and ground software systems. This is not a traditional IT compliance role; you are a hands-on software engineer first, with a deep passion for building security into the core of a product. You will </span><span data-ccp-charstyle="normaltextrun">be responsible for</span><span data-ccp-charstyle="normaltextrun"> everything from hands-on coding of security services to integrating automated controls into our CI/CD pipelines and ensuring our architecture meets the stringent requirements for a government Authority to Operate (ATO).</span></span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<p><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun">You will spend your time writing code, hardening our infrastructure, </span><span data-ccp-charstyle="normaltextrun">participating</span><span data-ccp-charstyle="normaltextrun"> in threat modeling, and mentoring our talented software engineers in secure development practices. You will be the team's expert on balancing </span><span data-ccp-charstyle="normaltextrun">cutting-edge</span><span data-ccp-charstyle="normaltextrun"> security with the very real constraints of embedded </span></span><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun">systems</span></span><span data-contrast="auto"><span data-ccp-charstyle="normaltextrun"> and the compliance demands of NIST and CMMC frameworks.</span></span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<p><strong><span data-contrast="auto">What You'll Do</span></strong><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="12" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><strong><span data-contrast="auto">Architect & Design:</span></strong><span data-contrast="auto"> </span><span data-contrast="auto">Design, develop, and contribute to </span><span data-contrast="auto">the Zero Trust security architecture for our flight software, including services for </span><span data-contrast="auto">authentication/</span><span data-contrast="auto">authorization, cryptographic key management, secure data storage</span><span data-contrast="auto">, and secure transport</span><span data-contrast="auto">.</span><span data-contrast="auto"> Lead the research and evaluation of security features, protocols, and third-party tools to make data-driven architectural decisions.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="12" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><strong><span data-contrast="auto">Harden Mission Infrastructure</span></strong><span data-contrast="auto">: Collaborate with infrastructure teams to secure our </span><span data-contrast="auto">onboard flight software </span><span data-contrast="auto">platform, including hardening </span><span data-contrast="auto">embedded </span><span data-contrast="auto">Linux systems, segmenting </span><span data-contrast="auto">spacecraft </span><span data-contrast="auto">network enclaves, configuring </span><span data-contrast="auto">onboard IAM policies, and mitigating operational cybersecurity risks across the asset lifecycle.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="12" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><strong><span data-contrast="auto">Implement Security Controls in the SDLC:</span></strong><span data-contrast="auto"> Work with the DevOps team to integrate and automate security controls directly into our CI/CD pipelines, including Static/Dynamic Application Security Testing (SAST/DAST), Software Composition Analysis (SCA), SBOM generation, and container vulnerability scanning using tools like SonarQube.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="12" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><strong><span data-contrast="auto">Lead Compliance Efforts:</span></strong><span data-contrast="auto"> Serve as the technical expert for designing and implementing security controls required by NIST SP 800-53 / 800-171 such as encryption, access control, and secure logging. Participate in security architecture reviews, code audits, and threat modeling sessions to identify and remediate vulnerabilities like API weaknesses and supply chain risks. Collaborate with security team and ISSM to prepare systems and documentation for ATO approval.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">What We're Looking For</span></strong><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<p><strong><span data-contrast="auto">Required Skills:</span></strong><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">5+ years of professional experience in software development, with at least 3 years in a security-focused role.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="2"><span data-contrast="auto">Deep understanding of modern security principles, including DevSecOps, Zero Trust, container security, and common threats.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="2"><span data-contrast="auto">Demonstrable expertise in one or more of the following security domains: network security, application security, or cryptography.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="2"><span data-contrast="auto">Technical experience implementing and assessing controls for frameworks such as NIST SP 800-53 / 800-171.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="5" data-aria-level="2"><span data-contrast="auto">Hands-on experience with scripting and programming languages (e.g., Python, Bash, C++).</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="6" data-aria-level="2"><span data-contrast="auto">Strong understanding of Linux systems security and hardening.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="7" data-aria-level="2"><span data-contrast="auto">Experience with container security (Docker, k3s) and vulnerability scanning tools.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="8" data-aria-level="2"><span data-contrast="auto">One or more current, relevant security certifications such as Security+, CySA+, GSEC, CASP, or CISSP.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="9" data-aria-level="2"><span data-contrast="auto">Active security clearance required.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Desired Skills (The more of these you have, the better):</span></strong><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<ul>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2"><span data-contrast="auto">Experience with embedded Linux environments and the challenges of resource-constrained systems (CPU, memory).</span></li>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2">Hands-on experience with service-oriented or message-oriented architectures.</li>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2">Experience in the aerospace, defense, or another high-assurance industry. Particularly those who have written flight software for spacecraft, robotics, and/or autonomous vehicles.</li>
