← Back to job listings
TA
Senior Identity & Authorization Engineer
True Anomaly · Long Beach, CA, United States
About The Role
Join True Anomaly, a pioneering company in the space security industry. As a Senior Identity & Authorization Engineer, you will play a critical role in building the multi-tenant identity infrastructure that enables secure operations in classified environments. You will have ownership of challenging, greenfield problems and a chance to fundamentally impact the outcome of future conflict and the future of the company.
- Architect and deploy Kubernetes-native identity and authorization infrastructure for IL6 (SECRET) multi-tenant environments.
- Evaluate, deploy, and harden self-hosted IdPs (Keycloak, Dex, Authentik, etc.) for classified Kubernetes clusters.
- Design and implement multi-tenant isolation strategies ensuring zero lateral movement between customer/program boundaries.
- You do not need to have experience building space ground systems or experience in aerospace
- Zero Trust Principles: Deep understanding of NIST SP 800-207 and practical zero trust architecture patterns
- Authorization Design: Implemented RBAC, ABAC, or ReBAC authorization models in production systems
- Experience: 10+ years in platform/security engineering with 5+ years focused on identity, authentication, or authorization systems
- Clearance: Eligible for TS/SCI clearance (U.S. citizen or lawful permanent resident), active clearance strongly preferred
- Multi-Tenant Architecture: Designed and implemented proper tenant isolation (zero lateral movement, strong security boundaries) for SaaS, defense, or high-assurance systems
- Identity Infrastructure: Production experience deploying/operating at least one K8s-native IdP (Keycloak, Dex, etc.) or enterprise IAM system
- Scripting/Automation: Proficiency in Python, Go, or Bash for automation and tooling
- Compliance Frameworks: Working knowledge of NIST 800-53, CMMC Level 3+, or FedRAMP High requirements
- Kubernetes Production Experience: Deployed and operated production Kubernetes clusters with 3+ years experience
- Active TS/SCI clearance (or ability to start immediately upon clearance grant)
- IL4/IL5 deployment and operations experience (IL6 is nice-to-have but not required)
- ATO Experience: Participated in at least one ATO process for NIST 800-53, CMMC, FedRAMP, or IL4/IL5 systems
- Experience with modern authorization frameworks (SpiceDB, Authzed, OpenFGA, Ory Keto)
- SPIFFE/SPIRE workload identity implementation experience
- Service mesh authentication (Istio, Linkerd, Cilium) in production
- HashiCorp Vault or enterprise secret management in classified or high-assurance environments
- CAC/PIV card integration and PKI certificate management
- Policy-as-code (OPA/Rego, Kyverno, Cedar) for runtime enforcement
- Experience in aerospace, defense, intelligence community, or national security space
- Startup or fast-paced environment experience (balance velocity with compliance rigor)
- CISSP, CCSP, or other security certifications
- Contributed to open-source identity/auth projects (Keycloak, Dex, OPA, SPIFFE, etc.)
- Kubernetes CKS (Certified Kubernetes Security Specialist) certification
- Experience with cross-domain solutions (CDS) or multi-level security (MLS) systems
- Previous experience at defense prime, IC contractor, or FAANG Gov (AWS/Azure/Google public sector)
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring