About the job
At Spire, we are enhancing our approach to security engineering on a robust foundation, featuring a standardized AWS developer platform, a well-established toolchain for satellite software, ISO 27001 certification, and ongoing collaborations with government customers worldwide. In our pursuit of achieving CMMC Level 2+ compliance for Controlled Unclassified Information (CUI) handling in a defense-relevant environment, we are looking for a seasoned technical lead to direct our product security strategy and implementation.
Your primary role will be to 'shift security left' and weave it throughout our development processes. This includes embedding automated controls such as Software Bill of Materials (SBOM), vulnerability scanning, and secure CI/CD pipelines. You will also maintain standard libraries and infrastructure for authentication, authorization, and logging. Additionally, you will develop monitoring tools for operational services and assist teams in aligning their systems with NIST 800-171/CMMC and other security objectives whenever control inheritance is insufficient.
This is a senior, hands-on individual contributor role with leadership responsibilities where you will code, configure, and debug while mentoring a small team of security engineers. As the technical leader of our Product Security Team, you will collaborate closely with our Chief Software Engineer to ensure alignment with security objectives and the software roadmap, our AWS infrastructure team for cloud hardening, our development tooling team for satellite software security, and the cybersecurity/governance, risk management, and compliance (GRC) group. We maintain a lean setup where bureaucracy is managed primarily by GRC and TPM teams, allowing you to focus on impactful coding and architecture improvements based on our existing strengths.
In this role, you may also participate in discussions with peers at governmental entities and other organizations regarding security-related matters.

