Назад
Company hidden
3 часа назад

Senior Security Engineer, Operations (Aerospace)

150 000 - 190 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer, Operations (Aerospace): Operating and maturing corporate detection and response capabilities for a satellite company with an accent on SIEM administration, adversary-focused detections, and incident command. Focus on threat hunting across identity, endpoints, SaaS, networks, and cloud, conducting forensics and purple-team exercises, and automating containment through SOAR and scripting.

Location: Los Angeles, CA, United States. The role requires either U.S. person status under ITAR or eligibility for a federally issued export-control license.

Salary: $150,000–$190,000 per year, plus equity.

Company

hirify.global Corporation develops high-power satellite platforms for commercial and U.S. government missions from low Earth orbit to deep space.

What you will do

  • Own corporate security detection and response from alert triage and investigation through containment, remediation, and post-incident follow-up.
  • Administer and mature the SIEM by onboarding and normalizing log sources, enriching telemetry, tuning rules, and managing platform health, retention, and cost.
  • Build and maintain MITRE ATT&CK-mapped detection content using detection-as-code, version control, peer review, and automated testing.
  • Lead incident response, coordinate stakeholders, produce root-cause analysis, and maintain incident timelines and follow-through.
  • Develop SOAR, scripting, and vendor-API automation; conduct threat hunts, adversary emulation, and purple-team exercises.
  • Perform host, network, and cloud forensics and partner with IT, infrastructure, HR, and Legal on phishing, business email compromise, credential abuse, insider risk, and control hardening.

Requirements

  • 5+ years of experience in security operations, detection and response, or incident response.
  • Hands-on experience administering and tuning SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Panther, or Chronicle.
  • Experience leading security incidents end to end and working with attacker TTPs, MITRE ATT&CK, endpoint, identity, network, SaaS, and cloud telemetry.
  • 2+ years of development experience in a modern programming language such as Python, Go, C++, or Rust for security automation, or a relevant bachelor’s degree in security, computer science, engineering, mathematics, or another STEM discipline.
  • Knowledge of operating systems, networking, cloud and SaaS platforms, security practices, and large-scale log analysis.
  • Must be a U.S. person under ITAR or otherwise eligible for a federally issued export-control license.

Nice to have

  • Detection and response certifications such as GCIH, GCFA, GCIA, GCDA, or OSCP.
  • Experience with detection-as-code pipelines, security data lakes, security telemetry ETL, or cloud detection and response in AWS, Azure, or GCP.
  • Experience with threat intelligence, malware analysis, reverse engineering, or protecting aerospace, defense, manufacturing, OT, mission, or ground-segment environments.
  • Experience in a defense, aerospace, or ITAR-regulated environment and contributions to the security community.

Culture & Benefits

  • Participation in an on-call rotation, including occasional after-hours and weekend security escalations.
  • Paid time off, medical, dental, and vision coverage.
  • Life insurance and paid parental leave.
  • Equity in the company.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →