Information Assurance Engineer I
Opens the original job posting in a new tab.
Job description
Vast is developing next-generation space stations and space infrastructure using an incremental, hardware-rich, and low-cost approach. Vast is rapidly developing its multi-module Haven Station to ensure a continuous human presence in space for America and its allies, enabling advanced microgravity research and manufacturing, and unlocking a new space economy for government, corporate, and private customers. Haven Demo’s 2025 success made Vast the only operational commercial space station company to fly and operate its own spacecraft.
Next, Haven-1 is expected to become the world’s first commercial space station when it launches in 2027, followed by additional Haven modules. Additionally, the company recently announced Vast Satellite , a high-power satellite product line leveraging its space station components and the heritage of Haven Demo. Headquartered in Long Beach, California , and with more than 1,000 employees and over a billion dollars in private capital, Vast has built the facilities required to manufacture and operate America’s next space station.
The company plans to develop future habitats and systems for the Moon and Mars, dedicated space stations for government partners, and other crewed systems that will unlock the expanding long-term space economy. Vast is looking for an Information Assurance Engineer I , reporting to the Information Security Manager , to assist in the deployment and maintenance of the organization's growing information security compliance program. The Information Assurance Engineer I supports the development of security policies and procedures, ensuring compliance with pertinent regulations and security standards (i.e.
NIST SP 800-171 Rev 2, NIST 800-53 Rev 5). This will be a full-time , exempt position located in our Long Beach location.
Responsibilities
- Support compliance documentation and evidence collection activities for NIST SP 800-171, NIST SP 800-53, CMMC 2.0, and applicable ITAR/EAR requirements across corporate and mission environments
- Assist with the implementation, validation, and continuous monitoring of security controls and compliance requirements
- Support automated compliance workflows, including evidence collection, policy checks, control validation, and audit preparation
- Assist in maintaining integrations between security tools such as EDR, SIEM, vulnerability scanners, and asset inventory platforms and compliance/ticketing systems
- Utilize approved AI and LLM/machine learning tools to support security analysis, documentation review, evidence organization, and identification of potential compliance gaps
- Help create and maintain compliance dashboards, metrics, and automated reports to track security and compliance posture
- Support risk assessments, change management activities, remediation tracking, and internal and external security assessments
- Monitor security systems, networks, and applications for compliance issues and assist with identifying and addressing compliance drift
- Partner with Information Security Engineering and other technical teams to support the implementation and validation of security controls
- Assist with maintaining compliance records, policies, procedures, and system security documentation
- Participate in security and compliance audits, assessments, and readiness activities
- Provide information security and compliance-related support and training as required of work
Minimum Qualifications
- 1+ years of experience supporting information security, compliance, risk management, or cybersecurity efforts in the Defense Industrial Base, aerospace/space industry, or a similar regulated environment
- Familiarity with security standards and frameworks such as NIST SP 800-53, NIST SP 800-171, NIST CSF, or CMMC
- Basic understanding of cloud security and compliance concepts in AWS, Google Cloud Platform (GCP), Azure, or similar environments
- Experience supporting security control monitoring, documentation, evidence collection, and remediation activities
- Experience supporting security assessments, gap assessments, self-assessments, or compliance audits
- Familiarity with security tools such as SIEM, IDS/IPS, EDR, vulnerability scanners, and asset management platforms
- Basic understanding of APIs and how security tools and platforms can be integrated or automated
- Familiarity with workflow automation, orchestration, or scripting tools such as n8n, Tines, SOAR platforms, Python, PowerShell, or similar technologies
- Working knowledge of Controlled Unclassified Information (CUI) protection requirements and security controls applicable to Defense Industrial Base environments
- Strong documentation, organization, communication, and problem-solving skills
Preferred Skills
& Experience:
- Possess an active certification listed under DoD 8140 IAM Level I/II and/or IAT Level I/II, such as Security+ CE, SSCP, or similar
- Experience using AI/LLM tools to support security analysis, documentation, research, or compliance activities
- Exposure to automated evidence collection or continuous compliance monitoring
- Familiarity with infrastructure-as-code or configuration management tools such as Terraform, Ansible, or similar
- Basic scripting experience with Python, PowerShell, Bash, or similar languages
- Exposure to MCP (Model Context Protocol) or other AI integration patterns for security tooling
- Experience working with GRC, ticketing, compliance, or security workflow platforms
- Ability to work effectively in a fast-paced, rapidly growing environment and collaborate with engineering, IT, security, and program teams Additional
Requirements
- Ability to travel up to 10% of the time
- Willingness to work overtime, or weekends to support critical mission milestones
- Ability to lift up to 25lbs unassisted
- Specific certifications, as appropriate Pay Range: Information Assurance Engineer I: $98,400.00 - $144,000.00 Pay Range: California $98,400 — $144,000 USD COMPENSATION AND BENEFITS Base salary will vary depending on job-related knowledge, education, skills, experience, business needs, and market demand. Salary is just one component of our comprehensive compensation package. Full-time employees also receive company equity, as well as access to a full suite of compelling benefits and perks, including: medical, dental, and vision coverage for employees and dependents, generous paid time off; up to 20+ days of vacation for exempt staff and up to 10+ days of vacation for non-exempt staff with the ability to cash-out unused vacation annually, paid parental leave, short and long-term disability insurance, life insurance, access to a 401(k) retirement plan, ClassPass credits, personalized mental healthcare through Spring Health, and other discounts and perks. We also take pride in offering exceptional food perks, with snacks, drip coffee & onsite barista, cold drinks, and dinner meals remaining free of charge, and lunch subsidized as part of Vast’s ongoing commitment to providing high-quality meals for employees. U.S. EXPORT CONTROL COMPLIANCE STATUS The person hired will have access to information and items subject to U.S. export controls, and therefore, must either be a “U.S. person” as defined by 22 C.F.R. § 120.62 or otherwise eligible for deemed export licensing. This status includes U.S. citizens, U.S. nationals, lawful permanent residents (green card holders), and asylees and refugees with such status granted, not pending. EQUAL OPPORTUNITY Vast is an
Equal Opportunity
Employer; employment with Vast is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.