POSITION SUMMARYSince Axiom Space is a very complex work environment, we are looking for a resilient, high-energy
Identity Architect who is a critical visionary responsible for designing and implementing a robust, resilient, and compliant identity ecosystem. This role ensures that every human and non-human entity interacting with Axiom Space digital and physical assets is verified, authorized, and audited. You will bridge the gap between high-level compliance requirements specifically
NIST 800-53/171 and technical execution, ensuring that our identity fabric supports the protection of
ITAR/EAR controlled technical data while utilizing
FIPS 140-3 validated cryptographic modules.
KEY DUTIES & RESPONSIBILITIES- Zero Trust Architecture Design: Design and maintain a Zero Trust identity framework that enforces granular access control, ensuring least privilege across on-premises, cloud, and orbital mission system
- Regulatory Alignment: Architect identity solutions to meet NIST 800-53 (Security and Privacy Controls) and NIST 800-171 (Protecting CUI), specifically focusing on Identification and Authentication (IA) and Access Control (AC) families
- Export Control Engineering: Implement identity-based fencing and data tagging to ensure ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations) compliance, preventing unauthorized access to sensitive space technology by foreign nationals
- Cryptographic Standards: Ensure all identity providers and authentication workflows (MFA, SSO) utilize FIPS 140-3 validated encryption modules for protecting credentials and token in transit and at rest
- MITRE ATT&CK Mitigation: Map identity related threats (e.g., Valid Accounts T1078, Steal or Forge Kerberos Tickets T1558) to the MITRE ATT&CK framework; design architectural safeguards to detect and prevent Credential Access and Lateral Movement
- Lifecycle Management (IAM/IGA): Automate the identity lifecycle from onboarding and access to offboarding ensuring prompt revocation of access to mission critical system
- Privileged Access Management (PAM): Architect secure "break-glass" procedures and Just-In-Time (JIT) access for engineers
- Collaboration & Governance: Partner with the Incident Response teams to integrate identity telemetry for advanced behavioral analytics and threat hunting
- Communicating project progress, status, and potential issues to stakeholders and leadership
- Implementing and maintaining agile project management methodologies throughout the project lifecycle
- Perform additional job duties as assigned
QUALIFICATIONS: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Education & Experience- Bachelor's degree in Information Security, Computer Science, or a related technical field (experience may be considered in lieu of a degree) with 7+ years of experience in Identity and Access Management (IAM) architecture or high-level Cyber Security Engineering
- CISSP or CISM is highly desired
- Track record of making things happen in ambiguous, fast-moving environments
- Uses good judgement to problem-solve proactively, positively impacting hard challenges
- Demonstrated organization skills to meet tight deadlines with high quality results
Core Skills- Passion for space and the mission
- Entrepreneurial, growth mindset
- High EQ and ability to collaborate within teams and cross-functionally
- Tech-solutioning in using systems and tools to move smarter and faster
Core Competencies:Embody our core values of
leadership,
innovation, and
teamwork. In addition, to perform the job successfully, an individual should demonstrate the following competencies:
- Accountability
- Technical Rigor
- Execution Discipline
- Pride of Delivery
WORK ENVIRONMENT:Generally, an office environment, but can involve inside or outside work depending on the task.
Requirements- This position may require access to export controlled technical data or technology subject to NASA regulations, International Traffic in Arms Regulations (ITAR), or Export Administration Regulations (EAR). In accordance with U.S. export control laws, final candidates may be required to undergo additional export control screening to determine eligibility for access. Meeting these requirements is a condition of employment
- Management has the prerogative to select at any level for which the position is advertised
- Must be willing to work evenings and weekends as needed to meet critical project milestones
Physical Requirements- Work may involve sitting or standing for extended periods (90% of the time)
- May require lifting and carrying up to 25 lbs. (5% of the time)
- Equipment and Machines
- Standard office equipment (PC, phone, printer, etc.)