Jobs and Careers
FI

Sr Cybersecurity IR Engineer

Firefly Aerospace
Cedar Park, United Statesfull_timeVerifiedPosted 7 Oct 2025

About the role

ABOUT FIREFLY AEROSPACE
As an end-to-end responsive space company, Firefly Aerospace is on a mission to enable our world to launch, land, and operate in space – anywhere, anytime. Our small- to medium-lift launch vehicles, lunar landers, and orbital vehicles allow us to service the entire lifecycle of government and commercial missions from low Earth orbit to the Moon and beyond. We utilize carbon composite structures, patented propulsion technologies, and common components across our vehicles to iterate quickly, improve reliability, and deliver payloads at a lower cost.

SUMMARY
As a Senior Incident Response Engineer (Detection & Response) at Firefly, you will own triage, threat hunting, investigation, containment, and reporting for our security alerts and user-reported phishing. You will turn alerts from world-class systems into decisive outcomes, tune detections to reduce noise, and build custom rules and safeguards to protect Firefly data (including CUI) in alignment with compliance requirements. You will collaborate closely with Cybersecurity engineers, our GRC team, and a security operations engineer focused on dashboards/automation, using Python and Bash to streamline response and improve time-to-containment.

RESPONSIBILITIES

Alert Triage, Incident Response & Threat Hunting:

  • Monitor and triage alerts from SIEM, EDR, Identity Protection, and risky-user analytics; determine severity, scope, and next actions.
  • Proactive threat hunting: develop hypotheses, pivot through endpoint/identity/cloud/email telemetry (e.g., FQL/KQL), enrich with intel, validate findings, and convert successful hunts into durable detections/runbooks.
  • Execute and coordinate containment/eradication (host isolation, process kill, account disable, token/session revocation, conditional access changes, email purge) and handoffs to platform owners when needed.
  • Operate the user-reported phishing pipeline end-to-end (header analysis, safe detonation, artifact extraction); orchestrate tenant-wide purge and user notifications; feed outcomes into awareness and detection tuning.
  • Preserve evidence, maintain timelines, and drive root-cause analysis with clear communications to stakeholders.
  • Track and improve MTTD/MTTR; participate in a light on-call rotation for priority incidents.

Detection Engineering & SIEM Content:

  • Write and tune detections, watchlists, and anomaly rules to reduce false positives and increase coverage on high-impact TTPs.
  • Build dashboards and alert pipelines in NG-SIEM; adopt detection-as-code practices (Git PRs, versioning, testing).

CUI Protection & Compliance Enablement:

  • Implement and tune data loss prevention (DLP), labeling, and auto-classification controls for Firefly data; create detections for data mishandling and exfiltration paths.
  • Produce incident documentation aligned to NIST SP 800-171/CMMC (e.g., incident handling, monitoring, reporting evidence) and support audits/tabletops.

Automation & Tool Development:

  • Develop Python/Bash utilities to accelerate triage, enrichment, and evidence collection; partner with the security operations engineer to productionize repeatable workflows.
  • Integrate playbooks and scripts into existing pipelines to remove toil and improve consistency.

Documentation & Knowledge Management:

  • Create and maintain IR runbooks, playbooks, and post-incident report templates; deliver concise executive summaries and technical post-mortems.
  • Mentor junior responders and contribute to team readiness through drills and training.

QUALIFICATIONS

Required:

  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent hands-on experience).
  • 5+ years in SOC/Incident Response/Threat Detection & Response with end-to-end ownership of investigations.
  • Hands-on experience with CrowdStrike Falcon (EDR, Identity Protection) and NG-SIEM/LogScale, or similar enterprise tools.
  • Proficiency in Python and Bash for automation and tooling.
  • Experience writing/tuning detections and applying MITRE ATT&CK in practice.
  • Experience implementing/operating data protection for sensitive data and familiarity with CMMC/NIST SP 800-171 incident-handling and monitoring controls.
  • Strong written and verbal communication skills, including executive-grade incident reporting and stakeholder updates.

Desired:

  • Experience oper

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Firefly Aerospace

View company profile →