Senior Detection and Response Engineer

Northwoodspace

$120K — $150K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on SOC operations, incident response, or threat hunting experience
  • Experience with SIEM platforms including custom rule development
  • Digital forensics and malware analysis skills with relevant tools
  • Proficiency in Python, PowerShell, or similar languages
  • Experience with endpoint security platforms and network monitoring
  • Strong Linux forensics and log analysis skills
  • Knowledge of threat intelligence frameworks and IOC analysis

Responsibilities

  • Lead incident response and forensics for security incidents
  • Build and tune detection rules for satellite communications
  • Operate 24/7 security monitoring across multi-cloud environments
  • Hunt for threats targeting satellite ground stations
  • Create incident response playbooks specific to space communications
  • Analyze threat intelligence and brief stakeholders on emerging threats
  • Build security automation scripts for incident response and threat hunting

Benefits

  • Opportunity to work on mission-critical national security operations
  • Engage in cutting-edge satellite communication security
  • Be part of a team innovating in space technology
  • Exposure to advanced threat detection and response frameworks
  • Support for ongoing training and development in security practices
Full Job Description
Role:

We're building the internet for space. Help us defend it.

Northwood is deploying a global network of phased array ground stations for mission-critical government and commercial space communications. We need a Senior Detection and Response Engineer to build and operate our security operations center, hunt threats across distributed satellite infrastructure, and lead incident response for systems that can't go down.

Responsibilities:
  • Lead incident response and forensics - Own security incidents from detection through resolution across globally distributed ground stations and cloud infrastructure. Conduct digital forensics, malware analysis, and coordinate response efforts for incidents impacting national security missions.
  • Build and tune detection rules - Develop custom detection logic for SIEM platforms that can identify threats specific to satellite communications and ground station operations. Create behavioral analytics and threat hunting queries for distributed infrastructure.
  • Operate 24/7 security monitoring - Monitor security events across AWS multi-cloud environments, Linux-based ground station systems, and satellite communication networks. Triage alerts, investigate suspicious activity, and escalate critical threats.
  • Hunt threats across space infrastructure - Proactively search for advanced persistent threats targeting satellite ground stations, RF communications, and space-based assets. Develop threat hunting methodologies for unique attack vectors in space communications.
  • Create incident response playbooks - Build runbooks for security incidents specific to satellite ground stations and space communications. Develop escalation procedures and communication protocols for government customers and mission-critical operations.
  • Analyze threat intelligence - Research adversary tactics targeting aerospace and defense infrastructure. Integrate threat feeds into detection systems and brief stakeholders on emerging threats to space communications.
  • Build security automation - Develop Python/PowerShell scripts for automated incident response, threat hunting workflows, and security orchestration across distributed ground station networks.

Basic Qualifications
  • 5+ years of hands-on SOC operations, incident response, or threat hunting experience
  • Experience with SIEM platforms (Splunk, Sentinel, Chronicle) including custom rule development and advanced search techniques
  • Digital forensics and malware analysis skills with tools like Volatility, YARA, and hex editors
  • Proficiency in Python, PowerShell, or similar languages for security automation and threat hunting
  • Experience with endpoint security platforms (CrowdStrike, SentinelOne) and network security monitoring
  • Strong Linux forensics and log analysis skills across distributed systems
  • Knowledge of threat intelligence frameworks (MITRE ATT&CK, Diamond Model) and IOC analysis
  • Ability to obtain and maintain TS/SCI clearance

Preferred Qualifications
  • Experience with cloud security monitoring in AWS, Azure, or multi-cloud environments
  • Background in aerospace, defense, or critical infrastructure security operations
  • Experience with threat hunting in air-gapped or highly regulated environments
  • Knowledge of RF communications, satellite systems, or space-based asset security
  • Certifications such as GCIH, GCFA, GNFA, or similar incident response credentials
  • Experience building security orchestration and automated response (SOAR) workflows
  • Familiarity with government incident reporting requirements and procedures

Similar Jobs

More Jobs at Northwoodspace

  • Senior Security Engineer
    $120K — $150K *
    Torrance, CA 90503 (Los Angeles County)
    Aerospace & Defense
    In-Person
  • Forward Deployed Engineer
    $120K — $150K *
    Washington, DC 20011 (District Of Columbia County)
    Aerospace & Defense
    In-Person
  • Mechanical Engineer (Product Owner)
    $100K — $130K *
    Torrance, CA 90503 (Los Angeles County)
    Aerospace & Defense
    In-Person
  • Market Access Manager
    $90K — $130K *
    Torrance, CA 90503 (Los Angeles County)
    Telecommunications & Hardware
    In-Person
  • PCB Designer
    $90K — $120K *
    Torrance, CA 90503 (Los Angeles County)
    Aerospace & Defense
    In-Person

More Aerospace & Defense Jobs

Find similar Senior Detection and Response Engineer jobs: