Northwood Space Corp Logo

Northwood Space Corp

Senior Detection and Response Engineer

Reposted One Month Ago
Be an Early Applicant
In-Office
Torrance, CA, USA
120K-190K Hourly
Senior level
In-Office
Torrance, CA, USA
120K-190K Hourly
Senior level
Lead SOC operations and incident response for globally distributed satellite ground stations and cloud infrastructure. Build and tune SIEM detection rules, perform digital forensics and malware analysis, hunt advanced threats across space infrastructure, create incident response playbooks, integrate threat intelligence, and develop security automation for monitoring and response.
The summary above was generated by AI

About Northwood:

Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology. We are building a global network of phased array ground stations that enable real-time, reliable communication for satellite missions such as national security, global connectivity, and disaster response. With a vertically integrated approach, Northwood designs, builds, and rapidly deploys scalable systems that power the next generation of space missions. If you like solving complex challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it.

Role:

We're building the internet for space. Help us defend it.

Northwood is deploying a global network of phased array ground stations for mission-critical government and commercial space communications. We need a Senior Detection and Response Engineer to build and operate our security operations center, hunt threats across distributed satellite infrastructure, and lead incident response for systems that can't go down.

Responsibilities:

  • Lead incident response and forensics - Own security incidents from detection through resolution across globally distributed ground stations and cloud infrastructure. Conduct digital forensics, malware analysis, and coordinate response efforts for incidents impacting national security missions.

  • Build and tune detection rules - Develop custom detection logic for SIEM platforms that can identify threats specific to satellite communications and ground station operations. Create behavioral analytics and threat hunting queries for distributed infrastructure.

  • Operate 24/7 security monitoring - Monitor security events across AWS multi-cloud environments, Linux-based ground station systems, and satellite communication networks. Triage alerts, investigate suspicious activity, and escalate critical threats.

  • Hunt threats across space infrastructure - Proactively search for advanced persistent threats targeting satellite ground stations, RF communications, and space-based assets. Develop threat hunting methodologies for unique attack vectors in space communications.

  • Create incident response playbooks - Build runbooks for security incidents specific to satellite ground stations and space communications. Develop escalation procedures and communication protocols for government customers and mission-critical operations.

  • Analyze threat intelligence - Research adversary tactics targeting aerospace and defense infrastructure. Integrate threat feeds into detection systems and brief stakeholders on emerging threats to space communications.

  • Build security automation - Develop Python/PowerShell scripts for automated incident response, threat hunting workflows, and security orchestration across distributed ground station networks.

Basic Qualifications

  • 5+ years of hands-on SOC operations, incident response, or threat hunting experience

  • Experience with SIEM platforms (Splunk, Sentinel, Chronicle) including custom rule development and advanced search techniques

  • Digital forensics and malware analysis skills with tools like Volatility, YARA, and hex editors

  • Proficiency in Python, PowerShell, or similar languages for security automation and threat hunting

  • Experience with endpoint security platforms (CrowdStrike, SentinelOne) and network security monitoring

  • Strong Linux forensics and log analysis skills across distributed systems

  • Knowledge of threat intelligence frameworks (MITRE ATT&CK, Diamond Model) and IOC analysis

  • Ability to obtain and maintain TS/SCI clearance

Preferred Qualifications

  • Experience with cloud security monitoring in AWS, Azure, or multi-cloud environments

  • Background in aerospace, defense, or critical infrastructure security operations

  • Experience with threat hunting in air-gapped or highly regulated environments

  • Knowledge of RF communications, satellite systems, or space-based asset security

  • Certifications such as GCIH, GCFA, GNFA, or similar incident response credentials

  • Experience building security orchestration and automated response (SOAR) workflows

  • Familiarity with government incident reporting requirements and procedures

Additional Information:

If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.

To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Northwood Space is an Equal Opportunity Employer; employment with Northwood Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.

HQ

Northwood Space Corp Torrance, California, USA Office

20701 Manhattan Place, Torrance, CA, United States, 90501

Similar Jobs

2 Days Ago
Hybrid
140K-215K Annually
Senior level
140K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Develop full-stack tools and automation for deploying and managing cloud infrastructure. Responsibilities include designing software solutions, collaborating with business partners, developing architecture and automation strategies, reporting on projects, and providing technical leadership. The role requires React and Go development, API integration, CI/CD, automated testing, version control, security-focused coding, troubleshooting, documentation, and applying AI technologies to improve workflows and decision-making.
Top Skills: Ai TechnologiesCi/CdCloud InfrastructureCSSGitGoGraphQLHTMLJavaScriptReactRest
17 Days Ago
Easy Apply
Hybrid
Easy Apply
142K-212K Annually
Senior level
142K-212K Annually
Senior level
Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
Develop and operate detection and response capabilities across enterprise, cloud, and product environments. Responsibilities include building detections-as-code, triaging alerts, leading incident response and forensic investigations, threat hunting, automating workflows, maintaining SIEM and security data pipelines, developing AI-enabled security tooling, and participating in on-call rotations. The role also involves threat intelligence collaboration, security engineering mentorship, and continuous improvement of detection and response systems.
Top Skills: AICi/CdCloud PlatformsData PipelinesGitGitGoPythonSecurity Data LakesSIEMSplunkSQL
18 Days Ago
Remote or Hybrid
US
137K-191K Annually
Senior level
137K-191K Annually
Senior level
Information Technology
Engineer AI-powered threat detections, automated response playbooks, and continuous adversary emulation. Apply machine learning and LLMs to security operations, conduct threat hunting and AI red teaming, map coverage to MITRE ATT&CK, and develop detection-as-code through CI/CD. Build production-grade Python integrations, measurable containment capabilities, and safe autonomous defenses with guardrails. Mentor security professionals and collaborate across threat response, cyber defense engineering, and platform teams.
Top Skills: AIAtomic Red TeamCalderaCi/CdCloud SecurityCobalt StrikeCrowdstrikeEntra IdInfrastructure-As-CodeLlmsMachine LearningMicrosoft DefenderMicrosoft SentinelMitre Att&CkPolicy-As-CodePythonSIEMSoarSplunkTinesXdr

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account