- Own the systems the company runs on, measured by whether they work: identity, endpoints, cloud infrastructure, network, detection and response, and the compliance controls underneath them.
- Expect to move between unrelated domains in the same day or hour. Breadth is the defining feature of this role, and switching context without losing the thread is the skill that carries you through it.
- Build the internal tooling and automation that lets a small team cover a surface that would otherwise require a large one. This is a first-class part of the job, not something you get to when tickets are quiet.
- Own infrastructure as code in Terraform across AWS.
- Run identity in Entra ID: authentication, conditional access, SSO and SCIM integrations, group and role design, and privileged access.
- Manage endpoints in Intune: enrollment, configuration and compliance baselines, and update rings across the fleet.
- Operate Microsoft Sentinel and Defender XDR: detection tuning, hunting queries, and triage that closes every incident with a classification you can defend.
- Drive our CMMC Level 2, NIST 800-171 (R2 and R3), and ITAR programs. Controls are implemented as code and evidence is produced continuously through our own tooling and Vanta, so that an audit becomes a query against systems we already run.
- Triage and remediate vulnerabilities across the infrastructure we run, and drive findings in application code and containers to closure with the software teams that own them.
- Own Linux as a managed endpoint platform: engineering workstations and lab stations, provisioned, joined to identity, encrypted, patched, and brought under real configuration management for the first time, without breaking toolchains.
- Own the network: DNS, routing, remote access, and the boundary between on-prem infrastructure and cloud.
- Keep the logging pipeline everything above feeds healthy, so that detections and audit evidence come from sources we trust.
- Respond to incidents, write the postmortem, then fix the class of problem behind it.
- Decide what to work on. Nobody hands you a backlog. You find the highest-leverage thing and justify why it was the highest-leverage thing.
- Six-plus years across IT operations, infrastructure, or security engineering, with at least two where you owned production systems and were accountable when they broke.
- A track record of closing loops in domains you did not start out knowing. Given an unfamiliar problem, you take it to a finished, working solution without someone decomposing it for you first. This is the single thing we care most about.
- Regularly uses AI tools as essential leverage to accelerate work, improve clarity, and multiply output, and verifies before shipping.
- Depth in agentic engineering: agents that take real action against production systems, with the access control, observability, and evaluation needed to trust them, deployed as shared services the whole company can use.
- Infrastructure as code is your default.
- Owns code in production: Python, TypeScript, Go, or similar, at the level of a service or CLI that other people depend on. Whether you write it yourself or direct a model to write it matters far less than whether you can review it, debug it, and stay on the hook when it breaks.
- You build tools for other people, and you care whether anyone actually adopted what you shipped.
- Judgment about blast radius. You know which changes are reversible in five minutes, and which ones are silently wrong for a quarter, and you slow down for the second kind.
- Linux as a managed platform for real users, not just servers: you have kept engineering workstations or lab machines patched, compliant, and supportable, and you can work out what a misbehaving host is actually doing.
- Identity fluency in Entra ID or an equivalent, deep enough to design an access model.
- Real ownership of something security-relevant: a detection, an incident, an identity model, an access boundary.
- Vulnerability management experience across both infrastructure and application findings.
- On-prem network architecture design and implementation
- On-site in Broomfield, CO.
- Microsoft 365 and Entra ID in GCCH.
- A cybersecurity background: SIEM and EDR operations, detection engineering, threat hunting, or incident response.
- Exposure to CMMC Level 2, NIST 800-171, or ITAR. Genuinely not required: we will teach the frameworks. The hard part is knowing which technical mechanism actually satisfies a control, and that is learned here.
- Intune at fleet scale across macOS, Windows, and Linux.
- Having been an early member of a small infrastructure or security team, where you decided your own scope.
- $119,507 - $140,000 per year
- Employee friendly equity compensation
- 4% direct matching 401k
- Health Insurance: 100% employee coverage & 75% dependent coverage
- Parental leave and childcare coverage
- Flexible vacation and sick time from day one
- 12 company holidays
- $100 monthly wellness benefit
- Relocation package if not based in Denver
Skills Required
- Six or more years of experience across IT operations, infrastructure, or security engineering
- At least two years owning production systems and being accountable when they fail
- Track record of independently taking unfamiliar problems through to finished, working solutions
- Regular use of AI tools to accelerate work, improve clarity, and increase output while verifying results
- Experience with agentic engineering, including production agents, access control, observability, and evaluation
- Infrastructure-as-code experience
- Production programming experience with Python, TypeScript, Go, or a similar language
- Ability to review, debug, and support production services or command-line tools
- Experience building tools for other users and driving adoption
- Strong judgment regarding change risk and blast radius
- Experience managing Linux workstations or lab machines, including patching, compliance, support, and troubleshooting
- Fluency with Microsoft Entra ID or an equivalent identity platform, including access-model design
- Ownership of a security-relevant capability such as detection, incident response, identity modeling, or access boundaries
- Vulnerability management experience covering infrastructure and application findings
- Experience designing and implementing on-premises network architecture
- Ability to work on-site in Broomfield, Colorado
- Must be a U.S. Person as defined under 22 CFR 120.62
- Must verify identity and employment eligibility in the United States
- Microsoft 365 and Entra ID experience in GCCH
- Cybersecurity background involving SIEM, EDR, detection engineering, threat hunting, or incident response
- Exposure to CMMC Level 2, NIST 800-171, or ITAR
- Intune experience at fleet scale across macOS, Windows, and Linux
- Experience as an early member of a small infrastructure or security team
What We Do
Albedo is the first space company to commercialize and provide platform capabilities to the new orbit regime of VLEO. VLEO — very low Earth orbit — transforms satellite capabilities by operating twice as close to Earth, enabling dramatic improvements in performance while reducing system costs. Albedo’s first satellite Clarity-1 — launched in March 2025 and now operating in VLEO — exemplifies the disruptive potential of the company’s proprietary VLEO platform. Clarity-1 delivers imagery at a resolution previously exclusive to drones & aircraft or billion-dollar classified satellites, while showcasing a platform that can support a variety of mission types. The world is rapidly changing and a new level of visibility and transparency is required to solve some of our largest problems. Albedo’s 10cm visible and 2m thermal imagery will fuel insights for industries such as mapping, insurance, utilities, solar, agriculture, carbon offsets, infrastructure sustainability, national security, and much more.







