SR. INFORMATION SECURITY DETECTION ENGINEER
SpaceX is looking for a detection engineer to join the information security team to help protect and drive the SpaceX mission. Information drives our business and we must protect the confidentiality, integrity, and availability of systems and processes across the enterprise. As a highly visible and dynamic organization, we must also value and guard against damage to our reputation and brand. Finally, it is paramount we defend against loss of control or confidence in our systems, to guarantee the highest probability of success. SpaceX information security detection engineers are responsible for building tailored security detections.
- Work closely with the Security Operations Center (SOC) and engineering teams to improve and build new tailored security detections.
- Build playbooks to properly triage and respond to security incidents.
- Analyze SOC alert statistics and workflows to reduce false positives and properly focus engineering efforts.
- Provide design support on ways to improve detection and response capabilities.
- Provide back-up support to the incident response team when necessary.
- Keep up-to-date on modern attack techniques to continually integrate knowledge into new detections.
- Operate and help mature SOC playbooks, workflow automations, and use cases to protect SpaceX people, missions, and assets.
- 5+ years of professional experience in information security developing detections for attacker tactics, techniques, and procedures (TTPs).
- 3+ years of experience writing and tuning host and network detections.
PREFERRED SKILLS AND EXPERIENCE:
- Experience with scripting languages (Python/PowerShell) for automation.
- Experience with operating system internals for Linux and/or Windows platforms.
- Experience with modern security information and event management (SIEM) systems such as Splunk and/or ELK.
- Experience automating security operations and incident response processes.
- Strong understanding of security architecture, tool integration, and API development/automation.
- Knowledge of cloud infrastructure and cloud security.
- Reverse engineering and malware analysis.
- Vulnerability research and penetration testing.