Albedo

IT & Security Engineer

Albedo$106K — $114K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in IT operations, infrastructure, or security engineering, with accountability for production systems.
  • Proven ability to independently resolve unfamiliar problems with minimal direction.
  • Experience leveraging AI tools to enhance work productivity and clarity.
  • Expertise in agentic engineering with a focus on observability and access control for production systems.
  • Strong proficiency in infrastructure as code, particularly Terraform across AWS.
  • Proven ability to manage code in production, using languages like Python or Go, with inclusive debugging skills.
  • Experience in vulnerability management across infrastructures and applications.

Responsibilities

  • Own and ensure the reliability of all major IT systems and security controls.
  • Adapt swiftly to various IT domains and tasks throughout the day.
  • Develop automation and internal tools to maximize team efficiency.
  • Implement infrastructure as code practices using Terraform in AWS environments.
  • Manage identity in Entra ID, including authentication and access controls.
  • Oversee endpoint management and compliance using Intune across device fleets.
  • Conduct incident response and correction write-ups to improve future outcomes.

Benefits

  • Equity compensation for employees.
  • 4% direct matching 401k plan.
  • Comprehensive health insurance coverage for employees and dependents.
  • Parental leave and childcare support.
  • Flexible vacation and sick leave from the start.
  • 12 recognized company holidays.
  • $100 monthly wellness stipend.
Full Job Description
About This Role:

Albedo builds and operates satellites in Very Low Earth Orbit. As IT & Security Engineer you own a wide surface alongside our IT and security lead: identity, endpoints, cloud infrastructure, network, detection and response, compliance obligations, and a long tail of SaaS. The team scales by turning process into code, and this role is measured by how much faster the rest of the company moves because of what you build.
What You'll Do:
  • Own the systems the company runs on, measured by whether they work: identity, endpoints, cloud infrastructure, network, detection and response, and the compliance controls underneath them.
  • Expect to move between unrelated domains in the same day or hour. Breadth is the defining feature of this role, and switching context without losing the thread is the skill that carries you through it.
  • Build the internal tooling and automation that lets a small team cover a surface that would otherwise require a large one. This is a first-class part of the job, not something you get to when tickets are quiet.
  • Own infrastructure as code in Terraform across AWS.
  • Run identity in Entra ID: authentication, conditional access, SSO and SCIM integrations, group and role design, and privileged access.
  • Manage endpoints in Intune: enrollment, configuration and compliance baselines, and update rings across the fleet.
  • Operate Microsoft Sentinel and Defender XDR: detection tuning, hunting queries, and triage that closes every incident with a classification you can defend.
  • Drive our CMMC Level 2, NIST 800-171 (R2 and R3), and ITAR programs. Controls are implemented as code and evidence is produced continuously through our own tooling and Vanta, so that an audit becomes a query against systems we already run.
  • Triage and remediate vulnerabilities across the infrastructure we run, and drive findings in application code and containers to closure with the software teams that own them.
  • Own the Linux estate: provisioning, hardening, patching, and bringing it under real configuration management for the first time.
  • Own the network: DNS, routing, remote access, and the boundary between on-prem infrastructure and cloud.
  • Keep the logging pipeline everything above feeds healthy, so that detections and audit evidence come from sources we trust.
  • Respond to incidents, write the postmortem, then fix the class of problem behind it.
  • Decide what to work on. Nobody hands you a backlog. You find the highest-leverage thing and justify why it was the highest-leverage thing.
Your Ideal Skills and Experience:

  • Six-plus years across IT operations, infrastructure, or security engineering, with at least two where you owned production systems and were accountable when they broke.
  • A track record of closing loops in domains you did not start out knowing. Given an unfamiliar problem, you take it to a finished, working solution without someone decomposing it for you first. This is the single thing we care most about.
  • Regularly uses AI tools as essential leverage to accelerate work, improve clarity, and multiply output, and verifies before shipping.
  • Depth in agentic engineering: agents that take real action against production systems, with the access control, observability, and evaluation needed to trust them, deployed as shared services the whole company can use.
  • Infrastructure as code is your default.
  • Owns code in production: Python, TypeScript, Go, or similar, at the level of a service or CLI that other people depend on. Whether you write it yourself or direct a model to write it matters far less than whether you can review it, debug it, and stay on the hook when it breaks.
  • You build tools for other people, and you care whether anyone actually adopted what you shipped.
  • Judgment about blast radius. You know which changes are reversible in five minutes, and which ones are silently wrong for a quarter, and you slow down for the second kind.
  • Linux as a managed platform for real users, not just servers: you have kept engineering workstations or lab machines patched, compliant, and supportable, and you can work out what a misbehaving host is actually doing.
  • Identity fluency in Entra ID or an equivalent, deep enough to design an access model.
  • Real ownership of something security-relevant: a detection, an incident, an identity model, an access boundary.
  • Vulnerability management experience across both infrastructure and application findings.
  • On-prem network architecture design and implementation
  • On-site in Broomfield, CO.
Nice to have:
  • Microsoft 365 and Entra ID in GCCH.
  • A cybersecurity background: SIEM and EDR operations, detection engineering, threat hunting, or incident response.
  • Exposure to CMMC Level 2, NIST 800-171, or ITAR. Genuinely not required: we will teach the frameworks. The hard part is knowing which technical mechanism actually satisfies a control, and that is learned here.
  • Intune at fleet scale across macOS, Windows, and Linux.
  • Having been an early member of a small infrastructure or security team, where you decided your own scope.
Salary Range:
  • $106,529 - $114,555 per year


Compensation and Benefits for Full-Time Roles:
    • Employee friendly equity compensation
    • 4% direct matching 401k
    • Health Insurance: 100% employee coverage & 75% dependent coverage
    • Parental leave and childcare coverage
    • Flexible vacation and sick time from day one
    • 12 company holidays
    • $100 monthly wellness benefit
    • Relocation package if not based in Denver


The final compensation package is subject to change if the candidate's experience and company need drive a different job level than originally slated for the position.

Relocation: Relocation support for this position is available

Applicants must be a U.S. Person as defined under 22 CFR 120.62

#LI-Onsite

Research shows that while men apply to jobs where they meet an average of 60% of the criteria, women and other underrepresented people tend to only apply when they meet 100% of the qualifications. At Albedo, we'd rather hear from you. We care more about how you think than which boxes you check. We value people who do the math, make their assumptions explicit, and ask the annoying questions: what breaks, what's the failure mode, what has to be true for this to work? If that sounds like you, apply, even if you don't meet every line.

About Albedo

ALBEDO Telecom is a company that designs and manufactures products for the telecom industry including testers, synchronization nodes and networking devices. Typical users are R&D laboratories, Mobile and Telecom operators to verify and install the infrastructures that support any kind of applications based on voice, video and data. It is headquartered in Barcelona, Spain in the European Union.
Learn more about Albedo

Similar Jobs

More Jobs at Albedo

More Information Technology Jobs

Find similar IT & Security Engineer jobs: