Product Security Engineer
Job description
About the role
Join the Starlink team to secure the global satellite internet network. You will build and maintain security infrastructure for satellites, consumer hardware, and ground systems to protect millions of users. In this capacity, you will own the design and execution of security controls across the full product lifecycle. You will act as a technical leader to define and drive security standards for space and ground segments. The role requires you to balance innovation with the stringent reliability demands of orbital operations. You will collaborate closely with hardware, firmware, and software teams to embed security from the outset. Your work will directly influence the resilience of critical infrastructure used in remote and underserved regions. This position is pivotal in establishing the security posture for one of the world's largest satellite constellations.
Key facts
What you'll do
- Architect and implement security services, including cryptographic infrastructure for satellite communications and ground networks.
- Develop security features tailored for the Starlink dish, user terminal router, ground gateways, and the satellite bus subsystems.
- Integrate security protocols and secure coding practices into manufacturing test flows and operational network services.
- Manage production systems in orbit and on earth while identifying, triaging, and implementing security enhancements and patches.
- Create prototypes to test and validate new security designs under realistic orbital and terrestrial environmental constraints.
- Support the expansion of secure internet access to global communities by ensuring robust authentication and data protection mechanisms.
- Conduct threat modeling and risk assessments for new features across the distributed satellite, terrestrial, and user device ecosystem.
- Drive adoption of security best practices by mentoring engineers and establishing guidelines for secure development.
- Analyze security incidents and telemetry to detect adversarial behavior and drive improvements across the stack.
- Partner with compliance and legal teams to ensure security implementations meet regulatory and export control standards.
- Collaborate with hardware engineers to define secure boot, key storage, and tamper-resistant mechanisms for field-deployed devices.
- Investigate emerging vulnerabilities and attack techniques to proactively harden the satellite network and user equipment.
Requirements
- Bachelor degree in a STEM field or 2+ years of professional security software development experience.
- Proficiency in at least one programming language such as Python, C++, or Golang for implementing security controls and tooling.
- Experience designing security solutions for distributed systems, operating systems, or large-scale infrastructure that span multiple geographic regions.
- Ability to work weekends and extended hours when necessary to respond to critical security events or mission milestones.
- Must meet ITAR requirements: U.S. citizen, lawful permanent resident, refugee, or asylee.
- Strong understanding of secure software development lifecycle processes and how to apply them in fast-paced environments.
- Demonstrated capability to work independently and make sound security decisions with minimal direct supervision.
- Willingness to adhere to strict documentation and audit requirements for security artifacts and change management.
Nice to have
- Advanced degree in a technical or engineering discipline with a focus on security, computer science, or related field.
- Experience improving security within complex, large-scale systems that operate across multiple layers of the technology stack.
- Familiarity with hardware security modules like TPMs or HSMs for key lifecycle management and secure attestation.
- Deep knowledge of network protocols, specifically TCP/IP and UDP, as they are used in latency-sensitive satellite links.
- Proven ability to navigate ambiguity and master new technologies rapidly in dynamic and high-stakes operational settings.
- Strong verbal and written communication skills for cross-team collaboration with engineering, operations, and mission assurance groups.
- Experience with security testing, fuzzing, and reverse engineering of network protocols or embedded firmware.
- Knowledge of regulatory frameworks such as FCC, FCC Experimental, and ITAR as they apply to satellite communications.
Practical notes
SpaceX is an equal opportunity employer. Applicants needing reasonable accommodations or access to the Affirmative Action Plan should contact EEOCompliance@spacex.com.
Only U.S. citizens and eligible U.S. persons may apply for roles requiring ITAR compliance. This position is located in Bastrop, Texas, and requires the ability to work extended hours and weekends during critical project or incident windows. Travel may be required to Starbase, Texas, and other company facilities as needed for engineering reviews, manufacturing support, or security assessments. Roles at SpaceX often cross functional paths, providing opportunities to contribute to launch, connectivity, and AI initiatives. This role reports to the Starlink security organization and participates in the broader product security community.