Senior Software Engineer - Security Engineering
About Loft Federal Loft Federal is committed to delivering the U.S. national security space community a fast, affordable, and streamlined pathway to orbit. As a wholly owned U.S. subsidiary of Loft Orbital Solutions, Inc., we specialize in providing mission-ready space infrastructure with unmatched efficiency. At Loft, we empower our team with autonomy, ownership, and bold problem-solving opportunities while fostering a tight-knit, supportive environment. We believe that diversity, inclusivity, and community are the foundation of an open and innovative culture. We value kind, collaborative, and mission-driven teammates who excel in problem-solving and communication—because great solutions come from great teams. Are you ready to embark on this exciting journey with us? We are seeking a Senior Software Security Engineer to lead the design, implementation, and assessment of the security architecture for our flight and ground software systems. This is not a traditional IT compliance role; you are a hands-on software engineer first, with a deep passion for building security into the core of a product. You will be responsible for everything from hands-on coding of security services to integrating automated controls into our CI/CD pipelines and ensuring our architecture meets the stringent requirements for a government Authority to Operate (ATO). You will spend your time writing code, hardening our infrastructure, participating in threat modeling, and mentoring our talented software engineers in secure development practices. You will be the team's expert on balancing cutting-edge security with the very real constraints of embedded systems and the compliance demands of NIST and CMMC frameworks. What You'll Do Architect & Design: Ground-up design, hands-on development, and team-centric collaboration to the Zero Trust security architecture for our flight software, including services for authentication/authorization, cryptographic key management, secure data storage, and secure transport. Lead the research and evaluation of security features, protocols, and third-party tools to make data-driven architectural decisions. Harden Mission Infrastructure: Collaborate with infrastructure teams to secure our onboard flight software platform, including hardening embedded Linux systems, segmenting spacecraft network enclaves, configuring onboard IAM policies, and mitigating operational cybersecurity risks across the asset lifecycle. Implement Security Controls in the SDLC: Work with the DevOps team to integrate and automate security controls directly into our CI/CD pipelines, including Static/Dynamic Application Security Testing (SAST/DAST), Software Composition Analysis (SCA), SBOM generation, and container vulnerability scanning using tools like SonarQube. ...