At Sierra Space, we build the missions and systems that keep our world secure in the domain above Earth.
Sierra Space team members share a spirit of innovation and collaboration and a belief that we can deliver on the boldest missions in space today. Together with our customers, we aim to safeguard our nation, sustain human presence in space, and secure the freedom of operations in low Earth orbit and beyond.
Our success is measured by the trust of those who rely on what we build and deliver, and our technologies keep the United States and its allies mission-ready throughout space.
We are mission-driven, and together, we are an extraordinary team.
About the RoleThe Cybersecurity Engineer III is responsible for designing, implementing, and maintaining advanced security measures to protect the organization's information systems. This role involves working with various security technologies, including encryption, intrusion detection/prevention systems (IDS/IPS), and multi-factor authentication. They will have extensive knowledge of secure systems architecture, emerging technologies, threats, and regulatory requirements. The Cybersecurity Engineer III will work closely with senior engineers and cross-functional teams to ensure the security and integrity of the organization's information systems. This position offers the opportunity to work on complex security projects, stay updated with the latest industry trends, and contribute to the continuous improvement of the organization's security posture.About YouOur mission is driven by an unyielding commitment to advancing space-based technology in service of our customers and safeguarding national security. We seek individuals who are passionate about innovating beyond boundaries and relentlessly pursuing solutions that protect, preserve and empower – to join us in this critical mission.
We’re looking for team members who align with our values, mission and goals – while also meeting the minimum qualifications below. The preferred qualifications are a bonus, not a requirement.
Key Responsibilities:
- Support the enterprise vulnerability management program across infrastructure, endpoints, applications, cloud environments, and network devices.
- Develop and maintain vulnerability scanning strategies, schedules, configurations, coverage metrics, and operating procedures.
- Analyze vulnerability scan results and threat intelligence to validate findings, assess exploitability and business impact, and prioritize remediation using a risk-based approach.
- Coordinate with infrastructure, application, cloud, network, and business teams to assign, track, and verify remediation activities within established service-level targets.
- Provide technical guidance on remediation options, compensating controls, exception requests, and risk acceptance decisions.
- Monitor vulnerability management dashboards, trends, and key performance indicators; prepare clear executive and technical reports on exposure, remediation progress, and residual risk.
- Investigate discrepancies in scan coverage, vulnerability data, and remediation status to improve the accuracy and completeness of enterprise reporting.
- Integrate vulnerability management processes and data with asset management, configuration management, ticketing, SIEM, GRC, and other security platforms.
- Support vulnerability assessments, penetration testing, compliance assessments, and audits by providing evidence, technical analysis, and remediation status.
- Develop scripts, workflows, and other automation to improve scanning, data analysis, ticket creation, reporting, and remediation verification.
- Stay current on emerging vulnerabilities, exploitation trends, security advisories, and defensive technologies, and communicate relevant risks and recommended actions to stakeholders.
Minimum Qualifications:
- Requires Bachelor's degree in a related field (or equivalent work experience in lieu of degree or Masters +3 years experience).
- Typically 5+ years of related experience.
- Certifications: (1 or more required) GIAC (Global Information Assurance Certification), network technology certifications such as a CCNP (Cisco Certified Network Professional), or SANS level 300 courses.
- Knowledge of one or more: emerging technologies, emerging threats, emerging regulatory requirements.
- Knowledge of secure systems architecture.
Preferred Qualifications:
- Ability to obtain and maintain a U.S. security clearance
- Demonstrated experience operating or engineering an enterprise vulnerability management program across diverse technology environments.
- Hands-on experience with vulnerability assessment and management platforms such as Tenable, Qualys, Rapid7, or equivalent tools.
- Experience developing risk-based vulnerability prioritization methods using severity, exploitability, asset criticality, threat intelligence, and business impact.
- Experience coordinating remediation across infrastructure, endpoint, application, cloud, network, and third-party teams in a large or complex enterprise.
- Experience with vulnerability exception management, compensating controls, risk management, remediation validation, and service-level reporting.
- Proficiency with asset discovery, inventory reconciliation, scan configuration, credentialed scanning, authenticated assessment, and vulnerability data quality management.
- Experience integrating vulnerability management platforms with ticketing, CMDB, SIEM, GRC, orchestration, or reporting systems.
- Experience translating vulnerability data into executive-level risk reporting, dashboards, metrics, and actionable remediation plans.
- Knowledge of common vulnerability scoring and prioritization standards, including CVE, CVSS, CWE, CISA KEV, and related threat intelligence sources.
