← Back to jobs

Remote job

Detection Engineer

Other Full-time Permanent US

Job details

Not specified Salary
US Eligibility
Junior Experience
Full-time Employment

About this role

Role overview This position supports a federal Cyber Incident Response Team, designing and engineering detection capabilities across SIEM and network security platforms. The work blends hands-on detection content development with cross-team collaboration to improve an organization's overall security posture against sophisticated threats.

Responsibilities - Design, engineer, and implement detection initiatives under a cybersecurity team lead, including AI-assisted tooling where applicable. - Develop and tune detection logic for Microsoft Sentinel, Cisco FirePower, IDS/IPS, and adjacent network security platforms, mapping rules to frameworks such as MITRE ATT&CK. - Author and optimize KQL queries for Sentinel, reducing false positives and improving fidelity of security-relevant events handed to triage and response teams. - Manage detection code in Git and GitHub, using version control and collaborative workflows for auditability. - Translate findings between network engineering and cybersecurity teams, advocating for secure designs and briefing stakeholders on architecture and strategy. - Recommend improvements that align with federal and industry standards such as NIST and CISA guidance.

Requirements - U.S. citizenship and a Bachelor's degree in Cybersecurity, Computer Science, or a related field, or equivalent experience. - 6+ years in information security, including 2+ years of event and log analysis across AV, IDS/IPS, firewalls, Active Directory, web proxies, DLP, and SIEM. - At least one year of hands-on Microsoft Sentinel and KQL experience, plus one year configuring Cisco FirePower and IDS/IPS. - Practical detection engineering skills, including signature design and tuning for IoCs and IoAs. - Packet and malware analysis using tools such as Wireshark, along with scripting in PowerShell, Python, regex, grep, sed, or awk. - Strong grounding in TCP/IP, application-layer protocols, Windows/Linux internals, and the MITRE ATT&CK framework.

Nice to have - Threat hunting and security automation experience. - Familiarity with cloud security monitoring in Azure or AWS. - Certifications such as GIAC GCIA, GCED, or Microsoft Security Operations Analyst Associate.

Benefits and work setup - U.S.-based federal services role with disclosed compensation ranges tied to specific state labor markets; benefits package referenced by the employer.

Skills detected in the listing

PythonInformation SecurityAWSAzure
Detected Sep 29, 2026
Last verified Sep 29, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight