Orbis Operations, LLC Logo

Orbis Operations, LLC

Staff Security Engineer

Posted 13 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead security architecture for a secure multi-cluster service mesh platform. Design authentication, authorization, tenant isolation, encryption, credential lifecycle, and service-to-service trust. Establish secure development patterns, threat modeling, testing, security quality gates, incident response, vulnerability discovery, and compliance practices. Implement and review Go and gRPC security systems, mentor engineers, guide technical direction, and collaborate with customers and cross-functional teams. Requires international travel to the Middle East and geopolitical hot zones up to 25% annually.
The summary above was generated by AI

Company Overview

Orbis Operations is a technology company that delivers sovereign intelligence and decision capabilities to the United States Government and its allies. We convert complex information and operational systems into decisive outcomes, giving public institutions and critical enterprises the tools to move faster, see clearer, and act first in an increasingly contested world.

We are not a consulting firm and not a systems integrator. Every Orbis team is built around practitioners who have operated at the mission edge, and every engagement is judged on one thing: whether it produces working capability, not slide decks. Solutions forged from experience; that is how we build, and it is how we hire.

Job Summary

Orbis is seeking a Staff Security Engineer to drive the security and trust architecture across Catalyst, our secure multi-cluster service mesh platform. You will set the patterns other engineers follow for authentication, authorization, and tenant isolation. We are looking for someone who has built platform-wide security architecture and wants to set technical direction for a team building critical infrastructure.

TRAVEL: International travel to Middle East and geopolitical hot zones, up to 25% per calendar year is required. Please apply only if you can meet this requirement.

Key Responsibilities

  • Define the architecture for Catalyst's authentication and authorization layer (e.g., OIDC, OAuth2, and SAML, RBAC, ABAC models) and help set the patterns other engineers build against
  • Drive reliability and security strategy for the trust layer: define SLOs and SLAs for authn/authz latency and availability, lead incident response for credential and access-control incidents, and design for safe revocation under partial failure
  • Participate in on-call and incident response for our data platform including leading post-incident reviews, triage, prevention, and mitigation
  • Define and implement secure-by-default developer patterns and infrastructure primitives to reduce security friction and eliminate common vulnerability classes (e.g., standardized authentication middleware, automated credential lifecycle management, and hardened service-to-service communication patterns using mTLS and SPIFFE/SPIRE)
  • Define the QA philosophy and test strategy for the security layer, including threat modeling, adversarial test coverage, and session and revocation edge cases, and own the security quality gates in the deployment pipeline (e.g., integrating SCA, SAST, and container image scanning)
  • Implement and review pull requests across session, token, and authentication systems ensuring that security, testing, and operational readiness
  • Architect and implement encryptions at rest and in transit, key hierarchies, and HSM/KMS integration (e.g., using HashiCorp Vault or cloud-native KMS providers)
  • Lead team rituals such as design discussions to improve culture, surface new ideas, risks, and strategies across the team
  • Partner with security and IT teams to align on networking, observability, and identity patterns (e.g., including VPCs, network policies, IAM, and service mesh configurations) and ensure compliance with relevant industry standards (e.g., OWASP, ISO 27001, NIST, SOC 2)
  • Lead offensive security and vulnerability discovery efforts (e.g., directing third-party penetration tests, conducting internal red-team exercises, regular security assessments and penetration testing) against core platform components to identify and remediate vulnerabilities
  • Being a force multiplier by championing security programs, patterns, standards, and documentation
  • Grow team capability through deliberate coaching; mentor senior engineers on secure API and protocol design
  • Travel up to 25% for customer engagement, architecture reviews, or team collaboration (Middle East)

Required Qualifications

  • 7+ years of experience, with a track record of shaping whole platform or infrastructure security areas rather than individual features
  • Deep hands-on experience designing and operating mTLS and TLS-based trust in distributed, multi-service systems, including certificate issuance, x509 validation, CA bundle management, and key rotation
  • Proven experience building authorization engines and policy models from scratch, including designing the interfaces that other engineers implement against
  • Strong background in identity and credential lifecycle: JWT and token issuance and verification, credential grants, session semantics, and revocation across federated or multi-tenant environments
  • Fluency in Go and protobuf/gRPC service design, with experience securing gRPC contracts and service-to-service communication in a service mesh or comparable architecture
  • A working threat modeling practice: you can reason about attacker paths across host and plugin boundaries, enrollment flows, and tenant isolation gaps, and translate that into concrete architecture
  • Exceptional communication skills across technical and non-technical audiences; you routinely interface with customers, product leaders, and engineering teams to gather requirements, articulate security trade-offs, and drive alignment from initial design to delivery
  • Has set technical direction others followed, and can point to a subsystem and explain what they built and what they'd do differently
  • Travel up to 25% for customer engagement, architecture reviews, or team collaboration (Middle East)

