Skip to content

Open nowPosted 48 days ago

Principal Cybersecurity Lead

E-Space102 open roles

Pay
$160,000 – $220,000 a year
Where
Saratoga, CA
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Cybersecurity LeadE-Space · Saratoga, CA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on E-Space's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 48 days ago

The posting

Ready to make connectivity from space universally accessible, secure and actionable? Then you’ve come to the right place!

E-Space is bridging Earth and space to enable hyper-scaled deployments of Internet of Things (IoT) solutions and services. We are building a highly-advanced low Earth orbit (LEO) space system that will fundamentally change the design, economics, manufacturing and service delivery associated with traditional satellite and terrestrial IoT systems.

We’re intentional, we’re unapologetically curious and we’re 100% committed to innovate space-based communications and deliver actionable intelligence that will expand global economies, protect space and our planet and enhance our overall quality of life.

What is this role:

What you will do:

  • Continuously monitor active threat campaigns, ransomware groups, state-sponsored actors, criminal ecosystems, exploit trends, malware families, phishing infrastructure, and newly weaponized vulnerabilities relevant to the company.
  • Translate threat intelligence into detection hypotheses, hunting queries, control changes, exposure reviews, and prioritized defensive action - not passive reporting.
  • Maintain a current view of attacker tactics, techniques, and procedures using practical frameworks such as MITRE ATT&CK while recognizing where real-world behavior departs from frameworks.
  • Build trusted relationships with relevant industry, vendor, law-enforcement, and information-sharing communities as appropriate.
  • Understand and secure enterprise routing, switching, segmentation, DNS, DHCP, VPN, wireless, firewalls, proxies, email, identity providers, directory services, SaaS, cloud, remote access, endpoints, servers, containers, and CI/CD environments.
  • Map external and internal attack surfaces, trust boundaries, privileged paths, crown-jewel systems, internet exposure, shadow IT, third-party access, and plausible attack chains.
  • Drive secure architecture decisions across identity, zero-trust access, network segmentation, secrets, cryptography, logging, endpoint protection, cloud controls, backup resilience, and recovery.
  • Partner with infrastructure, product, software, IT, legal, privacy, and physical-security teams to reduce systemic risk without creating unusable controls.
  • Write, review, test, and maintain code that detects malicious or abnormal behavior across network, endpoint, identity, application, and cloud telemetry.
  • Develop behavioral analytics, correlation logic, enrichment pipelines, investigation tools, automated containment workflows, and repeatable forensic utilities.
  • Create high-quality SIEM/EDR/NDR detections and hunting content; measure precision, recall, coverage, false positives, alert latency, and operational value.
  • Use languages such as Python, Go, Rust, PowerShell, shell, SQL, or equivalent as the problem requires; work comfortably with APIs, event streams, structured logs, packet data, and large security datasets.
  • Apply software-engineering discipline to security code: version control, peer review, tests, deployment controls, observability, rollback, documentation, and secure secrets handling.
  • Proactively hunt for weak signals, anomalous sequences, living-off-the-land activity, identity abuse, covert persistence, unauthorized privilege, lateral movement, unusual data access, and exfiltration.
  • Investigate potential internal and external threats lawfully and proportionately, using authorized data sources, need-to-know access, privacy safeguards, and documented evidence handling.
  • Lead triage, scoping, containment, eradication, recovery, forensics, root-cause analysis, and post-incident improvement for serious events.
  • Preserve evidence and timelines suitable for executive, legal, regulatory, insurance, and law-enforcement needs when applicable.
  • Design and run incident simulations, purple-team exercises, detection validation, and authorized adversary emulation; ensure findings become durable engineering improvements.
  • Own risk-based vulnerability management across infrastructure, endpoints, cloud, applications, dependencies, appliances, and third-party services.
  • Distinguish theoretical severity from real exploitability by considering exposure, privileges, reachable attack paths, available exploits, compensating controls, asset value, and active exploitation.
  • Drive remediation of critical weaknesses and validate fixes through retesting, telemetry, and control verification.
  • Establish emergency processes for zero-days and mass-exploitation events, including rapid inventory, containment, patching, workaround validation, and executive updates.
  • Act as the company's senior technical decision-maker during serious cyber events. Decide when to isolate systems, disable accounts, block traffic, interrupt business processes, invoke outside support, or accept short-term operational risk - and document the evidence and reasoning behind those decisions.
  • Set the technical direction, operating model, priorities, metrics, and quality bar for detection, response, threat hunting, vulnerability management, and security engineering.
  • Recruit, mentor, and raise the capability of security engineers and analysts while remaining personally capable of deep technical investigation and coding.
  • Communicate risk in concrete business terms: what can happen, how likely it is, what evidence exists, what must be done, who owns it, and by when.
  • Build trusted escalation paths and an on-call model that supports decisive action without normalizing burnout or uncontrolled surveillance.
  • Own security decisions from incomplete initial signal through validated conclusion; state what is known, what is unknown, the confidence level, the immediate risk, and the next decision point.
  • Dive personally into the highest-risk vulnerabilities and incidents. Read logs, inspect packets, trace identities and privileges, review configurations and code, reproduce issues safely, challenge assumptions, and verify that remediation actually closes the attack path.
  • Prioritize vulnerabilities by real business exposure and attacker opportunity rather than CVSS score alone; connect individual weaknesses into plausible multi-step attack chains.
  • Refuse both analysis paralysis and reckless action. Make reversible decisions quickly when possible, escalate irreversible decisions appropriately, and update direction as evidence changes.
  • Maintain clear ownership through closure: containment is not completion. Require root cause, durable remediation, detection coverage, regression testing, and accountable follow-through.

