Senior Security Engineer
- $173,000–$260,000 per year
- Hybrid
- All infrastructure & security jobs
- FullTime
- Engineering
About the role
About Beacon AI
We’re a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer, more efficient, and more capable. Backed by top investors, we’ve secured a dozen Department of Defense contracts and partnered with major airlines to deliver mission-critical systems. We operate without silos or heavy processes. Small, focused teams own what they build, ship quickly, and learn fast, pushing the boundaries of how humans and AI work together in aviation.
Role Overview
We are seeking a Senior Security Engineer to ensure the security and integrity of Beacon AI’s systems and data across commercial and Department of Defense (DoD) environments. This is a hands-on security engineering role focused on designing and operating secure systems, partnering closely with software teams, and protecting mission-critical flight safety technology while meeting applicable security and compliance standards, including FedRAMP and DoD Impact Level (IL) requirements.
What You’ll Do
Design and implement secure architectures across applications, cloud infrastructure, backend services, and in-cockpit edge systems, including environments built to FedRAMP Moderate baseline and DoD IL4/IL5 environments.
Protect sensitive data through strong controls for access management, encryption, and secure data handling, consistent with NIST 800-53 and NIST 800-171 requirements.
Identify, assess, and mitigate security risks through vulnerability assessments, penetration testing, and security reviews.
Lead incident response efforts, including detection, containment, remediation, and follow-up analysis.
Integrate security into the SDLC by partnering with software teams on threat modeling, secure code review, and automated security checks in CI/CD and infrastructure-as-code.
Implement and operate security monitoring and logging to detect and respond to threats in real time.
Support authorization and compliance efforts (ATO packages, SSPs, POA&Ms) for FedRAMP and DoD accreditation processes.
Help maintain CMMC 2.0 readiness and alignment with DFARS cybersecurity clauses across the environment.
Secure our AI systems, including LLM and retrieval-based features, against risks like prompt injection, data leakage, and model misuse.
What Will Make You Successful
5+ years of hands-on experience in security engineering roles securing complex systems and data, including production cloud environments (AWS or AWS GovCloud strongly preferred)
Strong knowledge of security principles, threat modeling, and defensive security practices.
Experience with common security tools and technologies (e.g., SIEM, IDS/IPS, vulnerability scanning, encryption).
Familiarity with security and compliance frameworks such as NIST 800-53/800-171, ISO 27001, and CMMC.
Direct experience with FedRAMP authorization processes (ATO, SSP, POA&M) and/or DoD Impact Level (IL4/IL5) environments.
Comfort being an early security owner: setting priorities, building from scratch, and balancing risk against a fast-moving product roadmap.
Proven ability to collaborate effectively with software engineers on secure system design.
Hands-on mindset with strong analytical and problem-solving skills.
Bonus Points
Passion for aviation and a desire to improve air travel efficiency and safety.
Experience working with aviation, aerospace, or DoD customers, particularly in ITAR-controlled environments.
Familiarity with zero trust architectures or advanced security approaches.
Experience with StateRAMP, IL5/IL6 systems, or classified/controlled unclassified information (CUI) handling.
Experience securing mobile (iOS), embedded, or edge devices operating in disconnected or constrained environments.
Relevant security certifications such as CISSP, CISM, or CEH.
Work Location
This is a hybrid role based in San Carlos, CA, with 3+ days per week onsite and the option to work remotely on remaining days.
Perks & Benefits (Full-Time Employees)
Healthcare: 100%* of employee medical premiums covered; 25% for dependents
Time Off: 3 weeks PTO plus 13+ paid company holidays
401(k): Offered (no current employer match, but we are committed to enhancing this benefit in the future)
Due to U.S. export control regulations, we can only hire U.S. Persons (U.S. citizens, Green Card holders, lawful permanent residents, or individuals granted asylum or refugee status). We are unable to provide visa sponsorship or support visa transfers. All work must be performed in the United States.
Beacon AI is an equal opportunity employer and does not discriminate based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected characteristic. We prohibit harassment or discrimination of any kind in the workplace and comply with all applicable federal, state, and local employment laws.
Description as published by Beacon AI.