Remote job
Detection Engineer
Job details
About this role
Role overview This position supports a federal Cyber Incident Response Team, designing and engineering detection capabilities across SIEM and network security platforms. The work blends hands-on detection content development with cross-team collaboration to improve an organization's overall security posture against sophisticated threats.
Responsibilities - Design, engineer, and implement detection initiatives under a cybersecurity team lead, including AI-assisted tooling where applicable. - Develop and tune detection logic for Microsoft Sentinel, Cisco FirePower, IDS/IPS, and adjacent network security platforms, mapping rules to frameworks such as MITRE ATT&CK. - Author and optimize KQL queries for Sentinel, reducing false positives and improving fidelity of security-relevant events handed to triage and response teams. - Manage detection code in Git and GitHub, using version control and collaborative workflows for auditability. - Translate findings between network engineering and cybersecurity teams, advocating for secure designs and briefing stakeholders on architecture and strategy. - Recommend improvements that align with federal and industry standards such as NIST and CISA guidance.
Requirements - U.S. citizenship and a Bachelor's degree in Cybersecurity, Computer Science, or a related field, or equivalent experience. - 6+ years in information security, including 2+ years of event and log analysis across AV, IDS/IPS, firewalls, Active Directory, web proxies, DLP, and SIEM. - At least one year of hands-on Microsoft Sentinel and KQL experience, plus one year configuring Cisco FirePower and IDS/IPS. - Practical detection engineering skills, including signature design and tuning for IoCs and IoAs. - Packet and malware analysis using tools such as Wireshark, along with scripting in PowerShell, Python, regex, grep, sed, or awk. - Strong grounding in TCP/IP, application-layer protocols, Windows/Linux internals, and the MITRE ATT&CK framework.
Nice to have - Threat hunting and security automation experience. - Familiarity with cloud security monitoring in Azure or AWS. - Certifications such as GIAC GCIA, GCED, or Microsoft Security Operations Analyst Associate.
Benefits and work setup - U.S.-based federal services role with disclosed compensation ranges tied to specific state labor markets; benefits package referenced by the employer.