About the RoleMuon seeks a Senior Security Engineer to join our Security Engineering & IT team. The ideal candidate brings deep expertise across multiple security domains and can operate independently to protect Muon's infrastructure, data, and people. You will own and advance our security posture across endpoints, networks, cloud environments, and identity systems while contributing to compliance efforts including NIST 800-171 and ITAR/EAR requirements.
This position is hybrid and requires working on-site in our San Jose, CA office three days per week or fully remote from an approved U.S. location.
Responsibilities- Design, deploy, and manage endpoint security solutions (EDR/XDR) across macOS and Windows fleets, including policy tuning, alert triage, and incident response
- Own network security architecture including firewall rule management, IDS/IPS tuning, network segmentation, and VPN infrastructure
- Lead vulnerability management program - run scans, prioritize findings, coordinate remediation with engineering teams, and track closure metrics
- Administer and harden IAM systems (Okta, AWS IAM) including SSO integrations, conditional access policies, privilege access reviews, and lifecycle automation
- Develop and maintain security monitoring and alerting using SIEM platforms, building detection rules and response playbooks
- Conduct security assessments of new tools, vendors, and architectural changes before deployment
- Drive cloud security posture management across AWS environments including IAM policies, S3 bucket security, security group reviews, and CloudTrail/GuardDuty monitoring
- Support CMMC Level 2 and NIST SP 800-171 compliance - maintain SSP control narratives, collect evidence, and prepare for assessments
- Develop and deliver security awareness training and phishing simulation campaigns
- Lead or support incident response activities including containment, forensic analysis, root cause determination, and post-incident reporting
- Maintain and improve data loss prevention (DLP) controls for CUI and sensitive data
- Contribute to security policy development and keep documentation current as the environment evolves
Qualifications- 5+ years of experience in information security or security engineering roles
- Strong hands-on experience with endpoint detection and response platforms (CrowdStrike, SentinelOne, or similar)
- Demonstrated experience managing enterprise vulnerability scanning tools (Tenable, Qualys, Rapid7, or similar)
- Deep understanding of identity and access management principles and hands-on Okta or Azure AD administration
- Proficiency with cloud security in AWS (IAM, VPC, Security Groups, CloudTrail, GuardDuty, Config)
- Experience with SIEM platforms (Splunk, Sentinel, Elastic, or similar) for log analysis and detection engineering
- Solid networking knowledge - firewalls, proxies, DNS security, network segmentation, packet analysis
- Familiarity with compliance frameworks such as NIST 800-171, CMMC, SOC 2, or ISO 27001
- Excellent written and verbal communication skills - able to convey risk and technical findings to both engineers and leadership
Nice-to-Have Skills- Relevant certifications (CISSP, GIAC, CEH, AWS Security Specialty, or similar)
- Experience with infrastructure-as-code security (Terraform, CloudFormation) and CI/CD pipeline security
- Background in environments subject to ITAR/EAR export control requirements
SalaryThe salary range for this role is $184,000 - $208,000, plus a competitive equity grant and comprehensive benefits package. Final compensation will be determined based on skills, qualifications, experience, and geographic location as assessed during the interview process.