Lead Detection & Incident Response Engineer

Mundi

Los Angeles (CA)

On-site

USD 150,000 - 190,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity

Job summary

K2 Space is seeking a security operations professional to own detection and response for our corporate environment. You’ll run and mature our SIEM, build detections mapped to MITRE ATT&CK, and lead incidents from first signal through containment and lessons learned across endpoints, identity, SaaS, and cloud telemetry.

The ideal candidate has 5+ years in security operations, hands-on SIEM experience (Splunk, Sentinel, Elastic, Panther, Chronicle), and a proven record of guiding incidents

Qualifications

  • 5+ years of experience in security operations, detection and response, or incident response.
  • Hands-on SIEM administration and tuning, including log onboarding and detector development.
  • Experience leading security incidents end to end, from detection to post-incident review.
  • Strong knowledge of MITRE ATT&CK and practical evidence sources.
  • Experience with endpoint, identity, network, and cloud telemetry across macOS, Windows, and Linux.

Responsibilities

  • Own day-to-day detection and response across the corporate environment.
  • Administer and mature the SIEM, including log source onboarding, parsing, and normalization, telemetry enrichment, rule tuning, and platform health, retention, and cost.
  • Write, test, and maintain detection content mapped to MITRE ATT&CK using detection-as-code practices.
  • Act as incident commander for corporate security incidents, coordinating stakeholders and delivering timelines, root cause analysis, and post-incident follow-through.
  • Build response playbooks and automation across SOAR, scripting, and vendor APIs to reduce time to detect, triage, and contain.
  • Threat hunt proactively across endpoint, identity, SaaS, and cloud telemetry using threat intelligence and hypotheses about adversary behavior.
  • Run adversary emulation and purple team exercises to validate detection coverage, then close the gaps you find.
  • Perform host, network, and cloud forensics across macOS, Windows, and Linux to reconstruct attacker activity and scope impact.
  • Investigate phishing, business email compromise, credential abuse, and insider risk in partnership with IT, HR, and Legal.
  • Partner with IT and infrastructure teams to harden identity, endpoint, and network controls, including conditional access, EDR policy, MDM baselines, segmentation, and secure remote access, informed by what investigations reveal.
  • Translate detection and incident findings into vulnerability management priorities and security architecture improvements.
  • Participate in an on-call rotation for security escalations, including occasional after-hours and weekend response.
  • Maintain runbooks, detection documentation, and standard operating procedures, and mentor junior team members on investigation and response tradecraft.
  • Support compliance and audit efforts by producing monitoring, detection, and incident response evidence as needed

Skills

Security operations
SIEM administration
Incident response leadership
MITRE ATT&CK
Telemetry across endpoints/cloud
Programming for automation
OS & networking knowledge
Communication under pressure

Education

Bachelor’s degree in security engineering, cyber security, computer science, engineering, math, or other STEM

Tools

Splunk
Microsoft Sentinel
Elastic
Panther
Chronicle

Job description

K2 Space is seeking a security operations professional to own detection and response for our corporate environment. You’ll run and mature our SIEM, build detections mapped to MITRE ATT&CK, and lead incidents from first signal through containment and lessons learned across endpoints, identity, SaaS, and cloud telemetry.

The ideal candidate has 5+ years in security operations, hands-on SIEM experience (Splunk, Sentinel, Elastic, Panther, Chronicle), and a proven record of guiding incidents

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - Incident Response & SIEM
Senior Security Engineer - Incident Response & SIEM

Socket.dev • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Equity
Comprehensive benefits
Senior Security Engineer: SIEM & Incident Lead (Equity)
Senior Security Engineer: SIEM & Incident Lead (Equity)

K2 Space Corporation • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Medical/dental/vision
Paid time off
Equity
Senior Security Engineer: SIEM, IR & Threat Hunting
Senior Security Engineer: SIEM, IR & Threat Hunting

K2Spacecorporation • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Senior SIEM & Security Monitoring Engineer
Senior SIEM & Security Monitoring Engineer

K2Share LLC • Washington

On-site
USD 140,000 - 190,000
Senior SIEM & Detection Engineering Lead
Senior SIEM & Detection Engineering Lead

K2United, LLC. • Washington

On-site
USD 150,000 - 190,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Lead Security Analyst, Incident Response & Threat Hunting
Lead Security Analyst, Incident Response & Threat Hunting

2K • Austin (TX)

On-site
USD 120,000 - 180,000
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000
Expert Cyber Security Incident and Threat Engineer
Expert Cyber Security Incident and Threat Engineer

Request Technology, LLC • Oakland (CA)

On-site
USD 150,000 - 190,000
Bonus eligible
Threat Detection & Response Engineer
Threat Detection & Response Engineer

United States Digital Space LLC • United States

Hybrid
USD 120,000 - 180,000
Paid parental leave
Certification reimbursement
Digital mental health support
+1