Skip to content
Northwood SpaceNorthwood SpaceLos Angeles, CA

Senior Detection and Response Engineer

Senior Detection and Response Engineer building and operating a SOC for a global satellite ground station network. Lead incident response, threat hunting, detection engineering, and forensics for mission-critical space infrastructure and national security systems.

120k – 190k/yr
On-site5+ YOESecurity Engineering

About the role

Responsibilities

  • Lead incident response and forensics - Own security incidents from detection through resolution across globally distributed ground stations and cloud infrastructure. Conduct digital forensics, malware analysis, and coordinate response efforts for incidents impacting national security missions.
  • Build and tune detection rules - Develop custom detection logic for SIEM platforms that can identify threats specific to satellite communications and ground station operations. Create behavioral analytics and threat hunting queries for distributed infrastructure.
  • Operate 24/7 security monitoring - Monitor security events across AWS multi-cloud environments, Linux-based ground station systems, and satellite communication networks. Triage alerts, investigate suspicious activity, and escalate critical threats.
  • Hunt threats across space infrastructure - Proactively search for advanced persistent threats targeting satellite ground stations, RF communications, and space-based assets. Develop threat hunting methodologies for unique attack vectors in space communications.
  • Create incident response playbooks - Build runbooks for security incidents specific to satellite ground stations and space communications. Develop escalation procedures and communication protocols for government customers and mission-critical operations.
  • Analyze threat intelligence - Research adversary tactics targeting aerospace and defense infrastructure. Integrate threat feeds into detection systems and brief stakeholders on emerging threats to space communications.
  • Build security automation - Develop Python/PowerShell scripts for automated incident response, threat hunting workflows, and security orchestration across distributed ground station networks.

Basic Qualifications

  • 5+ years of hands-on SOC operations, incident response, or threat hunting experience
  • Experience with SIEM platforms (Splunk, Sentinel, Chronicle) including custom rule development and advanced search techniques
  • Digital forensics and malware analysis skills with tools like Volatility, YARA, and hex editors
  • Proficiency in Python, PowerShell, or similar languages for security automation and threat hunting
  • Experience with endpoint security platforms (CrowdStrike, SentinelOne) and network security monitoring
  • Strong Linux forensics and log analysis skills across distributed systems
  • Knowledge of threat intelligence frameworks (MITRE ATT&CK, Diamond Model) and IOC analysis
  • Ability to obtain and maintain TS/SCI clearance

Preferred Qualifications

  • Experience with cloud security monitoring in AWS, Azure, or multi-cloud environments
  • Background in aerospace, defense, or critical infrastructure security operations
  • Experience with threat hunting in air-gapped or highly regulated environments
  • Knowledge of RF communications, satellite systems, or space-based asset security
  • Certifications such as GCIH, GCFA, GNFA, or similar incident response credentials
  • Experience building security orchestration and automated response (SOAR) workflows
  • Familiarity with government incident reporting requirements and procedures

Skills

SIEMSplunksentinelchronicledigital forensicsmalware analysisvolatilityyaraPythonPowerShellcrowdstrikesentinelonelinux forensicsmitre att&ckAWS
Cobalt.io

Senior Security Researcher

Cobalt.ioUnited States

Conduct advanced vulnerability research, reverse engineering, threat analysis, and exploit development across application, mobile, operating-system, and cloud platforms. The role requires at least five years of offensive-security experience or a strong published research track record.

120k – 150k/yrRemote5+ YOESecurity Engineering
Northwood Space

Senior Security Engineer

Northwood SpaceLos Angeles, CA

Senior Security Engineer building security architectures and controls from the ground up for Northwood's global phased array ground station network enabling real-time satellite communications. Requires 5+ years IaC experience, deep knowledge of FedRAMP/NIST 800-171, ability to obtain TS/SCI clearance, and ownership of incident response, compliance automation, and government liaison duties.

120k – 190k/yrOn-site5+ YOESecurity Engineering
Mozilla

Senior Security Engineer, Bug Bounty

MozillaUnited States

Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.

116k – 183k/yrRemote3+ YOESecurity Engineering
Northwood Space

Corporate Security Lead

Northwood SpaceLos Angeles, CA +1

Builds and leads corporate IT security operations including helpdesk, endpoint management, SIEM deployment, and team hiring for a space communications company. Requires 5+ years in IT/security/DevSecOps, hands-on tools like Okta and AWS, and compliance knowledge.

125k – 206k/yrOn-site5+ YOESecurity Engineering
Clickhouse

Senior Security Automation Engineer

ClickhouseUnited States

Senior Security Automation Engineer building centralized security telemetry, universal identity provisioning, and agentic risk engines to enable continuous compliance, self-healing controls, and real-time risk visibility at ClickHouse. Requires strong IAM/IGA and automation experience with Python, JS/TS, or Go.

125k – 205k/yrRemote5+ YOESecurity Engineering