Varda Space Industries Logo

Varda Space Industries

Cybersecurity Analyst

Posted Yesterday
Be an Early Applicant
In-Office
El Segundo, CA, USA
110K-140K Annually
Mid level
In-Office
El Segundo, CA, USA
110K-140K Annually
Mid level
Operate daily security monitoring and alert triage, coordinate with a managed SOC partner, maintain incident and event logs, produce audit and compliance evidence, and support continuous monitoring and incident response documentation for certification readiness.
The summary above was generated by AI
About Varda

Low Earth orbit is open for business. Varda is accelerating the development of commercial space infrastructure, from in-orbit pharmaceutical processing to reliable and economical reentry capsules. Varda’s W-Series vehicles are built, designed, and operated by Varda in-house, including the pharmaceutical processing payloads, the capsules, the C-PICA heatshields, and the satellite buses.

From life-saving pharmaceuticals to more powerful fiber optics, there is a world of products used on Earth today that can only be manufactured in space. Varda is accelerating innovation in the orbital economy by creating both the products and infrastructure needed so space can directly benefit life on Earth. Our mission is to expand the economic bounds of humankind.  

Our team is uniquely suited to accomplishing this goal, with leadership and staff comprised of veterans from SpaceX, Blue Origin, major pharmaceutical companies and Silicon Valley. Varda was founded in January 2021 by Will Bruey and Delian Asparouhov with significant backing from world class investors including Khosla Ventures, Lux Capital, Founders Fund, Caffeinated Capital, General Catalyst, and Also Capital.  

Varda is headquartered in El Segundo, California, where we have offices and a production facility where our vehicles, equipment, and materials are built, integrated, and tested. Varda also has offices in Washington, DC and Huntsville, AL. 

Join Varda, and work to create a bustling in-space ecosystem.

Cybersecurity Analyst 

InfoSec Organization •  Reports to CISO  •  On-site 

About the Role 

We are hiring a Cybersecurity Analyst to own our day-to-day security monitoring function and produce the evidence required to achieve and maintain our cybersecurity certification. This role is the operational core of our cybersecurity organization, responsible for managing alert triage across our cybersecurity tool stack, coordinating with our managed SOC partner, documenting security events, and keeping our monitoring and incident response activities continuously evidenced and ready for review. 

This is a hands-on, high-accountability role reporting directly to the CISO. You will work closely with our InfoSec Engineer, Compliance Program Manager, and our managed security operations partner. You will help set up and monitor our security tool stack, which spans endpoint protection, network detection, secure web access, application control, and identity management. You establish the monitoring cadence that keeps our security posture visible and our compliance evidence current. 

The Immediate Mission 

You will be assisting in getting the organization assessment ready: 

  • Take ownership of daily alert triage across our security tool stack, reviewing and dispositioning alerts before they age without review 
  • Serve as the internal liaison to our managed SOC partner, receiving their monitoring reports, validating their outputs, and integrating their work into our compliance evidence.
  • Build and maintain the incident log, ensuring every security event is captured, classified, and closed with supporting documentation.
  • Produce audit log evidence demonstrating that our systems are monitored, logs are retained, and events are reviewed on a consistent schedule.
  • Deliver regular monitoring reports to our compliance tracking platform, ensuring up-to-date evidence flows into our central repository.
  • Coordinate with the Compliance Program Manager to ensure monitoring and incident response evidence is organized and ready for assessor review.

What You’ll Own 

Security Monitoring and Alert Triage 

  • Own daily triage of alerts from our network detection platform and other security tools, reviewing, classifying, escalating, and documenting dispositions.
  • Serve as the primary internal point of contact for our managed security operations partner, receiving daily and weekly alert summaries, validating completeness, and tracking open items to closure.
  • Maintain the security event log, a running record of alerts, dispositions, escalations, and outcomes that serve as core compliance evidence 
  • Identify patterns in alert data and surface recurring issues to the InfoSec Engineer for remediation.
  • Ensure continuous monitoring coverage is documented and demonstrable, a direct requirement of the cybersecurity framework we are certifying against 

Incident Response Documentation 

  • Own the incident log, documenting every security event from detection through closure, including timeline, classification, containment actions, and resolution.
  • Coordinate with our managed security operations partner on incident triage, escalation, and post-incident reporting, ensuring their outputs are captured and integrated into our internal records.
  • Maintain the Incident Response Plan as a living document, updating it based on lessons learned and ensuring it reflects actual operational procedures.
  • Produce incident response evidence for our compliance assessment, including incident logs, escalation records, containment documentation, and post-incident reviews.
  • Support the Compliance Program Manager in mapping incident documentation to the applicable compliance controls.