- Certifications such as CISSP, CISM, CISA, CCSP, GIAC, or a vulnerability-management-related certification.
- Strong technical leadership, communication, analytical, project management, and mentoring skills.
Compensation:
Pay Range:
$122,109.00 - $167,898.75Your actual base compensation will be determined on a case-by-case basis and may vary based on job-related knowledge and skills, education, experience, internal equity and market competitiveness.
Elevate Your CareerAt Sierra Space, we are committed to your personal and professional development. We empower you to make profound and meaningful contributions and foster a vibrant culture of collaboration, where teamwork ignites breakthrough innovations.
We also offer a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, and more.
Sierra Space is an industry-leading space and defense technology company providing satellites, spacecraft, and enabling mission systems and components. We deliver mission-proven technologies to our customers that safeguard our nation, protect space-based assets and enable space exploration.
Application Deadline: This role will remain posted until a qualified pool of candidates is identified.
Please note: Sierra Space does not accept unsolicited resumes from contract agencies or search firms. Any unsolicited resumes submitted to our website or to Sierra Space team members not through our approved vendor list or Talent Acquisition will be considered property of Sierra Space, and we will not be obligated to pay any referral fees.
Sierra Space Corporation is an equal opportunity employer and is committed to working with and providing reasonable accommodations to applicants with disabilities. If you need special assistance or a reasonable accommodation related to applying for employment with Sierra Space or at any stage of the recruitment process, please contact us.
Skills Required
- Bachelor's degree in a related field, or equivalent work experience in lieu of a degree, or a master's degree plus three years of experience
- Typically five or more years of related experience
- At least one required certification: GIAC, CCNP or another network technology certification, or SANS level 300 coursework
- Knowledge of emerging technologies, emerging threats, or emerging regulatory requirements
- Knowledge of secure systems architecture
- Ability to obtain and maintain a U.S. security clearance
- Experience operating or engineering an enterprise vulnerability management program across diverse technology environments
- Hands-on experience with Tenable, Qualys, Rapid7, or equivalent vulnerability management platforms
- Experience developing risk-based vulnerability prioritization methods
- Experience coordinating remediation across infrastructure, endpoint, application, cloud, network, and third-party teams
- Experience with vulnerability exceptions, compensating controls, risk management, remediation validation, and service-level reporting
- Proficiency with asset discovery, inventory reconciliation, scan configuration, credentialed scanning, authenticated assessment, and vulnerability data quality management
- Experience integrating vulnerability platforms with ticketing, CMDB, SIEM, GRC, orchestration, or reporting systems
- Experience creating executive-level risk reports, dashboards, metrics, and remediation plans from vulnerability data
- Knowledge of CVE, CVSS, CWE, CISA KEV, and related threat intelligence sources
- Certifications such as CISSP, CISM, CISA, CCSP, GIAC, or a vulnerability-management-related certification
- Technical leadership, communication, analytical, project management, and mentoring skills
Sierra Space Compensation & Benefits Highlights
-
Retirement Support — The 401(k) program includes employer matching with a vesting schedule and is repeatedly highlighted as a standout element. Feedback suggests this structure meaningfully supports long‑term savings.
-
Healthcare Strength — Comprehensive medical options (PPO and HDHP) with dental, vision, and HSA/FSA are consistently listed, alongside life and disability coverage. Feedback suggests healthcare offerings are solid and broadly well‑regarded.
-
Parental & Family Support — Paid parental leave is present and commonly described as favorable among core benefits. Feedback suggests new parents can access meaningful time away to care for family needs.
Sierra Space Insights
What We Do
Securing The Freedom of Operations Headquartered in Colorado, Sierra Space is a mission-proven Defense Tech company delivering satellite platforms, critical subsystems, reusable spaceplanes, hypersonic technologies, propulsion systems, and infrastructure for the nation’s most critical missions. With more than three decades of heritage and a record of flight-proven success in space, Sierra Space is trusted by U.S. National Security, Civil customers, and global allies. Our technologies safeguard our nation, sustain human exploration in space, and ensure the freedom of operations beyond Earth. Sierra Space is defining the new era of Space Defense, strengthening deterrence today and preserving freedom of action for generations to come.
Why Work With Us
At Sierra Space, you’ll find a supportive, respectful and upbeat culture where your opinions matter and your personal contributions have impact. If you’re thinking about your own next frontier, we’d love to help you explore it.
Gallery
Sierra Space Offices
OnSite Workspace

