Northwood Space Corp
Security Operations Manager
Torrance, CA
No sponsorship$171k-$800kDetected 32 days ago
TypeScriptPythonBashPowerShellAWSCloud PlatformsLinuxNetwork SecuritySIEMSOARUEBASOC OperationsDetection EngineeringIncident ResponseFirewallZero TrustNetwork EngineeringResearchLeadershipCommunicationCollaboration
About the role
- If you like solving complex challenges and seeing your work deployed around the world with real impact, Northwood is the place to do it.
- Your ability to secure the necessary clearance is essential for fulfilling key responsibilities of the role.
- Should you be unable to obtain it, Northwood Space reserves the right to modify or terminate your employment to align with optional needs.
Responsibilities
- Build and operate Northwood's SOC function, including continuous monitoring of security events across AWS GovCloud, GCC, on-premises facilities, and endpoint environments.
- Build behavioral analytics, UEBA rules, and threat hunting queries tailored to Northwood's infrastructure and adversary profiles targeting aerospace and defense.
- Own security incidents end-to-end, from initial detection through containment, eradication, recovery, and post-incident review.
- Lead tabletop exercises and incident response drills to validate playbook effectiveness and team readiness.
- Proactively hunt for advanced persistent threats across Northwood's on-premises and cloud environments, developing and refining hunting methodologies as the threat landscape evolves.
- Maintain familiarity with government incident reporting requirements and ensure response procedures satisfy applicable regulatory obligations.
- Develop Python, PowerShell, or Bash automation for incident response workflows, threat hunting pipelines, and security orchestration across Northwood's environment.
- Build and maintain SOAR playbooks and automated response actions to reduce mean time to respond and minimize manual analyst burden.
- Collaborate with the Security Engineering Lead to ensure SOC tooling integrations across SIEM, EDR, email security, and identity platforms are maintained and continuously improved.
- Hire, mentor, and develop security operations analysts and engineers as the team scales.
Requirements
- 5+ years of hands-on SOC operations, incident response, or threat hunting experience, with demonstrated experience in a technical leadership capacity.
- Experience with EDR platforms, including alert triage, policy management, and forensic investigation workflows.
- Digital forensics and malware analysis proficiency, including tools such as Volatility and YARA.
- Proficiency in Python, PowerShell, or Bash for security automation and threat hunting workflows.
- Working knowledge of threat intelligence frameworks including MITRE ATT&CK and the Diamond Model.
- Familiarity with compliance frameworks relevant to government environments, including NIST 800-171, CMMC, and DFARS incident reporting requirements.
- U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.
- Own alert triage, investigation, and escalation workflows, ensuring critical threats are identified and actioned with the urgency required of a mission-critical environment.
Nice to have
- Active TS clearance or higher.
- Experience with cloud security monitoring in AWS GovCloud and Microsoft GCC environments.
- Hands-on experience with SOAR platforms and automated response workflow development.
- Background in aerospace, defense, critical infrastructure, or other highly regulated security operations environments.
- Experience with threat hunting in air-gapped or compliance-constrained environments.
- Familiarity with government incident reporting requirements and procedures including DFARS 252.204-7012.
- Certifications such as GCIH, GCFA, GNFA, or equivalent incident response credentials.
- ITAR compliance experience.
Skills
- Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology.
Compensation
- $171k-$800k
Benefits
- Develop and continuously improve custom detection logic within Northwood's SIEM platform, including log source onboarding, correlation rule development, tuning, and coverage gap analysis.
- Maintain detection content aligned to MITRE ATT&CK, ensuring coverage maps are current and gaps are systematically addressed.
- Define SOC operating procedures, analyst workflows, and on-call responsibilities to ensure consistent operational coverage.
Company info
- Develop and maintain SOC operational metrics, reporting cadences, and dashboards for internal stakeholders and government customers.
- Develop and maintain incident response playbooks and escalation procedures, including communication protocols for government customers and mission-critical operations.
- If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.
Visa & Work Authorization
- citizenship or status as a lawful permanent resident required to conform with ITAR export regulations
Apply directly at Northwood Space Corp →Create a free account for alerts like thisView Northwood Space Corp immigration profile
This listing is sourced directly from Northwood Space Corp's careers page and normalized into a canonical job model.