Log Management and Audit Evidence 

  • Pull and organize log samples from our endpoint protection, network security, web access, application control, and identity management platforms, demonstrating that logging is active and coverage is comprehensive.
  • Document log configuration, including retention settings, coverage scope, and alert thresholds, as evidence that our monitoring posture meets compliance requirements 
  • Produce regular monitoring reports to our compliance tracking platform, ensuring the system reflects the current operational status 
  • Coordinate with the InfoSec Engineer to ensure logging is enabled and configured correctly across all systems in scope.
  • Maintain organized evidence packages, including log samples, triage records, and monitoring reports, ready for assessor review.

Managed SOC Coordination 

  • Serve as the day-to-day operational liaison to our managed security operations partner, tracking deliverables, validating report quality, and escalating gaps to the CISO.
  • Ensure monitoring outputs from our security partner are received on schedule and integrated into internal compliance records.
  • Own the deliverable log, tracking what has been received, what is outstanding, and what has been incorporated into evidence packages.
  • Coordinate with the Compliance Program Manager to ensure third-party security operations outputs satisfy our compliance requirements.

Continuous Monitoring and Compliance Platform 

  • Maintain our compliance tracking platform as the operational source of truth for monitoring evidence, uploading reports, log reviews, and control status updates on a regular cadence 
  • Support the Compliance Program Manager in maintaining continuous compliance readiness after certification 
  • Flag gaps in monitoring coverage, log retention, or incident documentation to the CISO and Compliance Program Manager 
  • Participate in periodic control effectiveness reviews, providing operational data and evidence to support ongoing assessments 

Basic Qualifications 

  • 3 or more years in cybersecurity operations, SOC analyst, or cybersecurity monitoring role 
  • Hands-on experience with endpoint protection, network detection, or security event management platforms in an operational capacity, including reviewing alerts, triaging events, and documenting outcomes 
  • Demonstrated ability to write and maintain incident response documentation, such as incident logs, incident reports, and post-incident reviews 
  • Experience working with or alongside a managed security operations provider, receiving their output, and integrating it into internal security operations 
  • Familiarity with audit logging requirements and log review processes, including an understanding of what logging coverage means and how to demonstrate it 
  • Organized, detail-oriented, and able to maintain documentation quality under day-to-day operational pressure 
  • Comfortable working in a lean security organization where you own your domain independently 

Preferred Qualifications 

  • Direct experience supporting a formal cybersecurity compliance effort, with an understanding of how operational security outputs map to compliance evidence 

Our current security tool stack and the experience we are looking for: 

  • Endpoint protection and detection — we use CrowdStrike 
  • Network detection and response — we use Darktrace 
  • Secure web gateway and network security — we use Zscaler 
  • Application allows listing and execution control — we use ThreatLocker 
  • Identity and access management event monitoring — we use Okta 
  • Compliance tracking and evidence management — we use Vanta 
  • Relevant certifications are a plus but not required. We recognize Security+, CySA+, GCIA, GCIH, and CISA as strong signals for this role. Candidates working toward or eligible for CISSP are equally welcome. 
  • Familiarity with compliance-driven security environments, where day-to-day monitoring and incident documentation are part of a larger audit and certification process, is a plus but not required.
  • Familiarity with security information and event management platforms such as Splunk, Microsoft Sentinel, or Chronicle, relevant as we continue to build out our log aggregation capabilities 
  • A bachelor’s degree in computer science, Information Technology, Cybersecurity, or a related field is a plus. Equivalent hands-on experience, military cybersecurity training, or industry certifications are equally considered. 

Compensation

  • Cybersecurity Analyst: $110,000 - $140,000
  • Leveling and base salary are determined by job-related skills, education level, experience level, and job
  • performance
  • You will be eligible for long-term incentives in the form of stock options and/or long-term cash awards
  • Offer compensation also includes the ability to purchase company stock through the Employee Stock Purchase Plan
Benefits

Varda offers a comprehensive benefits package designed to support health, financial well‑being, and a high‑quality workplace experience. Below is an overview of what full‑time employees receive (at this time, interns receive a subset of benefits): 

Health & Wellness 

  • Flexible PTO policy + 12 paid holidays 
  • 100% company-paid Medical, Dental, and Vision insurance plans for employees and dependents with FSA and employer-matched HSA options
  • Voluntary accident, hospital, critical illness, and pet insurance 
  • $120/month wellness reimbursement for gym and fitness expenses 
  • 12 weeks of parental leave (with supplemental disability leave for CA mothers) 
  • Family building, pregnancy, parenting and menopause benefits via Maven Clinic 
  • Sponsored One Medical memberships for employees and their dependents 

Financial & Retirement 

  • Substantial incentive equity in a fully funded space start-up 
  • 401(k) retirement plan with 6% employer match (immediately vested)
  • $20/pay period cell phone reimbursement 
  • Relocation support for new hires, if needed 

Workplace Experience & Perks 

  • Fully stocked kitchen with lunch provided daily and dinner provided twice weekly 
  • Company and team-bonding events, happy hours and mission-success celebrations
  • Complimentary EV charging
  • Dog-friendly office space 🐕 

ITAR Requirements

Varda, like all employers, must ensure that its employees working in the United States are lawfully authorized to work in the U.S. Additionally, our employees are exposed to and have access to certain export-controlled items. Because our employees are provided access to export-controlled items, our policy is to only hire “U.S. persons” who are permitted to have access to our technology without an export license.
“US person” means: U.S. citizen, U.S. lawful permanent resident, or protected individual as defined by 8 U.S.C. 1324b(a)(3) (i.e., individual admitted to the U.S. as a refugee or granted asylum).


E-Verify Statement

Varda Space Industries, Inc. participates in the U.S. Department of Homeland Security E-Verify program. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about the E-Verify program.

E-Verify Notice                                                               Right To Work Notice

Read more                                                                             Read more

Varda Space Industries is an Equal Opportunity Employer.  We celebrate diversity and are committed to creating an inclusive environment for all employees. Candidates and employees are always evaluated based on merit, qualifications, and performance. We will never discriminate on the basis of race, color, gender, national origin, ethnicity, veteran status, disability status, age, sexual orientation, gender identity, martial status, mental or physical disability, or any other legally protected status.

HQ

Varda Space Industries El Segundo, California, USA Office

225 S Aviation Blvd., El Segundo, CA, United States, 90405

HQ

Varda Space Industries El Segundo, California, USA Office

225 S Aviation blvd, El Segundo, California, United States, 90045

Similar Jobs

Yesterday
In-Office
170K-229K Annually
Expert/Leader
170K-229K Annually
Expert/Leader
Aerospace • Information Technology • Professional Services • Security • Software
Manage a 24x7 SOC for federal customers: lead incident detection, triage, analysis, and escalation. Maintain SIEM and monitoring tools, develop TTPs, enforce policies, conduct risk assessments, drive SOC process improvements, and communicate incidents and summaries to leadership while ensuring compliance with DoW contract requirements.
Top Skills: Continuous MonitoringFirewallsIdsIncident ResponseNetwork Traffic AnalysisSecurity Operations Center (Soc)SIEM
Yesterday
In-Office
100K-150K Annually
Mid level
100K-150K Annually
Mid level
Information Technology • Consulting • Cybersecurity • Defense
Perform cyber resiliency analysis for tactical SDR waveforms, support system security engineering and RMF implementation for tactical radio overlays, collaborate with vendors and DoD stakeholders, produce technical documentation and reports, and provide status updates while supporting Security Team processes.
Top Skills: C5IsrRadio Frequency (Rf)Risk Management Framework (Rmf)Security Classification Guides (Scg)Software Defined Radios (Sdr)Waveforms
21 Days Ago
In-Office
110K-170K Annually
Expert/Leader
110K-170K Annually
Expert/Leader
Aerospace • Information Technology • Cybersecurity • Defense
Support Navy IT and cybersecurity operations across global Live Virtual Constructive (LVC) environments. Ensure compliance with DoD policies, RMF, and STIGs; monitor and troubleshoot systems; operate in CONUS/OCONUS settings; and collaborate with government stakeholders and technical teams.
Top Skills: Dod Cybersecurity PoliciesEnterprise Network SecurityLive Virtual Constructive (Lvc)RmfStigs

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account