Jobs and Careers
E-

Principal Cybersecurity Lead

E-SPACE
United Statesfull_timeVerifiedPosted 12 Aug 2026

About the role

Ready to make connectivity from space universally accessible, secure and actionable? Then you’ve come to the right place!

E-Space is bridging Earth and space to enable hyper-scaled deployments of Internet of Things (IoT) solutions and services. We are building a highly-advanced low Earth orbit (LEO) space system that will fundamentally change the design, economics, manufacturing and service delivery associated with traditional satellite and terrestrial IoT systems.

We’re intentional, we’re unapologetically curious and we’re 100% committed to innovate space-based communications and deliver actionable intelligence that will expand global economies, protect space and our planet and enhance our overall quality of life.

What is this role:

We are seeking a deeply technical, hacker-savvy Principal Cybersecurity Lead to defend the company as an active operator, security engineer, and incident leader. This person will understand how modern attackers discover, enter, persist, move laterally, exfiltrate data, and hide. They will continuously track active threat campaigns, newly exploited vulnerabilities, attacker tools, and changes in the global threat landscape, then convert that intelligence into practical defenses.

This is not a policy-only, advisory-only, or dashboard-only position. The successful candidate will make consequential security decisions, personally investigate suspicious activity, write production-quality detection and response code, interrogate network and endpoint telemetry, validate controls through authorized adversarial testing, and drive incidents to a technically sound conclusion. They must be willing to go deep enough to understand the vulnerability, exploit path, affected systems, attacker behavior, business impact, containment choice, and permanent corrective action.

What you will do:

Threat intelligence and attacker awareness

  • Continuously monitor active threat campaigns, ransomware groups, state-sponsored actors, criminal ecosystems, exploit trends, malware families, phishing infrastructure, and newly weaponized vulnerabilities relevant to the company.
  • Translate threat intelligence into detection hypotheses, hunting queries, control changes, exposure reviews, and prioritized defensive action - not passive reporting.
  • Maintain a current view of attacker tactics, techniques, and procedures using practical frameworks such as MITRE ATT&CK while recognizing where real-world behavior departs from frameworks.
  • Build trusted relationships with relevant industry, vendor, law-enforcement, and information-sharing communities as appropriate.
  • Enterprise security architecture and attack-surface ownership

    • Understand and secure enterprise routing, switching, segmentation, DNS, DHCP, VPN, wireless, firewalls, proxies, email, identity providers, directory services, SaaS, cloud, remote access, endpoints, servers, containers, and CI/CD environments.
    • Map external and internal attack surfaces, trust boundaries, privileged paths, crown-jewel systems, internet exposure, shadow IT, third-party access, and plausible attack chains.
    • Drive secure architecture decisions across identity, zero-trust access, network segmentation, secrets, cryptography, logging, endpoint protection, cloud controls, backup resilience, and recovery.
    • Partner with infrastructure, product, software, IT, legal, privacy, and physical-security teams to reduce systemic risk without creating unusable controls.
    • Detection engineering, coding and automation

      • Write, review, test, and maintain code that detects malicious or abnormal behavior across network, endpoint, identity, application, and cloud telemetry.
      • Develop behavioral analytics, correlation logic, enrichment pipelines, investigation tools, automated containment workflows, and repeatable forensic utilities.
      • Create high-quality SIEM/EDR/NDR detections and hunting content; measure precision, recall, coverage, false positives, alert latency, and operational value.
      • Use languages such as Python, Go, Rust, PowerShell, shell, SQL, or equivalent as the problem requires; work comfortably with APIs, event streams, structured logs, packet data, and large security datasets.
      • Apply software-engineering discipline to security code: version control, peer review, tests, deployment controls, observability, rollback, documentation, and secure secrets handling.
      • Threat hunting, insider risk and incident response

        • Proactively hunt for weak signals, anomalous sequences, livin

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

E-SPACE

View company profile →