
Senior Detection and Response Engineer
Job description
Senior Detection and Response Engineer at Northwood Space.
About the role
You will architect and lead the security operations for a globally distributed ground station network that delivers real-time communications to national security and disaster response missions. This role owns the design, operation, and continuous improvement of our Security Operations Center and threat hunting capabilities across on-premises and cloud infrastructure. You will investigate sophisticated cyber intrusions, perform digital forensics, and ensure the integrity of systems that cannot experience downtime. The position requires you to develop advanced detection logic for unique satellite communications environments and space-based infrastructure. You will own the creation and maintenance of incident response playbooks tailored to aerospace and government customers. You will analyze threat intelligence specific to the space industry and translate findings into actionable security controls. If you thrive in high-stakes, mission-critical environments and want to see your work deployed worldwide with immediate impact, this is the role for you.
Key facts
What you'll do
- Lead incident response and digital forensics for security incidents affecting globally distributed ground stations and cloud infrastructure, coordinating responses to safeguard national security missions.
- Design, tune, and optimize custom detection rules for SIEM platforms to identify advanced threats specific to satellite communications and ground station operations.
- Operate 24/7 security monitoring for AWS multi-cloud environments, Linux-based ground station systems, and satellite communication networks, triaging alerts and escalating critical threats.
- Conduct proactive threat hunting across space infrastructure to uncover advanced persistent threats targeting RF communications, ground stations, and space-based assets.
- Author and maintain incident response playbooks and runbooks for security incidents impacting space communications, defining escalation procedures and customer communication protocols.
- Research, ingest, and analyze threat intelligence relevant to aerospace and defense, integrating indicators of compromise into detection systems and briefing stakeholders on emerging risks.
- Build security automation using Python and PowerShell to streamline incident response, threat hunting workflows, and orchestration across distributed ground station networks.
- Perform malware analysis using tools such as Volatility, YARA, and hex editors to understand malicious code targeting space infrastructure and support forensic investigations.
- Collaborate with engineering and operations teams to harden Linux-based ground station systems, improve log collection, and strengthen monitoring across complex environments.
- Develop behavioral analytics and detection logic that accounts for the unique network characteristics and operational constraints of satellite communications.
- Maintain readiness for TS/SCI clearance eligibility and ensure all security activities comply with U.S. government export regulations, including ITAR.
- Document investigations, findings, and remediation steps in a clear and actionable manner to support both technical and executive stakeholders.
- Partner with threat intelligence communities to stay current on adversary tactics, techniques, and procedures affecting space-based and defense systems.
- Contribute to the continuous improvement of security operations by refining detection analytics, automation, and response processes based on lessons learned.
Requirements
- Bring 5+ years of hands-on experience in SOC operations, incident response, or threat hunting within highly secure or regulated environments.
- Demonstrate proficiency with SIEM platforms such as Splunk, Sentinel, or Chronicle, including the development of custom rules and advanced search queries.
- Apply digital forensics and malware analysis skills using tools like Volatility, YARA, and hex editors to investigate and remediate complex incidents.
- Write Python and PowerShell scripts to implement security automation, threat hunting workflows, and response actions across distributed infrastructure.
- Utilize endpoint security platforms such as CrowdStrike or SentinelOne and conduct network security monitoring to detect and respond to advanced threats.
- Perform Linux forensics and log analysis on distributed systems, correlating data sources to identify indicators of compromise and attack patterns.
- Apply knowledge of threat intelligence frameworks including MITRE ATT&CK and the Diamond Model, and analyze IOCs in the context of space communications.
- Obtain and maintain the ability to hold U.S. government TS/SCI clearance and comply with related eligibility requirements.
Nice to have
- Apply experience with cloud security monitoring in AWS, Azure, or other multi-cloud environments to protect ground station infrastructure.
- Leverage a background in aerospace, defense, or critical infrastructure security operations to enhance threat detection and response.
- Conduct threat hunting in air-gapped or highly regulated environments where standard tooling must be adapted.
- Understand RF communications, satellite systems, or space-based asset security to better identify risks and anomalies.
- Hold industry certifications such as GCIH, GCFA, GNFA, or similar incident response credentials that validate advanced detection and response capabilities.
- Build security orchestration and automated response (SOAR) workflows to streamline investigations and reduce manual effort.
- Follow government incident reporting requirements and procedures to ensure compliance and timely communication with stakeholders.
Practical notes
U.S. citizenship, lawful permanent residency, or eligibility for required authorizations is mandatory to conform to ITAR and U.S. government space technology export regulations.