×
Register Here to Apply for Jobs or Post Jobs. X

Incident Responder

Job in Menlo Park, San Mateo County, California, 94029, USA
Listing for: Arkenstone Defense
Full Time position
Listed on 2026-09-16
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 120000 - 170000 USD Yearly USD 120000.00 170000.00 YEAR
Job Description & How to Apply Below

At Arkenstone Defense, we empower defense tech startups with the tools, infrastructure, and compliance solutions they need to become successful prime contractors. Our mission is to remove barriers and help innovators grow - from day one to becoming a trusted prime for the U.S. Government.

We're early, we're lean, and we're building something that actually matters. The people who do well here aren't waiting to be told what to do; they see a gap and fill it.

About Us

At Arkenstone Defense, we empower defense tech startups with the tools, infrastructure, and compliance solutions they need to become successful prime contractors. Our mission is to remove barriers and help innovators grow - from day one to becoming a trusted prime for the U.S. Government.

We're early, we're lean, and we're building something that actually matters. The people who do well here aren't waiting to be told what to do; they see a gap and fill it.

Overview

We are seeking an Incident Responder (Remote, US) to focus on incident response, threat monitoring, and detection, supporting our federal and commercial customer base. You will identify complex security and technical compliance issues, recognize patterns and root causes, and help design innovative solutions that improve our threat monitoring and detection services. You will bring your experience with security systems and incident response — both on-premises and in cloud environments — to a team growing around supporting FedRAMP-authorized Cloud Service Providers.

This role operates on the frontline of the Mission Assurance Center (MAC), working alongside our MSSP to triage alerts, investigate threats, and protect internal and customer-facing environments. It is ideal for a motivated responder who wants to grow quickly in a compliance-heavy, mission-critical environment where your work directly supports the security of cleared work forces. You will execute defined tasks under direct supervision, follow established playbooks, and build the foundational skills that drive career progression within the MAC.

What

You’ll Do Engineering
  • Follow incident response procedures including documentation, evidence collection, and escalation to senior engineers
  • Execute incident response playbooks for common threat scenarios including phishing, malware, and unauthorized access
  • Document and track security incidents from detection through resolution and lessons learned
Threat Monitoring & Detection
  • Own the incident management lifecycle: from detection to postmortem and root cause analysis
  • Monitor SIEM and security tools for alerts; perform initial triage and elevate per documented playbooks; tune and create detection SIEM alerts
  • Collect and correlate security data from multiple sources to distinguish true positives from noise
  • Monitor and analyze threat intelligence sources to detect potential security threats and vulnerabilities; implement continuous monitoring systems to ensure real-time awareness of security events
  • Participate in on-call rotation for after-hours security monitoring and incident response
Process & Knowledge Development
  • Maintain and improve runbooks, knowledge base articles, and repetitive task automations
  • Work closely with internal engineering, development, and compliance teams to implement security measures and address compliance requirements
  • Stay current on industry trends, emerging threats, and changes in compliance standards to ensure ongoing effectiveness.
Requirements
  • 3-5 years of experience in Incident Response or Detection engineering roles
  • Hands-on exposure to AWS Athena
  • Proficiency in detection engineering: alert creation and tuning - writing SQL, KQL, Sigma, or YARA rules for threat detection
  • Proven track record of operating large-scale systems in multi-cloud environments
  • Strong knowledge of cloud-native architecture, container orchestration (e.g., Kubernetes), and CI/CD pipelines
  • Proficient in scripting (Python, Bash, etc.) and infrastructure automation tools
  • Excellent problem-solving skills and a bias toward ownership and action
  • Familiarity with SIEM platforms
  • Working knowledge of incident response processes, procedures, and documentation standards.
  • Comfortable making decisions under pressure and leading through incidents
  • Working knowledge of FedRAMP or NIST 800-53 controls (preferred)
  • Comfortable participating in customer discussions
  • Clear communicator who can translate technical concepts to mixed audiences
Who You Are
  • Drive a culture of accountability, ownership, and continuous improvement
  • You thrive on building…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary