Astra

DevSecOps Engineer

California, United States

Not SpecifiedCompensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, GIS Software, Cloud ServicesIndustries

Position Overview

  • Location Type:
  • Job Type: Full time
  • Salary:

We are seeking an experienced and proactive DevSecOps Engineer to join our Cybersecurity Application Platform Security Team to secure our Geographic Information Systems (GIS) applications as a part of large business transformation effort – Elevate. The ideal candidate will have hands-on experience with cybersecurity platforms, with a deep understanding of cloud security (especially AWS), strong experience with DevSecOps practices, and an understanding of GIS applications to operate the environment securely, enhance security posture, secure CI/CD pipelines and continuously bake-in security and compliance.

Key Responsibilities

  • Work with Elevate (GIS) teams to bake-in security controls part of design and implement secure AWS architectures for GIS applications.
  • Provide security best practices for implementing COTS software such as ArcGIS in AWS.
  • Implement and maintain robust security measures & DevSecOps Framework (SHIELD) throughout every phase of development, from planning to deployment and maintenance across CI/CD pipeline. (‘Secure by design’, ‘Secure by default’).
  • Implement security policy-as-code (PaC) & Compliance-as-Code (CaC) and integrates continuous security testing within CI/CD pipelines.
  • Report on DevSecOps specific security metrics, KPIs, KRIs to track progress and demonstrate the value of security investments aligning with IT, Cyber L1, L2s.
  • Partner with SIOC team to perform code reviews and static analysis to identify security vulnerabilities.
  • Validate Identity and Access Management (IAM) policies and roles.
  • Secure data at rest and in transit using AWS encryption services.
  • Work with stakeholders to implement network security measures, including VPCs, security groups, and NACLs.
  • Stay updated on emerging threats, vulnerabilities, and security trends related to AWS, Azure and DevSecOps practices.
  • Promote cybersecurity awareness among developers and stakeholders.
  • Foster a security-first mindset across Elevate application platform teams, promoting shared responsibility for cybersecurity (lead by cyber, owned by all).

Qualifications

  • Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience).
  • 5+ years of experience in IT security, with at least 3 years focused on DevSecOps, DevOps or Security Engineering roles.
  • Extensive hands-on experience with AWS services and security best practices.
  • Strong understanding of GIS applications (ArcGIS) and their security requirements.
  • Proficiency in scripting languages such as Python, Bash, or Ruby.
  • Experience with CI/CD tools (e.g., Jenkins, GitLab CI, or AWS CodePipeline).
  • Knowledge of container technologies and orchestration platforms (e.g., Docker, Kubernetes).
  • Familiarity with infrastructure-as-code tools (e.g., Terraform, CloudFormation).
  • Understanding of security standards and frameworks (e.g., NIST CSF).
  • Excellent communication and collaboration skills.
  • Familiarity with the shared responsibility model in cloud environments (AWS, Azure) and hybrid cloud deployments.
  • CISSP, CISM, or DevSecOps-specific credentials are a plus.
  • Strong analytical and problem-solving skills with excellent communication and teamwork abilities.

Preferred Technical Skills

  • Experience with scripting languages (e.g., Python, PowerShell) for automation of security tasks.
  • Knowledge of container security (Docker, Kubernetes).
  • Familiarity with secure software development lifecycle (SDLC) practices.

Soft Skills

  • Excellent Communication Skills: Ability to clearly articulate security concepts to diverse audiences, including engineers, product managers, and executives.
  • Collaboration & Influence: Proven ability to work cross-functionally with teams to align on security priorities and influence roadmaps.

Preferred Qualifications

  • Relevant security certifications (e.g., AWS Certified Security - Specialty, CISSP, CEH).
  • Experience with GIS-specific security challenges and solutions.
  • Knowledge of multi-cloud and hybrid cloud security architectures.

Skills

Cybersecurity platforms
Cloud security
AWS
DevSecOps practices
GIS applications
AWS architectures
COTS software (ArcGIS)
Security measures & Framework (SHIELD)
Policy-as-Code (PaC)
Compliance-as-Code (CaC)
Security testing
Code reviews
Static analysis
IAM policies
Encryption services
Network security (VPCs, security groups, NACLs)
Threats and vulnerabilities awareness
Security-first mindset

Astra

Provides launch services for small satellites

About Astra

Astra provides launch services specifically for small satellites, catering to commercial businesses, government agencies, and research institutions that need reliable access to space. The company operates small, agile rockets designed to transport these satellites into low Earth orbit (LEO). Astra's approach focuses on making space more accessible by reducing the costs and complexities associated with satellite launches, which allows a wider range of customers to utilize their services. Unlike many competitors, Astra emphasizes efficiency and cost-effectiveness in its operations, aiming to meet the growing demand for satellite-based services such as Earth observation and telecommunications. The company's goal is to facilitate more frequent and affordable satellite launches, thereby expanding opportunities for various applications in the space industry.

Alameda, CaliforniaHeadquarters
2016Year Founded
$291.8MTotal Funding
IPOCompany Stage
AerospaceIndustries
201-500Employees

Benefits

Competitive Medical (HMO & PPO)/Dental/Vision plans
Company paid Short Term Disability and Long Term Disability plans
401K with company match
Flexible Spending Account
Commuter benefits
Caregiving support benefits
Company perks, like PetPlan, curated gym/travel/products discounts
Free lunch
Company events

Risks

Going private may limit Astra's access to public capital markets.
Astra faces financial instability due to liquidity crunch and high cost of capital.
Intensifying competition in the small satellite launch market could impact Astra's market share.

Differentiation

Astra offers cost-effective launch services for small satellite payloads.
The company focuses on agile rockets for frequent access to space.
Astra provides online reservations for payload deliveries to various orbits.

Upsides

Growing demand for small satellite constellations aligns with Astra's business model.
U.S. government investment in space technology presents contract opportunities for Astra.
Astra's reusable rocket technology could lead to significant cost reductions.

Land your dream remote job 3x faster with AI