Назад
Company hidden
6 дней назад

Senior Incident Response Engineer (Aerospace)

144 000 - 180 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Incident Response Engineer (Aerospace/Cybersecurity): Leading detection, investigation, containment, and remediation of security incidents across SIEM, SOAR, endpoint, and cloud environments with an accent on digital forensics, threat hunting, and NIST SP 800-171 compliance. Focus on designing detection rules and response automation, reconstructing incident timelines, operationalizing threat intelligence, and evolving the incident response program for aerospace security operations.

Location: San Jose, California, United States

Base salary: $144,000–$180,000 per year

Company

hirify.global develops an end-to-end advanced air mobility platform, including air taxis, unmanned aircraft systems, and aviation-related artificial intelligence solutions for commercial aerospace and defense customers.

What you will do

  • Lead alert triage, validation, escalation, and detection-rule tuning as the primary internal SIEM engineer and technical liaison to the MSSP.
  • Coordinate technical response to security incidents, including identification, containment, eradication, recovery, and post-incident reporting.
  • Conduct forensic investigations involving memory analysis, disk imaging, timeline reconstruction, evidence preservation, and malware analysis.
  • Execute proactive threat hunts using SIEM and EDR telemetry to identify lateral movement, persistence, and indicators of compromise.
  • Develop MITRE ATT&CK-mapped detections, SOAR workflows, incident response playbooks, and automated containment procedures.
  • Own the incident response strategy, documentation architecture, metrics, roadmap, audits, and executive reporting.

Requirements

  • 5+ years of experience in incident response or security operations, including MSSP management, alert triage, and SLA performance.
  • Hands-on experience responding to malware, phishing, ransomware, and insider-threat incidents from detection through eradication.
  • Deep understanding of Windows, Mac, and Linux internals, network protocols, and scripting with Python, PowerShell, or Bash.
  • Experience with SIEM platforms and query languages, including Google SecOps/Chronicle, Splunk, Microsoft Sentinel, YARA-L/GoogleSQL, SPL, and KQL.
  • Experience designing SOAR workflows, conducting threat hunts, facilitating tabletop exercises, and maintaining security documentation.
  • Working familiarity with firewalls, network security, AWS, Azure, GCP, application security, CTI, and UEBA.

Nice to have

  • Advanced static or dynamic malware analysis using IDA Pro, Ghidra, or Cuckoo Sandbox.
  • Experience with email security platforms such as Material Security, Proofpoint, or Check Point Harmony.
  • Knowledge of NIST SP 800-171 and CMMC Level 2 Incident Response and Audit/Accountability requirements.
  • Experience in aerospace or startup environments.

Culture & Benefits

  • Pay-for-performance culture with compensation based on job-related knowledge, skills, and experience.
  • Commitment to diversity, inclusion, equal opportunity, and reasonable accommodations throughout the hiring process.
  • Certain positions may be eligible for visa sponsorship.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →