Incident Responder
Arkenstone Defense · Menlo Park, CA · 5 days ago
OTHRFull-time
About UsAt Arkenstone Defense, we empower defense tech startups with the tools, infrastructure, and compliance solutions they need to become successful prime contractors. Our mission is to remove barriers and help innovators grow - from day one to becoming a trusted prime for the U.S. Government.We're early, we're lean, and we're building something that actually matters. The people who do well here aren't waiting to be told what to do; they see a gap and fill it.OverviewWe are seeking an Incident Responder (Remote, US) to focus on incident response, threat monitoring, and detection, supporting our federal and commercial customer base. You will identify complex security and technical compliance issues, recognize patterns and root causes, and help design innovative solutions that improve our threat monitoring and detection services. You will bring your experience with security systems and incident response — both on-premises and in cloud environments — to a team growing around supporting FedRAMP-authorized Cloud Service Providers.This role operates on the frontline of the Mission Assurance Center (MAC), working alongside our MSSP to triage alerts, investigate threats, and protect internal and customer-facing environments. It is ideal for a motivated responder who wants to grow quickly in a compliance-heavy, mission-critical environment where your work directly supports the security of cleared workforces. You will execute defined tasks under direct supervision, follow established playbooks, and build the foundational skills that drive career progression within the MAC.What You’ll DoEngineeringFollow incident response procedures including documentation, evidence collection, and escalation to senior engineersExecute incident response playbooks for common threat scenarios including phishing, malware, and unauthorized accessDocument and track security incidents from detection through resolution and lessons learnedThreat Monitoring & DetectionOwn the incident management lifecycle: from detection to postmortem and root cause analysisMonitor SIEM and security tools for alerts; perform initial triage and escalate per documented playbooks; tune and create detection SIEM alertsCollect and correlate security data from multiple sources to distinguish true positives from noiseMonitor and analyze threat intelligence sources to detect potential security threats and vulnerabilities; implement continuous monitoring systems to ensure real-time awareness of security eventsParticipate in on-call rotation for after-hours security monitoring and incident responseProcess & Knowledge DevelopmentMaintain and improve runbooks, knowledge base articles, and repetitive task automationsWork closely with internal engineering, development, and compliance teams to implement security measures and address compliance requirementsStay current on industry trends, emerging threats, and changes in compliance standards to ensure ongoing effectiveness. Requirements3-5 years of experience in Incident Response or Detection engineering rolesHands-on exposure to AWS AthenaProficiency in detection engineering: alert creation and tuning - writing SQL, KQL, Sigma, or YARA rules for threat detectionProven track record of operating large-scale systems in multi-cloud environmentsStrong knowledge of cloud-native architecture, container orchestration (e.g., Kubernetes), and CI/CD pipelinesProficient in scripting (Python, Bash, etc.) and infrastructure automation toolsExcellent problem-solving skills and a bias toward ownership and actionFamiliarity with SIEM platformsWorking knowledge of incident response processes, procedures, and documentation standards.Comfortable making decisions under pressure and leading through incidentsWorking knowledge of FedRAMP or NIST 800-53 controls (preferred)Comfortable participating in customer discussionsClear communicator who can translate technical concepts to mixed audiencesWho You AreDrive a culture of accountability, ownership, and continuous improvementYou thrive on building meaningful relationships and helping others succeedYou understand the unique challenges that defense tech startups face, and can speak their languageMission AlignmentWe are a Defense-focused company supporting sensitive and cleared workforces. The Incident Responder will embrace our commitment to operational excellence, compliance rigor, and a world-class employee experience.Physical RequirementsProlonged periods of sitting at a desk and working on a computerMust be able to lift up to 15 pounds at timesAbility to communicate effectively in written and verbal form Benefits for working with us!We are committed to supporting our employees both professionally and personally. Our robust benefits package is designed to promote your well-being, growth, and work-life balanceCompetitive Salary: Recognizing your hard work with attractive compensation and rewarding excellence.Health and Wellness Programs: Including medical, dental, & vision insurance options, along with mental health support & wellness initiatives.Retirement Planning: Secure your future with our flexible 401(k) plan and matching company contributions.Paid Time Off & Holidays: Generous PTO, sick leave, and holiday pay to help you recharge and enjoy life outside of work.Employee Assistance Program: Confidential resources for personal and professional support.Professional Development: Access to training, certifications, and continuing education to foster your career growth. We are an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability, genetic information, veteran status, or any other characteristic protected under applicable law.Arkenstone Defense participates in E-Verify and will provide the federal government with your Form I-9 information to confirm employment authorization.