JOBSEARCHER

Principal Cloud Security Engineer

Overview In this role, you secure Rocket Lab’s cloud footprint across IaaS, PaaS, SaaS, and FaaS with automated, API-driven security. You collaborate with IT and development teams to implement risk-based controls, support security reviews, and drive secure DevSecOps and MLOps practices. You’ll translate risk data into actionable guidance for partners and help scale a secure platform for a fast-growing, multinational space company. This is a hands-on, architecture-focused security leadership position with a strong emphasis on automation and compliance. Compensation / BenefitsEmployee Stock Purchase Program with 15% stock discountcomprehensive medical plans (HMO, PPO, HDHP with HSA contribution)dental and vision coveragepaid vacation and sick time, 11 paid holidaysflexible spending accounts and dependent care401(k) with company match ResponsibilitiesDesign, implement, and maintain security controls for hybrid cloud environments (IaaS, PaaS, SaaS, FaaS)Develop custom automation to achieve cybersecurity objectivesSupport internal/external security design reviewsConduct security assessments and risk analyses for cloud and CI/CD pipelinesManage IAM solutions to control access to cloud resourcesCreate documentation, plans, and proofs of concept for cybersecurity improvementsConfigure and monitor cloud security tools and servicesCollaborate with development teams to integrate security into SDLC, DevOps, and MLOpsKeep systems updated on threats and best practices and propose proactive security measuresProvide guidance on incident response, compliance, and security awareness trainingParticipate in security audits, assessments, and regulatory compliance reviews Key requirements12+ years of scripting (Bash, PowerShell, Python) and infrastructure as code tools (Puppet, Ansible, Terraform)Bachelor’s degree or 16+ years total experienceCloud security architecture experience across AWS, Azure, Google CloudHands-on with cloud security tools (AWS Security Hub, Azure Security Center, Google Cloud Security Command Center)Experience with US Government compliance regimes (CMMC, NIST, DISA STIG) and ITIL/Change ReviewVulnerability management tools (Tenable, Bringa) and CLI scanners (Trivy, OpenSCAP)Git-based version control (GitHub, GitLab, Bitbucket)Networking, encryption, and secure communication knowledgeDatabases (PostgreSQL, SQLite) and data formats (Parquet, Arrow); analytics tools (PowerBI, Jupyter)Citizenship requirement for US programs (US citizen or eligible)Strong communication with business partnersCollaboration with cross-functional teamsability to translate risk into actionable guidanceAWS, Azure, Google Cloud securityIAM design and managementCI/CD security for pipelines