How to apply for Senior Security Risk Analyst
Muon Space
About Muon Space
Muon Space builds Earth-sensing satellite technology focused on climate action. The company is small enough that a security risk engineer can work across every function, from engineering to supply chain. This is a chance to shape risk and compliance practices at a satellite company rather than inherit an existing program.
About the role
You will run security risk assessments across the whole company, maintain a risk register, and give leadership a current view of Muon's risk posture. You will also drive remediation with the teams that own each risk and assess new tools, vendors, and process changes before adoption. The role includes mapping risks and controls to NIST 800-171 and ITAR/EAR compliance requirements.
A typical day
A typical day could include running a risk assessment with an engineering or operations team, updating the risk register, and reviewing a new vendor or tool before adoption. You might also meet with leadership to walk through current risk posture or work with a team on closing out an open remediation item. Ask the hiring manager how the team splits time between assessments, compliance work, and remediation tracking.
Who Muon Space is looking for
- Has run risk assessments across multiple domains (engineering, IT, operations, finance, supply chain), not just one area
- Can build or apply a consistent risk framework with likelihood and impact scoring, risk acceptance, and exceptions
- Has hands-on experience mapping risks and controls to NIST 800-171 and ITAR/EAR compliance requirements
- Works independently, communicates risk clearly to leadership, and can push remediation with teams that do not report to them
Tips for this application
- Name NIST 800-171 and ITAR/EAR explicitly in your resume and cover letter. This role calls out both, so show where you have applied them.
- Describe a risk register or risk framework you built or maintained. Include how you scored likelihood and impact and how you tracked items to closure.
- Give one example of assessing a vendor, tool, or architecture change before adoption. State the risk you found and what changed as a result.
- Show cross-functional work. The role spans engineering, IT, operations, finance, and supply chain, so list risks you assessed outside of security or IT.
- Address location clearly. The job allows on-site in San Jose, hybrid, or remote from an approved U.S. location. State your location and preference up front.
What to cover in your cover letter
Cover letter should cover: (1) a specific risk assessment you led end to end, including how you prioritized findings; (2) your experience with NIST 800-171 and ITAR/EAR control mapping; (3) how you drove remediation with teams that did not report to you; (4) why satellite or Earth-sensing infrastructure interests you and what you know about Muon Space's work.
Draft a cover letterResearch before applying
- Read Muon Space's public material on its satellite missions and Earth-sensing payloads to understand what data and infrastructure you would be protecting.
- Look up NIST SP 800-171 and ITAR/EAR basics if you have gaps, and note where they overlap with satellite and defense-adjacent work.
- Check Muon Space's careers page and any public statements on its security or compliance posture to see what is already in place.
- Find out how the Security Engineering & IT team is structured and who the role reports to. Ask in the interview if it is not public.
Likely interview topics
Based on the job description, expect questions about:
- Walk through a risk assessment you led. How did you scope it, score risks, and get remediation done?
- How have you mapped controls to NIST 800-171? Which controls were hardest to satisfy and why?
- Describe how you handle ITAR/EAR requirements in a technical environment. What have you done in practice?
- How do you assess a new vendor or tool before adoption? Give a concrete example.
- How do you present risk posture to leadership when remediation is slow or a team accepts a risk?
Common mistakes to avoid
- Treating this as a generic security analyst role. The job is risk-focused across all functions, not just monitoring or incident response.
- Claiming NIST 800-171 or ITAR/EAR experience without specifics. Expect questions on which controls you implemented and how.
- Ignoring the compliance side. The role explicitly includes NIST 800-171 and ITAR/EAR, so a resume that only covers technical security misses half the job.
Deadline
No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.