NASA Jet Propulsion Laboratory California Institute of Technology

Security and Network Engineer

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Computer Engineering, or related field plus 5+ years of experience in network administration and cybersecurity.
  • Hands-on experience with Arista, Cisco, or similar enterprise networking hardware.
  • Experience managing enterprise firewalls and network security perimeters.
  • Familiarity with network penetration testing and security auditing techniques.
  • Expertise in cybersecurity principles, including network access control and threat mitigation.
  • Working knowledge of federal compliance frameworks like NIST SP 800-53 and RMF.
  • Ability to qualify as a US person under ITAR regulations.

Responsibilities

  • Coordinate NASA ATO Compliance & Reporting, ensuring documentation meets federal mandates.
  • Develop and audit System Security Plans (SSPs) and manage Plan of Action and Milestones (POA&M) tracking.
  • Implement NIST and NASA cybersecurity frameworks for network architectures and system configurations.
  • Design and maintain firewall structures and intrusion prevention systems using Palo Alto firewalls.
  • Collaborate with Data Center staff to ensure security and network alignment in infrastructure.
  • Monitor and mitigate security threats with network-level tools and centralized logging.
  • Perform related duties as assigned by management.

Benefits

  • Competitive health, dental, and vision insurance coverage.
  • Generous paid time off including vacation, holidays, and sick leave.
  • Access to on-site daycare facilities and an athletic center.
  • Professional development opportunities including training and conferences.
  • Exceptional retirement savings plan and membership access to campus resources.
Full Job Description
Job Summary

IPAC at Caltech is seeking a Security and Network Engineer to support the cybersecurity, compliance architecture, and high-performance network infrastructure powering world-class NASA, NSF, and privately funded ground and spaceborne observatories. As a member of the IPAC Support Group (ISG) Data Center Engineering team, you will focus heavily on shaping IPAC's overall cybersecurity posture while working alongside other network, systems, and database engineers to build and defend the vital pipelines that connect the global astronomical community to invaluable scientific data.

IPAC, situated within the Division of Physics, Mathematics, and Astronomy at Caltech (www.caltech.edu), provides science operations, pipeline processing, user support, and data services for high-profile missions including the Nancy Grace Roman Space Telescope, SPHEREx, Euclid, the Near-Earth Object Surveyor, and the Zwicky Transient Facility (ZTF). Our diverse portfolio of research archives includes multi-petabyte datasets like the NASA/IPAC Infrared Science Archive (IRSA), alongside highly curated reference repositories like the NASA Extragalactic Database (NED) and the NASA Exoplanet Archive, which are key research references for modern astrophysics and exoplanet science.

This role prioritizes robust cybersecurity governance and technical systems defense. While cybersecurity and federal compliance are the primary focuses of this position, your core network engineering expertise will directly inform your security architecture. As part of a close-knit team of about ten engineers, you will help shape IPAC's cybersecurity architecture, coordinate federal compliance activities, and provide network-security expertise across the organization.

Essential Job Duties and Responsibilities

As an IPAC Security and Network Engineer, your role will be to:
  • Manage NASA ATO Compliance & Reporting: Coordinate IPAC's compliance, documentation, and reporting requirements necessary to achieve and maintain our NASA Authority to Operate (ATO) status. Lead the generation, aggregation, and continuous monitoring of evidence required to prove compliance with federal mandates.
  • Develop Security Plans & Frameworks: Design, maintain, and audit comprehensive System Security Plans (SSPs) and related Plan of Action and Milestones (POA&M) tracking for individual space missions, research projects, and IPAC-wide infrastructure.
  • Implement NIST & NASA Frameworks: Translate federal compliance guidelines-specifically NIST SP 800-53 security controls, FIPS requirements, and NASA-specific IT security directives-into enforceable network architectures, system configurations, and operational workflows.
  • Manage Enterprise Security Perimeters: Design, deploy, audit, and maintain firewall rules, intrusion prevention systems, and secure zone configurations across our enterprise edge, utilizing Palo Alto firewalls and related security platforms.
  • Provide Network Consultation & Backup Support: Collaborate with Data Center staff to apply security and networking expertise to IPAC infrastructure. Leverage your network engineering background to ensure compliance frameworks align practically with our network, systems, and software architectures. Provide cross-functional backup support to peer network engineers managing core Arista and Cisco routing and switching environments.
  • Monitor & Mitigate Threats: Implement and manage network-level monitoring, centralized logging, and security alerting tools to proactively analyze vulnerabilities, detect anomalies, and defend our data center environments.
  • Perform other duties as assigned.

Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Computer Engineering, or a related field, plus 5+ years of relevant experience in network administration and cybersecurity (or an equivalent combination of education and experience).
  • Solid hands-on network design and administration experience, particularly with Arista, Cisco, or similar enterprise networking hardware.
  • Proven experience managing enterprise firewalls and network security perimeters.
  • Experience with network penetration testing and security auditing. Experience with packet capture and data analysis.
  • Demonstrated expertise in cybersecurity principles, including network access control, threat mitigation, and secure architecture design.
  • Working familiarity with federal cybersecurity compliance frameworks (e.g., NIST SP 800-53, RMF).
  • Qualify as a US PERSON as defined by ITAR regulations: A US person is a citizen of the United States, a lawful permanent resident alien of the US ("Green Card" holder), or an individual granted refugee or asylee status under US law.

Preferred Qualifications

Beyond these basic qualifications, there are skills and experiences which will give you a head start here. We are a specialized environment looking for a well-rounded engineer who thrives in a shared-responsibility model. If you have experience in a few of these areas, you will hit the ground running, but even if these don't yet describe you and your experience, we would still like to hear from you:
  • Security Policy Development and Implementation: Experience drafting, updating, and enforcing organizational IT security policies, acceptable use guidelines, and incident response procedures in an academic or research setting.
  • Compliance Frameworks & ATO Lifecycle: Practical experience steering systems through the federal cybersecurity Risk Management Framework (RMF) to secure or maintain an ATO. Direct familiarity with auditing NIST SP 800-53 controls, FIPS standards, or related NASA cybersecurity guidelines.
  • Security & Vulnerability Tooling: Hands-on experience with the deployment, configuration, and operational oversight of enterprise security tools, such as Rapid7 for vulnerability scanning and reporting, and CrowdStrike for endpoint protection.
  • Systems & Scripting: Strong Linux systems administration skills (Red Hat or Debian) and experience leveraging scripting/programming languages (e.g., Python, Bash) for security analysis, log parsing, or task automation.
  • Cloud Security: Experience implementing and monitoring security controls within public cloud environments (e.g., AWS).
  • Mission Alignment: A genuine interest in science, astronomy, or space exploration. Understanding mission objectives helps us build better systems for the scientists and staff we support.
  • Teamwork & Collaboration: A strong collaborative mindset, a willingness to share operational duties, and the ability to communicate security and compliance constraints clearly and pragmatically within an active engineering group.

Required Documents
  • Full Resume.
  • Cover Letter (briefly highlighting key qualifications and fit for this role).
  • Names and Contact information of 3 professional references.

Application Details
  • This is an on-site position at the Caltech campus in Pasadena, California. Remote work is normally allowed up to one day per week.
  • Applicants for this position must be a United States (US) person as defined by ITAR regulations - A US person is a citizen of the United States, a lawful permanent resident alien of the US ("Green Card" holder), or individuals granted refugee and asylee status under US law.
  • Applications are due by August 31, 2026

Life at IPAC

People choose to work at IPAC for many reasons, and our casual, employee-centric culture often leads to fulfilling, long-term careers and positive relationships. Whether in science, engineering, or administration, IPAC staff share a unique sense of pride in knowing their individual talents support human discovery.

Unlike traditional corporate tech, IPAC emphasizes sustainable workloads and a healthy work-life balance: after-hours work is rare, shared across the operations team, and typically limited to exceptional situations. We actively support ongoing professional development, including training, conferences, and skill development aligned with your career goals. Caltech's benefits program offers a highly competitive benefits package, an exceptional 403(b) defined contribution plan, and access to campus facilities including the athletic center, libraries, on-site daycare, and Athenaeum club membership.

Hiring Range

$47.75 - $62.25 Per Hour

The salary of the finalist(s) selected for this role will be set based on a variety of factors, including but not limited to, internal equity, experience, education, specialty and training.

As one of the largest employers in Pasadena, CA, Caltech is committed to providing comprehensive benefits to eligible employees and their eligible dependents. Our benefits package includes competitive compensation, health, dental, and vision insurance, retirement savings plans, generous paid time off (vacation, holidays, sick time, parental leave, bereavement, etc.), tuition reimbursement, and more. Non-benefit eligible employees will have access to some benefits such as onsite counseling and sick time. Learn more about our benefits and staff perks.

About NASA Jet Propulsion Laboratory California Institute of Technology

NASA Jet Propulsion Laboratory (JPL) is a federally funded research and development center located in Pasadena, California. It is managed by the California Institute of Technology (Caltech) for NASA. JPL is responsible for the design, development, and operation of robotic spacecraft and instruments used for space exploration. The laboratory has been involved in many historic missions, including the Mars rovers, Voyager missions, and the recent Juno mission to Jupiter. JPL has a strong focus on research and development, with a large number of scientists and engineers working on cutting-edge technologies. The laboratory also has partnerships with several universities and research institutions, providing opportunities for collaboration and education.
Learn more about NASA Jet Propulsion Laboratory California Institute of Technology
Size
6,000 employees
Industry

Similar Jobs

More Jobs at NASA Jet Propulsion Laboratory California Institute of Technology

More Information Technology Jobs

Find similar Security and Network Engineer jobs: