Senior Security Engineer
Beacon AI is hiring a Senior Security Engineer. It pays $173k-$225k a year and Level rates it ; you can apply on Level.
AI in this role
Ensure the security and compliance of AI aviation systems in cloud and DoD environments.
About Beacon AI
We’re a fast-moving team of aviators, engineers, and operators building an AI platform to make flying safer, more efficient, and more capable. Backed by top investors, we’ve secured a dozen Department of Defense contracts and partnered with major airlines to deliver mission-critical systems. We operate without silos or heavy processes. Small, focused teams own what they build, ship quickly, and learn fast, pushing the boundaries of how humans and AI work together in aviation.
Role Overview
We are seeking a Senior Security Engineer to ensure the security and integrity of Beacon AI’s systems and data across commercial and Department of Defense (DoD) environments. This is a hands-on security engineering role focused on designing and operating secure systems, partnering closely with software teams, and protecting mission-critical flight safety technology while meeting applicable security and compliance standards, including FedRAMP and DoD Impact Level (IL) requirements.
What You’ll Do
Design and implement secure architectures across applications, cloud infrastructure, backend services, and in-cockpit edge systems, including environments built to FedRAMP Moderate baseline and DoD IL4/IL5 environments.
Protect sensitive data through strong controls for access management, encryption, and secure data handling, consistent with NIST 800-53 and NIST 800-171 requirements.
Identify, assess, and mitigate security risks through vulnerability assessments, penetration testing, and security reviews.
Lead incident response efforts, including detection, containment, remediation, and follow-up analysis.
Integrate security into the SDLC by partnering with software teams on threat modeling, secure code review, and automated security checks in CI/CD and infrastructure-as-code.
Implement and operate security monitoring and logging to detect and respond to threats in real time.
Support authorization and compliance efforts (ATO packages, SSPs, POA&Ms) for FedRAMP and DoD accreditation processes.
Help maintain CMMC 2.0 readiness and alignment with DFARS cybersecurity clauses across the environment.
Secure our AI systems, including LLM and retrieval-based features, against risks like prompt injection, data leakage, and model misuse.
What Will Make You Successful
5+ years of hands-on experience in security engineering roles securing complex systems and data, including production cloud environments (AWS or AWS GovCloud strongly preferred)
Strong knowledge of security principles, threat modeling, and defensive security practices.
Experience with common security tools and technologies (e.g., SIEM, IDS/IPS, vulnerability scanning, encryption).
Familiarity with security and compliance frameworks such as NIST 800-53/800-171, ISO 27001, and CMMC.
Direct experience with FedRAMP authorization processes (ATO, SSP, POA&M) and/or DoD Impact Level (IL4/IL5) environments.
Comfort being an early security owner: setting priorities, building from scratch, and balancing risk against a fast-moving product roadmap.
Proven ability to collaborate effectively with software engineers on secure system design.
Hands-on mindset with strong analytical and problem-solving skills.
Bonus Points
Passion for aviation and a desire to improve air travel efficiency and safety.
Experience working with aviation, aerospace, or DoD customers, particularly in ITAR-controlled environments.
Familiarity with zero trust architectures or advanced security approaches.
Experience with StateRAMP, IL5/IL6 systems, or classified/controlled unclassified information (CUI) handling.
Experience securing mobile (iOS), embedded, or edge devices operating in disconnected or constrained environments.
Relevant security certifications such as CISSP, CISM, or CEH.
Work Location
This is a hybrid role based in San Carlos, CA, with 3+ days per week onsite and the option to work remotely on remaining days.
Perks & Benefits (Full-Time Employees)
Healthcare: 100%* of employee medical premiums covered; 25% for dependents
Time Off: 3 weeks PTO plus 13+ paid company holidays
401(k): Offered (no current employer match, but we are committed to enhancing this benefit in the future)
Due to U.S. export control regulations, we can only hire U.S. Persons (U.S. citizens, Green Card holders, lawful permanent residents, or individuals granted asylum or refugee status). We are unable to provide visa sponsorship or support visa transfers. All work must be performed in the United States.
Beacon AI is an equal opportunity employer and does not discriminate based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, veteran status, or any other protected characteristic. We prohibit harassment or discrimination of any kind in the workplace and comply with all applicable federal, state, and local employment laws.
How we rate this
Senior Security Engineer at Beacon AI rates 60 out of 100 for how much of the daily work is AI. That makes it Works on AI (AI Level 3 of 4). The level is about AI in the job, not seniority.
Works on AI. The daily work is on AI products, without building the model.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where security engineering was part of your work. What did you do?
- Tell me about a project where penetration testing was part of your work. What did you do?
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where threat modeling was part of your work. What did you do?
- Tell me about a project where secure code review was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: Security Engineering, Penetration Testing, Incident Response, Threat Modeling, and Secure Code Review. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them. A tool named with nothing behind it rarely survives a human read.
- Show where AI is part of your daily process, not a one-off project. This role expects it to be a running habit.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get new cybersecurity jobs (Works on AI ●●●○ or higher) by email
One email a week with the new cybersecurity jobs (Works on AI ●●●○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that work on AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step