Senior Security Engineer, Operations
Los Angeles, CA·Posted 1mo ago
cybersecuritysaaspythongorustawsgcp
<div class="content-intro"><p data-renderer-start-pos="41">K2 is building the largest and highest-power satellites ever flown, unlocking performance levels previously out of reach across every orbit. Backed by over $1 billion in total funding from leading investors including Altimeter Capital, ICONIQ, Kleiner Perkins, Lightspeed Venture Partners, Redpoint Ventures, and T. Rowe Price — and with over $1 billion in signed contracts across commercial and US government customers, we're mass-producing the highest-power satellite platforms ever built for missions from LEO to deep space.</p> <p data-renderer-start-pos="570">The rise of heavy-lift launch vehicles is shifting the industry from an era of mass constraint to one of mass abundance, and we believe this new era demands a fundamentally different class of spacecraft. Engineered to survive the harshest radiation environments and to fully capitalize on today's and tomorrow's massive rockets, K2 satellites deliver unmatched capability at constellation scale and across multiple orbits.</p> <p data-renderer-start-pos="994">With multiple launches in 2027 and plans to scale to 100 satellites a year, we're Building Bigger — helping develop the solar system and build toward a Kardashev Type II (K2) civilization. If you are a motivated individual who thrives in a fast-paced environment and you're excited about contributing to the success of a high-growth Series D-funded company, we'd love for you to apply.</p></div><p><strong><span data-contrast="none">The Role</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <p><span data-contrast="auto">K2 is a target for sophisticated adversaries, from nation-state actors to criminal groups, all intent on stealing or disrupting the technology behind a new class of high-powered satellites. This role owns detection and response for our corporate environment: you’ll run and mature our SIEM, build detections against real adversary tradecraft, triage what fires, and drive incidents from first signal through containment, eradication, and lessons learned. You’llbe deeply hands-on across identity, endpoints, SaaS, network, and cloud telemetry, closing the visibility gaps you find rather than simply documenting them. This is a role for someone who thrives on real-world impact and operates with urgency when it counts. Every detection you write and every incident you shut down directly supports our ability to move fast, operate confidently, and deliver breakthrough satellite capabilities.</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <p><strong><span data-contrast="none">Responsibilities</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <ul> <li><span data-contrast="auto">Own day-to-day detection and response across the corporate environment, from alert triage and investigation through containment and remediation</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Administer and mature the SIEM, including log source onboarding, parsing and normalization, telemetry enrichment, rule tuning, and platform health, retention, and cost</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Write, test, and maintain detection content mapped to MITRE ATT&CK using detection-as-code practices, including version control, peer review, and automated testing</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Act as incident commander for corporate security incidents, coordinating stakeholders and delivering timelines, root cause analysis, and post-incident follow-through</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Build response playbooks and automation across SOAR, scripting, and vendor APIs to reduce time to detect, triage, and contain</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Threat hunt proactively across endpoint, identity, SaaS, and cloud telemetry using threat intelligence and hypotheses about adversary behavior</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Run adversary emulation and purple team exercises to validate detection coverage, then close the gaps you find</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Perform host, network, and cloud forensics across macOS, Windows, and Linux to reconstruct attacker activity and scope impact</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Investigate phishing, business email compromise, credential abuse, and insider risk in partnership with IT, HR, and Legal</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Partner with IT and infrastructure teams to harden identity, endpoint, and network controls, including conditional access, EDR policy, MDM baselines, segmentation, and secure remote access, informed by what investigations reveal</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Translate detection and incident findings into vulnerability management priorities and security architecture improvements</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Participate in an on-call rotation for security escalations, including occasional after-hours and weekend response</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Maintain runbooks, detection documentation, and standard operating procedures, and mentor junior team members on investigation and response tradecraft</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="auto">Support compliance and audit efforts by producing monitoring, detection, and incident response evidence as needed</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> </ul> <p><strong><span data-contrast="none">Qualifications</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <ul> <li><span