<li data-leveltext="o" data-font="Courier New" data-listid="13" data-list-defn-props="{"335552541":1,"335559685":1440,"335559991":360,"469769226":"Courier New","469769242":[9675],"469777803":"left","469777804":"o","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="2">Experience with Infrastructure as Code (IaC) tools (Terraform, Helm, Ansible).<span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><strong><span data-contrast="auto">Why You'll Want to Work Here</span></strong><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="1" data-aria-level="1"><strong><span data-contrast="auto">High-Impact Mission:</span></strong><span data-contrast="auto"> Your work will directly contribute to the security of critical national space assets.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="2" data-aria-level="1"><strong><span data-contrast="auto">Greenfield Opportunity:</span></strong><span data-contrast="auto"> You will have the authority and autonomy to build a modern security architecture from the ground up, the "right way."</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="3" data-aria-level="1"><strong><span data-contrast="auto">Expert Team:</span></strong><span data-contrast="auto"> You will be a senior member of a small, highly skilled team where your expertise will be valued and your contributions will be immediately visible.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="14" data-list-defn-props="{"335552541":1,"335559685":720,"335559991":360,"469769226":"Symbol","469769242":[8226],"469777803":"left","469777804":"","469777815":"multilevel"}" data-aria-posinset="4" data-aria-level="1"><strong><span data-contrast="auto">Modern Tech Stack:</span></strong><span data-contrast="auto"> We are using a modern, cloud-native-inspired stack </span><span data-contrast="auto">(k3s, NATS, CI/CD) </span><span data-contrast="auto">to solve aerospace's most challenging problems.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></li>
</ul>
<p><span data-contrast="auto">If you are a software engineer who is passionate about security and wants to build trusted systems for a mission that matters, we encourage you to apply.</span><span data-ccp-props="{"134233117":true,"134233118":true,"201341983":0,"335559740":240}"> </span></p><div class="content-pay-transparency"><div class="pay-input"><div class="description"><div><span style="font-size: 14px;">Per Colorado law, we are required to disclose the base compensation range for this role. This range is intentionally wide as we assess individuals based on their unique abilities and experience to find the best fit for our needs. Ultimately, your compensation will be determined by your education, experience, knowledge, skills, and abilities. </span></div>
<div> </div>
<div><span style="font-size: 14px;">In addition to a competitive salary and <a href="https://loftfederal.com/careers/" target="_blank">benefits</a> package, you will find a truly remarkable culture guided by transparency and collaboration and work that is challenging and meaningful. We can't wait to meet you and see what you may add to our team!</span></div></div><div class="title">Salary Range</div><div class="pay-range"><span>$130,000</span><span class="divider">—</span><span>$180,000 USD</span></div></div></div><div class="content-conclusion"><h4>Equal Employment Opportunity & Affirmative Action </h4>
<p>Loft Federal is an Equal Employment Opportunity and Affirmative Action Employer. We consider all qualified applicants for employment without regard to race, color, age, religion, sex, gender identity or expression, sexual orientation, marital status, national origin, ancestry, veteran status, genetic information, disability, pregnancy, or any other legally protected status.</p>
<p><strong>Accessibility & Accommodations</strong></p>
<p>If you require a reasonable accommodation due to a disability when applying for an open position, please contact us at <span style="text-decoration: underline;"><strong><a href="mailto:[email protected]">[email protected]</a></strong></span> for assistance.</p>
<p class="p1"><strong>We Hire for Talent, Not Just Resumes</strong></p>
<div>
<p class="p1">Research shows that while men apply for jobs when they meet about<span class="Apple-converted-space"> </span>60% of the qualifications, women and other underrepresented groups tend to apply only when they meet<span class="Apple-converted-space"> </span>100% of the listed criteria. At Loft Federal, we<span class="Apple-converted-space"> </span>value diverse perspectives, respectful debate, and people who challenge assumptions. If you’re excited about a role but don’t meet every requirement, we strongly encourage you to apply.</p>
</div>
<div>
<p class="p1"><strong>Third-Party Recruiters & Agencies</strong></p>
<strong>No outside recruiters, please. </strong>Loft Federal does not accept unsolicited resumes from headhunters, staffing agencies, or third-party recruiters. We will not pay fees for candidates submitted without a signed agreement in place. </div></div>
Related Roles
Senior Director, Business Development - Intelligence Community
Loft Federal
Golden, CO or Washington, DCDino Aficionado
Loft Federal
Golden, ColoradoSenior Data Scientist, Machine Learning
Serve Robotics
US- remoteRemote2027 Software Engineer Intern
Anduril Industries
Atlanta, Georgia, United States; Boston, Massachusetts, United States; Costa Mesa, California, United States; Irvine, California, United States; Seattle, Washington, United StatesSoftware Validation and Verification (V&V) Engineer
Horizon Surgical Systems
Los Angeles, CaliforniaNetwork Architect
Cerebras Systems
Sunnyvale, CA