Logos Space
Posted 1d ago

Lead Security Architect – Cloud Platform & Network Security

Logos Space
Mountain View or San Diego
$220k-$270k/yrOnsiteFull Time
Responsibilities
  • architecting security
  • hardening control planes
  • detecting threats
Requirements
  • Bachelor's degree or equivalent experience
  • 10+ years in cybersecurity
  • Software engineering, or infrastructure security
  • 5+ years architecting distributed cloud security
  • Kubernetes
  • Networking
  • Cryptography, and cloud security expertise
Technical tools mentioned
KubernetesSPIFFESPIREmTLSService MeshSoftware-Defined Networking (SDN)eBPFTetragonFalcoCiliumOPAGatekeeperKafkaPrometheusSIEMSOARNIST SP 800-53CMMCFedRAMPGoRustPythonHSMsTPMsHashiCorp VaultIstioSTRIDEATT&CKAWSGCPAzureLinux

Job description

Lead Security Architect – Cloud Platform & Network Security

Logos Space is a Low Earth Orbit (LEO) satellite system purpose-built to serve the connectivity needs of the commercial enterprise users and government users. We will help fill an important gap in the market, providing resilient, high-performance satellite-based connectivity services to enterprise and government customers worldwide. Business customers have contracts with agreed-upon performance standards for their broadband, and Logos will build these capabilities into the system from the beginning. Speed and reliability are the foundation of the system. Logos is designed to extend cloud and data center network connectivity anywhere in the world to fixed, seaborne, and airborne terminals.

Logos is led by a team of highly experienced engineers with proven track records in the networking and satellite industries.

The Product and Data Link Security team at Logos Space Engineering is responsible for ensuring the success of our network by providing unique levels of security and authentication in space communications. This position is a critical driver of the architecture, overseeing development efforts specific to the security architecture, as well as working with other teams like ground segment and spacecraft systems.

We are seeking engineers who can thrive in a fast-moving environment, comfortable taking vague design ideas and turning them into concrete, testable architecture and secure solutions.

The Role:

We are seeking an experienced Lead Security Architect – Cloud Platform & Network Security to spearhead the security architecture for our LEO satellite network infrastructure.

While our DevSecOps team owns software supply chain security and CI/CD vulnerability scanning, this role owns the runtime threat resistance, zero-trust network topology, cryptographic key management, and distributed systems defense across our multi-region cloud, ground stations, and edge software nodes.

Working closely with the Lead, Cloud Platform Software, you will define how our Kubernetes clusters, telemetry pipelines, and SDN control planes withstand real-world cyber threats in hostile or degraded operating environments.

Key Responsibilities:

Zero-Trust Workload Identity: Architect and implement identity frameworks (e.g., SPIFFE/SPIRE, mTLS, Service Mesh) to establish cryptographically verified identity for microservices operating across cloud, ground segment nodes, and hybrid edge hardware.

SDN & Control Plane Hardening: Conduct threat modeling and design runtime security controls for our Software-Defined Networking (SDN) stack, protecting routing protocols, control messages, and telemetry streams from spoofing, tampering, and denial-of-service (DoS) attacks.

Runtime Defense & Policy Enforcement: Deploy eBPF-based runtime monitoring (e.g., Tetragon, Falco, Cilium) and policy-as-code admission controllers (OPA/Gatekeeper) to detect and neutralize zero-day exploits, container breakouts, and unauthorized process executions in real time.

Key Ceremonies & PKI Governance: Design, orchestrate, and execute formal cryptographic key ceremonies (multi-party key generation, root CA creation, and secret splitting) to establish trust anchors for root certificate authorities, satellite communication keys, and cloud/ground HSM clusters

Hardware-Backed Key & Cryptographic Management: Oversee the architecture for root-of-trust, Hardware Security Modules (HSMs), TPMs, and Vault clusters managing satellite communications keys, TLS certificates, and secrets lifecycle.

Security Telemetry & Anomaly Detection: Collaborate with the Platform team to embed security observability into high-throughput logging and telemetry pipelines (Kafka, Prometheus, SIEM/SOAR) for automated threat detection and incident response.

Defense & Federal Compliance: Translate rigorous federal and defense cybersecurity mandates (e.g., NIST SP 800-53, CMMC Level 3+, FedRAMP High, DoD IL5/IL6) into technical security designs without compromising platform agility or speed.

Basic Qualifications

Education: Bachelor’s degree in Computer Science, Cybersecurity, Computer Engineering, or equivalent practical experience.

Experience: 10+ years in cybersecurity, software engineering, or infrastructure security, with 5+ years architecting security for distributed cloud platform software.

Technical Expertise:

Deep understanding of Kubernetes architecture, container isolation, Linux kernel security, and eBPF technology.

Hands-on experience with modern networking protocols, zero-trust architectures, service meshes (Istio/Cilium), and mTLS.

Proficiency writing software or tooling in Go, Rust, or Python.

Hands-on architectural experience with HSMs, TPMs, and enterprise secrets management (e.g., HashiCorp Vault).

Clearance: Ability and willingness to obtain and maintain a Top Secret Clearance.

Preferred Qualifications

Experience securing carrier-grade telecom, aerospace, satellite ground stations, or critical defense network infrastructure.

Demonstrated experience handling threat modeling (STRIDE/ATT&CK) for real-time distributed routing or control plane systems.

Deep knowledge of public cloud security guardrails across AWS, GCP, or Azure alongside hybrid/on-prem deployments.