data-contrast="none">5+ years of experience in security operations, detection and response, or incident response, preferably in a fast-paced startup or technology environment</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Hands-on experience administering and tuning a SIEM (e.g., Splunk, Microsoft Sentinel, Elastic, Panther, or Chronicle), including log source onboarding, parsing, and detection rule development</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Demonstrated experience leading security incidents end to end, from detection and scoping through containment, eradication, and post-incident review</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Strong working knowledge of attacker tactics, techniques, and procedures (TTPs), the MITRE ATT&CK framework, and the evidence sources needed to investigate them</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Experience investigating endpoint, identity, network, and cloud telemetry across macOS, Windows, and Linux, including EDR, identity provider, and SaaS audit logs</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">2+ years of development experience with any modern programming language (including but not limited to Python, Go, C++, Rust) used to automate detection, enrichment, and response, in lieu of a degree; OR a bachelor’s degree in security engineering, cyber security, computer science, engineering, math, or other STEM discipline</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Knowledge of operating systems, networking, cloud and SaaS platforms, security best practices, and log analysis at scale</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Comfortable working with mission critical and sensitive systems, with a sense of urgency appropriate with responsibilities</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Due to the high visibility of this position, excellent interpersonal skills, attention to detail, and problem-solving skills</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> </ul> <p><strong><span data-contrast="none">Nice to Have</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <ul> <li><span data-contrast="none">Bachelor’s degree (or equivalent) in computer science or engineering</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Detection and response certifications such as GCIH, GCFA, GCIA, GCDA, or OSCP, or equivalent hands-on experience</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Experience building detection-as-code pipelines, security data lakes, or ETL for security telemetry</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Experience with cloud detection and response in AWS, Azure, or GCP</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Experience with threat intelligence, malware analysis, or reverse engineering</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Experience protecting engineering, manufacturing, OT, or mission and ground segment environments</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Prior experience in a defense, aerospace, or other ITAR-regulated environment</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Security community contributions such as tooling, blog posts, conference talks, or CTFs</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> </ul> <p><strong><span data-contrast="none">Compensation and Benefits:</span></strong><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559738":240,"335559739":240,"335559740":278}"> </span></p> <ul> <li><span data-contrast="none">Base salary range for this role is $150,000 - $190,000 and equity in the company</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Salary will be based on several factors including, but not limited to: knowledge and skills, education, and experience level</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> <li><span data-contrast="none">Comprehensive benefits package including paid time off, medical/dental/vision coverage, life insurance, paid parental leave, and many other perks</span><span data-ccp-props="{"134233117":false,"134233118":false,"201341983":0,"335559685":720,"335559737":0,"335559738":0,"335559739":0,"335559740":278,"335559991":360}"> </span></li> </ul><div class="content-conclusion"><p>If you don’t meet 100% of the preferred skills and experience, we encourage you to still apply! Building a spacecraft unlike any other requires a team unlike any other and non-traditional career twists and turns are encouraged!</p> <p>If you need a reasonable accommodation as part of your application for employment or interviews with us, please let us know.</p> <p><strong>Export Compliance</strong></p> <p>As defined in the ITAR, “U.S. Persons” include U.S. citizens, lawful permanent residents (i.e., Green Card holders), and certain protected individuals (e.g., refugees/asylees, American Samoans). Please consult with a knowledgeable advisor if you are unsure whether you are a “U.S. Person.”</p> <p>The person hired for this role will have access to information and items controlled by U.S. export control regulations, including the export control regulations outlined in the International Traffic in Arms Regulation (ITAR). The person hired for this role must therefore either be a “U.S. person” as defined by <a class="c-link" href="https://www.law.cornell.edu/cfr/text/22/120.15" target="_blank">22 C.F.R. § 120.15</a> or otherwise eligible for a federally issued export control license.</p> <p><strong>Equal Opportunity</strong></p> <p>K2 Space is an Equal Opportunity Employer; employment with K2 Space is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.</p></div>