Desired Qualifications

  • Experience designing secure APIs for multi-tenant platforms, including tenant isolation guarantees and secure-by-default plugin or extension boundaries
  • Familiarity with policy engines such as Cedar or OPA, with experience deciding when to build a custom authorization model versus adopt one
  • Experience securing enrollment or bootstrap flows for fleets of untrusted or semi-trusted nodes joining a distributed system
  • Background in national security, intelligence, or defense environments with direct understanding of mission-critical operational requirements
  • Active security clearance (Secret or above); Top Secret preferred

Physical Requirements

  • Prolonged periods of sitting at a desk and working on a computer
  • Participation in virtual and in-person meetings
  • Ability to attend planned meetings and/or work in classified spaces for extended periods within the specified work regions
  • TRAVEL: International travel to Middle East and geopolitical hot zones, up to 25% per calendar year is required. Please apply only if you can meet this requirement

Orbis Benefits

Beyond the opportunity to work alongside practitioners who have operated at the mission edge, joining Orbis means real ownership over outcomes that matter — the chance to build technology that gives the United States Government and its allies a genuine decision advantage, not just another dashboard. From competitive retirement matching to a PTO policy that encourages real time off, we're committed to creating an environment where our team can do their best work and still have a life outside of it.

Our comprehensive benefits package is designed to meet the diverse needs of our employees and their families. A full list of benefits is shared with candidates following an initial conversation with our HR team, so you'll have a clear picture of the support and resources available to you as part of the Orbis team.

Orbis Locations

Orbis works in whatever arrangement the mission requires. Depending on the role, that might mean five days a week on a customer site, full-time in one of our offices, a hybrid schedule, or fully remote work — our team is spread across 25 states and four countries to match. We make sure every team member has the tools and access needed to do the work, wherever that work happens.

Travel is common across many Orbis roles, particularly those supporting customer missions in the field.

Orbis is headquartered in McLean, VA, with additional office locations in Taipei, Taiwan, and Canberra, Australia.

EEO Statement

Orbis Operations is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, disability, veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.

Orbis Operations is committed to creating an inclusive and diverse workplace where all employees are valued and respected. We encourage applications from all qualified individuals, including those from underrepresented groups.

In accordance with the Americans with Disabilities Act (ADA), Orbis Operations will provide reasonable accommodations to qualified individuals with disabilities throughout the application and employment process. If you require an accommodation, please contact us at [email protected].

Similar Jobs

8 Hours Ago
Easy Apply
Remote
United States
Easy Apply
168K-238K Annually
Senior level
168K-238K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Lead corporate endpoint security architecture with a focus on macOS, designing secure-by-default controls, automation, patching, software distribution, and security baselines across macOS, iOS, Windows, and Linux. Manage configurations through Terraform, GitOps, version control, CI pipelines, and automated rollouts. Partner with IT and security teams to improve telemetry, detection, response, auditability, and operational efficiency. Mentor engineers and serve as a senior escalation point for complex endpoint security issues in a fully remote environment.
Top Skills: BashFleetdmGitGitopsGoGoogle WorkspaceInfrastructure As CodeiOSJamf ProLdapLinuxmacOSOktaPowershellPythonTerraformWindows
3 Days Ago
Remote or Hybrid
182K-288K Annually
Senior level
182K-288K Annually
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
5 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
160K-195K Annually
Senior level
160K-195K Annually
Senior level
Fintech • Financial Services
Staff Security Engineer partners with Product, Engineering, and DevOps to embed security into application architecture, cloud infrastructure, and CI/CD processes. Responsibilities include secure design and code review, vulnerability remediation, AWS cloud security, WAF tuning, security automation in Python, SIEM and log pipeline contributions, endpoint controls, and security standards. The role requires deep expertise in application security, cloud security, or security automation, plus threat modeling and independent project ownership.
Top Skills: AsmAWSCi/CdCnappContainer OrchestrationDastGoIamInfrastructure As CodePythonRuby On RailsSastScaSIEMTerraformWaf

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account