Forge robust IT systems for Vast Space’s Haven Station, from cloud-first architectures to on-board networks. Machine cutting-edge solutions for real-time monitoring and maintenance in zero-gravity environments. Weld together secure, scalable infrastructures that support advanced manufacturing and research. Assemble load-bearing server racks and precision circuit boards, adhering to tight tolerances and torque specs. Program automated systems that inspect assembly lines and test hardware components. This is where the future of space exploration gets built.
View original listingAbout This Role
At Vast, our mission is to contribute to a future where billions of people are living and thriving in space. Vast is developing next-generation space stations to ensure a continuous human presence in space for America and its allies, enabling advanced microgravity research and manufacturing, and unlocking a new space economy for government, corporate, and private customers. Using an incremental, hardware-rich and low-cost approach, Vast is rapidly developing its multi-module Haven Station. Haven Demo’s 2025 success made Vast the only operational commercial space station company to fly and operate its own spacecraft. Next, Haven-1 is expected to become the world’s first commercial space station when it launches, followed by additional Haven modules to enable permanent human presence by 2030. Our team is all-in, committed to executing our mission safely and on time. If you want to work with the most talented people on Earth furthering space exploration for humanity, come join us.
Vast is looking for a IT DevOps Engineer, reporting to the Manager, IT Infrastructure, to support the development of the systems that will be required for the design and build of artificial-gravity human-rated space stations.
This will be a full-time, exempt position located in our Long Beach location.
You will have the opportunity to build a modern IT infrastructure from the ground up. We build our systems cloud-first, with an emphasis on researching and deploying the latest technologies and paradigms. You will identify opportunities to improve and expand our IT infrastructure to enhance speed, security, and ease of use. You will have the opportunity to plan, build, test, deliver, and maintain projects from start to finish. Likewise, you will prioritize establishing our IT function to be an ally to enhance employee productivity while balancing security.
Responsibilities:
- Architect and secure Kubernetes clusters on bare metal and cloud environments, emphasizing isolation, encryption, and policy enforcement.
- Develop and manage secure provisioning for bare metal systems, including DHCP, DNS, PXE/iPXE/HTTPBoot, and Linux, with an emphasis on measured boot, secure boot, and hardware trust.
- Build and maintain security tooling and automation (Go, Python, Bash) for provisioning, monitoring, and continuous security validation across environments.
- Collaborate with data center operations, hardware, and networking teams to enforce physical security, network segmentation, and zero-trust principles.
- Manage infrastructure configuration using GitOps (Git, Flux, Terraform) with security scanning and policy-as-code controls.
- Establish monitoring and alerting pipelines to detect, investigate, and respond to security events in infrastructure and cloud systems.
- Maintain and improve system documentation, runbooks, and security procedures for consistent, auditable, and repeatable infrastructure operations.
- Conduct threat modeling and risk assessments on infrastructure components, driving remediation to reduce the attack surface.
- Support incident response activities, including containment, analysis, and post-incident improvements to infrastructure security.
Minimum Qualifications:
- 3+ years experience designing, deploying, and managing highly available self-hosted security services such as a SIEM.
- 2+ years of experience in building modern DevOps tools & best practices: CI/CD systems, deployment tools (CloudFormation, Terraform, Pulumi, etc.).
- Deep expertise with the cloud and Kubernetes.
- Understanding of networking/security/auth constructs and requirements.
Preferred Skills & Experience:
- Experience with Kubernetes security (RBAC, PodSecurity, admission controllers, policy enforcement, and runtime security tooling).
- Experience building and maintaining observability pipelines (Falco, eBPF, OSQuery, or similar tooling).
- Proficiency with Linux and Kubernetes bootstrapping with a focus on secure provisioning.
- Experience collaborating with facilities, hardware, or network teams to enforce physical and logical security in a data center environment.
Senior IT DevOps Engineer I: $140,000 - $216,000
Senior IT DevOps Engineer II: $170,000 - $260,000
Senior IT DevOps Engineer III: $203,000 - $307,000
U.S. EXPORT CONTROL COMPLIANCE STATUS
The person hired will have access to information and items subject to U.S. export controls, and therefore, must either be a “U.S. person” as defined by 22 C.F.R. § 120.62 or otherwise eligible for deemed export licensing. This status includes U.S. citizens, U.S. nationals, lawful permanent residents (green card holders), and asylees and refugees with such status granted, not pending.EQUAL OPPORTUNITY
Requirements
- This will be a full-time, exempt position located in our Long Beach location.
- Responsibilities:
- Architect and secure Kubernetes clusters on bare metal and cloud environments, emphasizing isolation, encryption, and policy enforcement.
- Develop and manage secure provisioning for bare metal systems, including DHCP, DNS, PXE/iPXE/HTTPBoot, and Linux, with an emphasis on measured boot, secure boot, and hardware trust.
- Build and maintain security tooling and automation (Go, Python, Bash) for provisioning, monitoring, and continuous security validation across environments.
- Collaborate with data center operations, hardware, and networking teams to enforce physical security, network segmentation, and zero-trust principles.
- Manage infrastructure configuration using GitOps (Git, Flux, Terraform) with security scanning and policy-as-code controls.
- Establish monitoring and alerting pipelines to detect, investigate, and respond to security events in infrastructure and cloud systems.
- Maintain and improve system documentation, runbooks, and security procedures for consistent, auditable, and repeatable infrastructure operations.
- Conduct threat modeling and risk assessments on infrastructure components, driving remediation to reduce the attack surface.
Apply in 60 Seconds
No resume required. Just the basics.