SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.
SR. CYBER ASSURANCE ANALYST, FINANCE
Cyber Assurance is the practice of providing confidence that systems, products and processes meet security, regulatory and compliance obligations. It bridges governance with technical execution -- validating that controls are in place, risks are managed, and requirements are met for both internal and customer-facing systems.
As a teammate you will operate within Information Assurance, working closely with engineers to understand systems, how controls are implemented, be hands-on with collecting and reviewing evidence, and driving efficiencies and remediation efforts, along with providing technical support for finance systems.
As an ideal candidate, you love living at the intersection of security, compliance, finance systems, and risk management. You thrive on rolling up your sleeves to dig into configs, access controls, change logs, system designs, and evidence packages while making sense of challenging, complex, or ambiguous requirements. You’re as comfortable explaining ITGCs, SOC1/2 and ISO frameworks, and risk concepts to non-technical and technical teams as you are reviewing a user access matrix, validating a change management control, or identifying an insecure default configuration. You are firm when it matters, but flexible in finding practical ways to move the ball forward. You excel at handling concurrent complex efforts and flourish in an environment where learning never ceases—where the breadth of operations ranges from rockets to financial ledgers, and ERP systems—and where teams are laser-focused on mission accomplishment. Excitement guaranteed.
RESPONSIBILITIES:
- Lead and support ITGC testing, SOC 1, SOC 2, SOX-related IT controls, and other relevant audits/certification efforts.
- Partner with engineers and system owners to gather, validate, and package technical evidence for security controls (access management, change management, computer operations, system development lifecycle, configurations, logs, etc.).
- Perform technical security and risk assessments of systems, supporting IT infrastructure, and related networks; identify deviations from security policy, standards, ITGC requirements, or regulatory expectations.
- Identify security controls, ITGC, and compliance gaps (especially those impacting financial reporting or SOC readiness), advise on remediation, and drive timely resolution with engineering and process owners.
- Maintain clear documentation of security controls, control processes, risk assessments, evidence, and audit artifacts.
- Identify and drive assessment and audit efficiency through system integration, data analytics/utilization, GRC tooling, automation, and process improvement.
- Support third-party risk management efforts for suppliers, including onboarding assessments and periodic reviews.
- Identify and propose business-enabling actions by maintaining an up-to-date understanding of emerging information security and IT risks, changes in SOC 1/SOC 2 standards, ITGC best practices, and new compliance/assurance techniques.
- Mentor fellow teammates and take an active role in their development.
BASIC QUALIFICATIONS:
- High school diploma or equivalency certificate.
- 5+ years of experience in cybersecurity compliance, audit or technical security roles with strong knowledge in security compliance frameworks.
- 5+ years of experience with control testing, security standards/policy development, security audits, or security risk management.
PREFERRED SKILLS AND EXPERIENCE:
- Ability to interpret code/configurations, access controls, change records, and system/network designs for ITGC, SOC 1/SOC 2, and compliance implications.
- Experience with security and compliance tooling such as vulnerability scanners, SIEMs, access review platforms, change management systems, container security, and system configuration baseline checks (e.g., CIS Benchmarks, STIGs).
- Hands-on experience with finance systems (ERP, general ledger, payment, or related platforms) and supporting ITGC/application control testing or certifications.
- Knowledge of U.S. and international regulatory and assurance requirements relevant to finance and IT (e.g., SOX, SOC 1, SOC 2, COSO, NIST, ISO 27001, GDPR, and related frameworks).
- Experience evaluating third-party risk (especially for finance/IT vendors), communicating with external stakeholders/auditors, and supporting mitigations.
- Strong communication skills across all organizational levels and ability to build cross-organizational coalitions (Finance, Engineering, IT, Legal, External Auditors).
- Direct experience with external audits, SOC examinations, regulatory compliance reviews, and management of audit evidence packages.
- Project and program management experience, tooling integration, and delivery in highly fluid environments.
- Professional certifications such as CISA, CISM, CISSP, CRISC, GSNA, ISO 27001 auditor, or equivalent (CISA and SOC/ITGC-focused credentials strongly preferred).
ADDITIONAL REQUIREMENTS:
- Must be willing to travel domestically and internationally in support of audit and other assurance activities.
- Must be willing to work extended hours and/or weekends as needed.
- This role requires you to be onsite; remote/hybrid work will not be considered.
COMPENSATION AND BENEFITS:
Pay Range:
Level 3: $130,000.00 - $195,000.00
Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience.
Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for long-term incentives, in the form of company stock or long-term cash awards, as well as potential discretionary bonuses and the ability to purchase additional stock at a discount through an Employee Stock Purchase Plan. You will also receive access to comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short and long-term disability insurance, life insurance, paid parental leave, and various other discounts and perks. You may also accrue 3 weeks of paid vacation and will be eligible for 10 or more paid holidays per year. Employees accrue paid sick leave pursuant to Company policy which satisfies or exceeds the accrual, carryover, and use requirements of the law.
ITAR REQUIREMENTS:
- To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here.
SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.
Applicants wishing to view a copy of SpaceX’s Affirmative Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to [email protected].
Skills Required
- High school diploma or equivalency certificate
- 5+ years of experience in cybersecurity compliance, audit, or technical security roles with strong knowledge in security compliance frameworks
- 5+ years of experience with control testing, security standards/policy development, security audits, or security risk management
- Willingness to travel domestically and internationally in support of audit and assurance activities
- Willingness to work extended hours and/or weekends as needed
- Role requires onsite work; remote/hybrid not considered
- ITAR eligibility (U.S. citizen, U.S. national, lawful permanent resident, refugee, asylee, or eligible to obtain required authorizations)
- Ability to interpret code/configurations, access controls, change records, and system/network designs for ITGC and compliance implications
- Experience with security and compliance tooling such as vulnerability scanners, SIEMs, access review platforms, change management systems, container security, CIS Benchmarks, or STIGs
- Hands-on experience with finance systems (ERP, general ledger, payment, or related platforms) and supporting ITGC/application control testing or certifications
- Knowledge of SOX, SOC 1, SOC 2, COSO, NIST, ISO 27001, GDPR and related frameworks
- Professional certifications such as CISA, CISM, CISSP, CRISC, GSNA, or ISO 27001 auditor (CISA and SOC/ITGC-focused credentials strongly preferred)
SpaceX Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about SpaceX and has not been reviewed or approved by SpaceX.
-
Equity Value & Accessibility — Equity grants are a core part of total compensation, with periodic company-run tender offers that create liquidity before any public listing. These mechanisms can make the equity component feel materially valuable in practice.
-
Healthcare Strength — The package includes comprehensive medical, dental, and vision coverage, with on-site clinics and health resources at major sites. This breadth of coverage is presented as a strong element of the offering.
-
Wellbeing & Lifestyle Benefits — Major locations feature on-site amenities such as fitness facilities, food/coffee, clinics, and other conveniences. These lifestyle perks enhance day-to-day value alongside cash and equity.
SpaceX Insights
What We Do
SpaceX designs, manufactures and launches the world’s most advanced rockets and spacecraft. The company was founded in 2002 by Elon Musk to revolutionize space transportation, with the ultimate goal of making life multiplanetary. SpaceX has gained worldwide attention for a series of historic milestones. It is the only private company ever to return a spacecraft from low-Earth orbit, which it first accomplished in December 2010. The company made history again in May 2012 when its Dragon spacecraft attached to the International Space Station, exchanged cargo payloads, and returned safely to Earth — a technically challenging feat previously accomplished only by governments. Since then Dragon has delivered cargo to and from the space station multiple times, providing regular cargo resupply missions for NASA.






