# Senior Detection and Response Engineer

**Company:** [Northwood Space](https://hotfix.jobs/companies/northwood-space)
**Location:** Los Angeles, CA
**Role:** Security Engineering
**Salary:** $120k – $190k/yr
**Experience:** 5+ years
**Skills:** SIEM, Splunk, sentinel, chronicle, digital forensics, malware analysis, volatility, yara, Python, PowerShell, crowdstrike, sentinelone, linux forensics, mitre att&ck, AWS
**Posted:** 2026-07-24

> Senior Detection and Response Engineer building and operating a SOC for a global satellite ground station network. Lead incident response, threat hunting, detection engineering, and forensics for mission-critical space infrastructure and national security systems.

## Job Description

## Responsibilities
- Lead incident response and forensics - Own security incidents from detection through resolution across globally distributed ground stations and cloud infrastructure. Conduct digital forensics, malware analysis, and coordinate response efforts for incidents impacting national security missions.
- Build and tune detection rules - Develop custom detection logic for SIEM platforms that can identify threats specific to satellite communications and ground station operations. Create behavioral analytics and threat hunting queries for distributed infrastructure.
- Operate 24/7 security monitoring - Monitor security events across AWS multi-cloud environments, Linux-based ground station systems, and satellite communication networks. Triage alerts, investigate suspicious activity, and escalate critical threats.
- Hunt threats across space infrastructure - Proactively search for advanced persistent threats targeting satellite ground stations, RF communications, and space-based assets. Develop threat hunting methodologies for unique attack vectors in space communications.
- Create incident response playbooks - Build runbooks for security incidents specific to satellite ground stations and space communications. Develop escalation procedures and communication protocols for government customers and mission-critical operations.
- Analyze threat intelligence - Research adversary tactics targeting aerospace and defense infrastructure. Integrate threat feeds into detection systems and brief stakeholders on emerging threats to space communications.
- Build security automation - Develop Python/PowerShell scripts for automated incident response, threat hunting workflows, and security orchestration across distributed ground station networks.

## Basic Qualifications
- 5+ years of hands-on SOC operations, incident response, or threat hunting experience
- Experience with SIEM platforms (Splunk, Sentinel, Chronicle) including custom rule development and advanced search techniques
- Digital forensics and malware analysis skills with tools like Volatility, YARA, and hex editors
- Proficiency in Python, PowerShell, or similar languages for security automation and threat hunting
- Experience with endpoint security platforms (CrowdStrike, SentinelOne) and network security monitoring
- Strong Linux forensics and log analysis skills across distributed systems
- Knowledge of threat intelligence frameworks (MITRE ATT&CK, Diamond Model) and IOC analysis
- Ability to obtain and maintain TS/SCI clearance

## Preferred Qualifications
- Experience with cloud security monitoring in AWS, Azure, or multi-cloud environments
- Background in aerospace, defense, or critical infrastructure security operations
- Experience with threat hunting in air-gapped or highly regulated environments
- Knowledge of RF communications, satellite systems, or space-based asset security
- Certifications such as GCIH, GCFA, GNFA, or similar incident response credentials
- Experience building security orchestration and automated response (SOAR) workflows
- Familiarity with government incident reporting requirements and procedures

## Similar roles

- [Senior Security Researcher](https://hotfix.jobs/jobs/a61a61dd-461a-45b9-946e-4d325c3ebb50) - Cobalt.io - Remote - $120k – $150k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9a4dea4c-1109-4598-ad7c-195de3c857ee) - Northwood Space - Los Angeles, CA - $120k – $190k/yr
- [Senior Security Engineer, Bug Bounty](https://hotfix.jobs/jobs/5532c56d-7528-4966-9a33-ffec20c4a012) - Mozilla - Remote - $116k – $183k/yr
- [Corporate Security Lead](https://hotfix.jobs/jobs/2a1defd4-9d21-4eb0-906b-0feb7fd4acc1) - Northwood Space - Los Angeles, CA - $125k – $206k/yr
- [Senior Security Automation Engineer](https://hotfix.jobs/jobs/2e4e1230-924e-4c2c-8df4-cdee5ef22cdb) - Clickhouse - Remote - $125k – $205k/yr

**Apply:** https://hotfix.jobs/jobs/f7821d51-7239-43cf-8e2b-75cf58b7e739
**Canonical:** https://hotfix.jobs/jobs/f7821d51-7239-43cf-8e2b-75cf58b7e739