Northwood logo
NorthwoodPosted 1 month ago

Senior Detection and Response Engineer

$120,000–$190,000 year

On-siteLos Angeles, California, United States or Torrance, California, United States

Full TimeSenior LevelStartupSpace Communications

Job Summary

Lead incident response and forensics by owning security incidents from detection through resolution across globally distributed ground stations and cloud infrastructure. Develop custom detection logic for SIEM platforms, create behavioral analytics queries, and proactively hunt for advanced persistent threats targeting satellite ground stations and RF communications. Operate 24/7 security monitoring to triage alerts and investigate suspicious activity within AWS multi-cloud environments and Linux-based systems. Build runbooks for security incidents, integrate threat intelligence feeds, and develop Python/PowerShell scripts for automated response workflows. Requires TS/SCI clearance, 5+ years of SOC operations experience, and proficiency in digital forensics and threat hunting methodologies.

Required Qualifications

  • 5+ years of hands-on SOC operations, incident response, or threat hunting experience
  • Experience with SIEM platforms (Splunk, Sentinel, Chronicle) including custom rule development and advanced search techniques
  • Digital forensics and malware analysis skills with tools like Volatility, YARA, and hex editors
  • Proficiency in Python, PowerShell, or similar languages for security automation and threat hunting
  • Experience with endpoint security platforms (CrowdStrike, SentinelOne) and network security monitoring
  • Strong Linux forensics and log analysis skills across distributed systems
  • Knowledge of threat intelligence frameworks (MITRE ATT&CK, Diamond Model) and IOC analysis
  • Ability to obtain and maintain TS/SCI clearance

Desired Qualifications

  • Experience with cloud security monitoring in AWS, Azure, or multi-cloud environments
  • Background in aerospace, defense, or critical infrastructure security operations
  • Experience with threat hunting in air-gapped or highly regulated environments
  • Knowledge of RF communications, satellite systems, or space-based asset security
  • Certifications such as GCIH, GCFA, GNFA, or similar incident response credentials
  • Experience building security orchestration and automated response (SOAR) workflows
  • Familiarity with government incident reporting requirements and procedures

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce