Senior Security Engineer, Operations

K2 Space

$150K — $190K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in security operations or incident response in a tech environment
  • Hands-on experience with SIEM administration and tuning
  • Proven ability to lead security incidents from detection through resolution
  • Strong understanding of attacker tactics and the MITRE ATT&CK framework
  • Experience investigating telemetry across various operating systems and platforms
  • 2+ years of development experience in a programming language like Python or Go, or relevant degree
  • Familiarity with security best practices and log analysis at scale

Responsibilities

  • Own detection and response for corporate security incidents
  • Administer and enhance the SIEM, including log management and rule tuning
  • Develop and maintain detection content using detection-as-code practices
  • Serve as incident commander for security incidents, ensuring effective communication and follow-up
  • Create automation and response playbooks to streamline incident handling
  • Conduct proactive threat hunting using intelligence and behavioral hypotheses
  • Perform forensics across systems to analyze attacker activity and impact

Benefits

  • Comprehensive benefits package including medical, dental, and vision coverage
  • Paid time off for personal and family needs
  • Life insurance and paid parental leave
  • Equity in the company as part of the compensation package
  • Open to applicants with diverse backgrounds and experiences
Full Job Description
The Role

K2 is a target for sophisticated adversaries, from nation-state actors to criminal groups, all intent on stealing or disrupting the technology behind a new class of high-powered satellites. This role owns detection and response for our corporate environment: you'll run and mature our SIEM, build detections against real adversary tradecraft, triage what fires, and drive incidents from first signal through containment, eradication, and lessons learned. You'llbe deeply hands-on across identity, endpoints, SaaS, network, and cloud telemetry, closing the visibility gaps you find rather than simply documenting them. This is a role for someone who thrives on real-world impact and operates with urgency when it counts. Every detection you write and every incident you shut down directly supports our ability to move fast, operate confidently, and deliver breakthrough satellite capabilities.

Responsibilities
  • Own day-to-day detection and response across the corporate environment, from alert triage and investigation through containment and remediation
  • Administer and mature the SIEM, including log source onboarding, parsing and normalization, telemetry enrichment, rule tuning, and platform health, retention, and cost
  • Write, test, and maintain detection content mapped to MITRE ATT&CK using detection-as-code practices, including version control, peer review, and automated testing
  • Act as incident commander for corporate security incidents, coordinating stakeholders and delivering timelines, root cause analysis, and post-incident follow-through
  • Build response playbooks and automation across SOAR, scripting, and vendor APIs to reduce time to detect, triage, and contain
  • Threat hunt proactively across endpoint, identity, SaaS, and cloud telemetry using threat intelligence and hypotheses about adversary behavior
  • Run adversary emulation and purple team exercises to validate detection coverage, then close the gaps you find
  • Perform host, network, and cloud forensics across macOS, Windows, and Linux to reconstruct attacker activity and scope impact
  • Investigate phishing, business email compromise, credential abuse, and insider risk in partnership with IT, HR, and Legal
  • Partner with IT and infrastructure teams to harden identity, endpoint, and network controls, including conditional access, EDR policy, MDM baselines, segmentation, and secure remote access, informed by what investigations reveal
  • Translate detection and incident findings into vulnerability management priorities and security architecture improvements
  • Participate in an on-call rotation for security escalations, including occasional after-hours and weekend response
  • Maintain runbooks, detection documentation, and standard operating procedures, and mentor junior team members on investigation and response tradecraft
  • Support compliance and audit efforts by producing monitoring, detection, and incident response evidence as needed

Qualifications
  • 5+ years of experience in security operations, detection and response, or incident response, preferably in a fast-paced startup or technology environment
  • Hands-on experience administering and tuning a SIEM (e.g., Splunk, Microsoft Sentinel, Elastic, Panther, or Chronicle), including log source onboarding, parsing, and detection rule development
  • Demonstrated experience leading security incidents end to end, from detection and scoping through containment, eradication, and post-incident review
  • Strong working knowledge of attacker tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, and the evidence sources needed to investigate them
  • Experience investigating endpoint, identity, network, and cloud telemetry across macOS, Windows, and Linux, including EDR, identity provider, and SaaS audit logs
  • 2+ years of development experience with any modern programming language (including but not limited to Python, Go, C++, Rust) used to automate detection, enrichment, and response, in lieu of a degree; OR a bachelor's degree in security engineering, cyber security, computer science, engineering, math, or other STEM discipline
  • Knowledge of operating systems, networking, cloud and SaaS platforms, security best practices, and log analysis at scale
  • Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate with responsibilities
  • Due to the high visibility of this position, excellent interpersonal skills, attention to detail, and problem-solving skills

Nice to Have
  • Bachelor's degree (or equivalent) in computer science or engineering
  • Detection and response certifications such as GCIH, GCFA, GCIA, GCDA, or OSCP, or equivalent hands-on experience
  • Experience building detection-as-code pipelines, security data lakes, or ETL for security telemetry
  • Experience with cloud detection and response in AWS, Azure, or GCP
  • Experience with threat intelligence, malware analysis, or reverse engineering
  • Experience protecting engineering, manufacturing, OT, or mission and ground segment environments
  • Prior experience in a defense, aerospace, or other ITAR-regulated environment
  • Security community contributions such as tooling, blog posts, conference talks, or CTFs

Compensation and Benefits:
  • Base salary range for this role is $150,000 - $190,000 and equity in the company
  • Salary will be based on several factors including, but not limited to: knowledge and skills, education, and experience level
  • Comprehensive benefits package including paid time off, medical/dental/vision coverage, life insurance, paid parental leave, and many other perks


If you don't meet 100% of the preferred skills and experience, we encourage you to still apply! Building a spacecraft unlike any other requires a team unlike any other and non-traditional career twists and turns are encouraged!

Similar Jobs

More Jobs at K2 Space

More Information Technology Jobs

Find similar Senior Security Engineer, Operations jobs: