Loading jobs…
Loading jobs…
Abnormal — Denver, Colorado
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. OUR MISSION True Anomaly delivers decisive capabilities for space superiority.
S. and its Allies to secure the space environment and counter threats from the ultimate high ground. OUR VALUES Be the offset.
We create asymmetric advantages with creativity and ingenuity. What would it take? We challenge assumptions to deliver ambitious results.
It’s the people. Our team is our competitive advantage and we are better together. YOUR MISSION Software is the central nervous system for True Anomaly's engineering and product thesis.
As we deploy our space operations platform into classified environments, identity and authorization become critical technical challenges requiring deep specialization. True Anomaly is seeking a highly experienced Senior Identity Authorization Engineer to build the multi-tenant identity infrastructure that enables secure operations at IL6 (SECRET) and beyond. You'll deploy and integrate Kubernetes-native identity platforms, implement fine-grained authorization models for space operations, and provide deep technical expertise on identity/auth during compliance processes.
Working closely with our security and platform teams, you'll evaluate and integrate modern authorization frameworks (ReBAC, SPIFFE/SPIRE, OPA), build policy-as-code enforcement systems, and ensure our identity architecture meets the rigorous standards required for classified environments. You do not need to have experience building space ground systems or experience in aerospace.
Benefits
including platinum healthcare, flexible work hours/location, highly competitive
Compensation
and a generous stock options package.
RESPONSIBILITIES
Architect and deploy Kubernetes-native identity and authorization infrastructure for IL6 (SECRET) multi-tenant environments Serve as a technical authority for identity/auth controls during ATO processes, documenting and evidencing compliance for IdP components Design and implement multi-tenant isolation strategies ensuring zero lateral movement between customer/program boundaries Evaluate, deploy, and harden self-hosted IdPs (Keycloak, Dex, Authentik, etc.) for classified Kubernetes clusters Design authorization models (RBAC, ABAC, ReBAC) for space operations use cases with fine-grained access control
Requirements
Implement workload identity frameworks (SPIFFE/SPIRE, K8s projected tokens) and service mesh authentication (Istio, Linkerd, Cilium) Build policy-as-code systems (OPA/Gatekeeper, Kyverno, Cedar) for automated compliance enforcement at runtime Integrate with government identity systems (CAC/PIV, LDAP, Active Directory) and legacy SAML 2.0 applications Collaborate with security team on secret management strategy (HashiCorp Vault, Azure Key Vault) with encryption key lifecycle for IL6 environments Work with application teams to define authentication/authorization contracts for microservices Partner with customers and government auditors during ATO processes to demonstrate compliance and address findings Stay current on emerging identity/auth technologies and evaluate applicability to classified environments
QUALIFICATIONS
S.