What you will bring to this role:

  • Substantial hands-on experience defending complex corporate environments and leading high-severity investigations from initial signal through containment and root cause.
  • Demonstrated hacker mindset and practical knowledge of exploitation, persistence, credential theft, identity attacks, lateral movement, evasion, command-and-control, and exfiltration - applied only in authorized and ethical contexts.
  • Deep understanding of TCP/IP, DNS, HTTP/TLS, routing, segmentation, firewalls, proxies, VPNs, wireless, endpoint internals, Windows and Linux, identity systems, cloud services, and enterprise logging.
  • Strong programming ability and evidence of building security detections, analytics, automation, or investigation tooling used in real operations.
  • Expertise with SIEM, EDR/XDR, NDR, IAM, cloud security telemetry, vulnerability tooling, packet/log analysis, and digital-forensics methods; vendor-specific experience is less important than first-principles understanding.
  • Ability to reason from incomplete or conflicting evidence, form and test hypotheses, quantify confidence, and recognize when an alert is noise, an isolated event, or part of a larger campaign.
  • Demonstrated record of making high-impact security decisions under time pressure and personally validating the technical evidence rather than delegating all analysis to vendors or junior staff.
  • Sound judgment regarding privacy, employee monitoring, legal authorization, evidence preservation, disclosure, and the boundary between defensive validation and unauthorized access.
  • Clear written and verbal communication with engineers, executives, legal counsel, employees, customers, and external responders during high-pressure events.

Bonus points:

  • Experience in a technology company with valuable intellectual property, distributed operations, sensitive customer data, or high-availability infrastructure.
  • Defense-industry cybersecurity experience is a plus, including supporting CMMC readiness and self-assessment, collecting and maintaining defensible control evidence, tracking remediation, and completing authorized self-reporting accurately and on time.
  • Experience establishing or materially improving a threat-hunting, detection-engineering, incident-response, or security-operations function.
  • Background in reverse engineering, malware analysis, exploit analysis, cloud incident response, identity forensics, or network protocol analysis.
  • Experience with threat-informed defense, purple teaming, security data engineering, and detection-as-code.
  • Relevant research, open-source security contributions, conference work, responsible disclosures, certifications, or competitive security experience - valued as evidence, not substitutes for demonstrated capability.

Additional Requirements

Why E-Space is right for you:

As a member of our team, you will play a crucial role in driving our success. Our team members have a strong sense of dedication and responsibility; this includes a strong commitment to our mission to create an entirely new suite of global capabilities to improve lives, business efficiencies and build a smarter planet. This means that there will be times when extra hours, including nights and weekends, may be needed to meet critical deadlines and mission goals. In return, we offer a dynamic work environment with opportunities for professional growth and development and the chance to make a meaningful impact in a high-growth industry.

We want you to make the most of your journey at E-Space. That’s why we support and invest in the physical, emotional and financial well-being of our team members and their families. Some of what you can expect when working at E-Space:

• An opportunity to really make a difference

• Sustainability at our core

• Fair and honest workplace

• Innovative thinking is encouraged

• Competitive salaries

• Continuous learning and development

• Health and wellness care options

• Financial solutions for the future

• Optional legal services (US only)

• Paid holidays

• Paid time off

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against E-Space's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on E-Space's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    E-Space's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.