About Logos Space

Private LEO satellite operator serving government and enterprise customers with secure, resilient communications.

Year founded
2024
Employees
48
Organization type
Private
Latest investment
Raised $50.00M Series A (2025) — led by U.S. Innovative Technologies (USIT)
Headquarters
US

Similar jobs

Security Architect roles near Mountain View, California
3w
Save
Mark Applied
Hide
Security Architect - IT/OT Modernization
Chicago or Los Angeles or New York City or San Francisco or Seattle or District of Columbia
$194k-$228k/yr OnsiteFull Time
West Monroe
West Monroe: Business and technology consulting firm.
7+ YOERequires 7–10+ years in security architecture or enterprise cybersecurity, IT/OT and ICS security expertise, cybersecurity tooling experience, regulated-industry experience, executive communication, and client travel availability.
SCADA, EMS, ADMS, DERMS, ERP, CRM, IAM, EDR, XDR, SIEM, SOAR, Dragos, DLP, SOC, NERC CIP, IEC 62443, NIST CSF, NIST 800-53, ISO 27001, AI/ML, Splunk, Microsoft Sentinel, Google SecOps, Palo Alto, ServiceNow SecOps, SailPoint, Okta, CrowdStrike
4w
Save
Mark Applied
Hide
Senior Principal Engineer, Security Architect (2026- 346)
San Jose or Seattle
$190k-$240k/yr OnsiteFull Time
Astera Labs
Astera LabsNASDAQ: ALAB: Provider of connectivity solutions for AI data centers.
12+ YOEBachelor's degree in CS/CE/EE,12+ years security engineering/architecture across hardware, firmware, software and cloud; expertise in cryptography, identity, network security, Azure/Microsoft enterprise, and threat modeling.
Microsoft Azure, Microsoft Entra, Microsoft M365, Microsoft Active Directory, PCIe, CXL, COSMOS, MITRE ATT&CK, CI/CD, EDA
1mo
Save
Mark Applied
Hide
Security Architect, Physical AI SoC
Santa Clara, California, United States
$200k-$500k/yr OnsiteFull Time
Velaura AI
Velaura AI: Private AI compute infrastructure developing ultra-low-power silicon and software for data centers and Physical AI.
10+ YOE10+ years hardware/SoC security experience, deep expertise in root of trust, secure boot, key management, applied cryptography, threat modeling, SoC development flows, and strong communication skills.
TrustZone, RTL, SDK, ISO 26262, ISO/SAE 21434, Common Criteria, FIPS 140-3, PSA Certified
1mo
Save
Mark Applied
Hide
Security Architect for Network and Cloud
Belfast or Chicago or Dallas or Houston or Los Angeles or Manila or Miami or New York City or Palo Alto or San Francisco or Tampa or Washington
HybridFull Time
Baker McKenzie
Baker McKenzie: Global law firm providing cross-border legal and business advisory services.
Bachelor's degree in Computer Science or equivalent experience; extensive cloud security, CASB, CNAPP, email security, IAM, network security, risk assessment, and compliance expertise; strong English communication skills.
CNAPP, CASB, Microsoft Defender for Cloud Apps, Microsoft Defender for Cloud, Microsoft Purview, Microsoft Entra ID, DLP, IAM
1mo
Save
Mark Applied
Hide
Security Architect - TikTok Account
San Jose, California, United States
$245k-$588k/yr OnsiteFull Time
TikTok
TikTok: Short-form mobile video and social media platform.
Bachelor's degree and experience in account security, identity authentication, or large-scale system architecture; familiarity with OAuth2/OIDC/SAML/FIDO2 and distributed high-concurrency systems; strong cross-team communication.
FIDO2, Passkey, OAuth2.1, OpenID Connect, OAuth2, OIDC, SAML, Zero Trust Architecture
1mo
Save
Mark Applied
Hide
Senior Security Architect - Hardware
Santa Clara or Austin or Hillsboro or Durham or Redmond
$184k-$357k/yr OnsiteFull Time
NVIDIA
NVIDIANASDAQ: NVDA: Computing platform for AI and accelerated graphics.
8+ YOE8+ years relevant experience; BS/MS/PhD (or equivalent) in EE/CS/CE; experience with SoC/GPU ASIC design, HW root of trust, secure boot; programming in C/C++, Verilog, ARM assembly, Python/Perl; strong communication skills.
C/C++, Verilog, ARM assembly, Python, Perl, TPM
1mo
Save
Mark Applied
Hide
Senior Security Architect - Hardware
Santa Clara or Austin or Hillsboro or Durham or Redmond
$184k-$357k/yr OnsiteFull Time
NVIDIA
NVIDIANASDAQ: NVDA: Computing platform for AI and accelerated graphics.
8+ YOEBS, MS, PhD, or equivalent experience in electrical engineering, computer science, or computer engineering; 8+ years relevant experience; ASIC, SoC/GPU architecture, hardware security, cryptography, and programming expertise.
C, C++, Verilog, ARM assembly, Python, Perl, ARM, RISC-V, TPM
2mo
Save
Mark Applied
Hide
Distinguished Engineer, End-to-End Security Architect
Austin or Milpitas
OnsiteFull Time
Graphcore
Graphcore: Developing AI compute hardware and software infrastructure.
Advanced technical degree or equivalent experience with significant platform/infrastructure/cloud security architecture expertise, threat modelling, zero-trust, key and secrets management, secure firmware/boot, and leadership across engineering and operations.