Cybersecurity Detection Engineer
1 month ago
Job Locations: US-DC
ID: 2024-2142
Category: Information Technology
Position Type: Regular Full-Time
FLSA Status: Exempt
OverviewThe detection engineer blends technical skills, threat research experience, and knowledge of adversary techniques to work with new and existing data sources to create high fidelity, actionable alerts the ITSO SOC can use to quickly and effectively identify, analyze, and eradicate cybersecurity threats.
This individual will be familiar with adversary Tactics, Techniques, and Procedures (TTPs), and will identify opportunities to improve the effectiveness of existing detection efforts. They will be responsible for developing methodologies to maintain and maximize the integrity and effectiveness of existing alerting through the creation, periodic review, testing, and validation of custom detection content.
Additionally, they will leverage cybersecurity threat intelligence and collaborate with the SOC's incident response teams to meet operational needs and defend against real-world threats.
The minimum qualifications are as follows:
- A minimum of three years of experience working in detection engineering, threat hunting, security operations, or incident response using Splunk Enterprise Security or Microsoft Sentinel.
- Experience with the processes to add/update/delete detection rules in Splunk Enterprise Security and Microsoft Sentinel.
- Proficient in detection engineering methodologies including SNORT and YARA rules.
- Proficient in Python programming, Bash, and PowerShell.
- Proficient in Splunk's Search Processing Language, React, Kusto Query Language, and the Common Information Model (CIM).
- Knowledgeable and experienced in leveraging cybersecurity threat intelligence, indicators of compromise, STIX/TAXII data feeds, MITRE ATT&CK, and SIEM integrations.
- Strong experience in networking principles, operating systems (Linux / Windows), and security tools such as IDS/IPS, firewalls, proxy servers and Endpoint Detection and Response (EDR).
- Knowledge of Windows Sysinternal Suite (including Sysmon) Unix auditd, and how to tune configuration files for identification of malicious activity.
- At least one of the following certifications: Splunk Enterprise Security Certified Admin credential or have passed the AZ-500 Microsoft Azure Security Technologies exam.
ADDITIONAL QUALIFYING FACTORS:
A satisfactory background screening, negative drug test, positive references and proof of identity and legal authorization to work in the United States and for TTO are required.
The Tatitlek Corporation gives hiring, promotion, training and retention preference to Tatitlek shareholders, shareholder descendants and shareholder spouses who meet the minimum qualifications for the job.
As an equal opportunity employer, The Tatitlek Corporation recognizes that our strength lies in our people. Discrimination and all unlawful harassment, including sexual harassment, in employment is not tolerated. We encourage success based on our individual merits and abilities without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, disability, marital status, citizenship status, military status, protected Veteran's status or employment.
Salary$155K+ annually
#J-18808-Ljbffr-
Cybersecurity Detection Engineer
2 months ago
Washington, United States The Tatitlek Corporation Full timeOverview The detection engineer blends technical skills, threat research experience, and knowledge of adversary techniques to work with new and existing data sources to create high fidelity, actionable alerts the ITSO SOC can use to quickly and effectively identify, analyze, and eradicate cybersecurity threats. This individual will be familiar with adversary...
-
Cybersecurity Detection Engineer
4 weeks ago
Washington, United States Pinnacle Group Full timeMust be able to obtain government security clearance. Develop and refine detection techniques to identify malicious activities and security breaches. Analyze descriptions of IOCs and design effective searches to detect these activities in large data sets. Create and maintain detection content, ensuring it is up-to-date with the latest threat intelligence....
-
Cybersecurity Operations Manager
3 weeks ago
Washington, Washington, D.C., United States T-Rex Solutions Full timeJob Overview">The Cybersecurity Operations Manager - Advanced Threat Detection will be responsible for leading a team of security analysts in monitoring and detecting advanced threats within the network.This role requires extensive knowledge of cybersecurity practices, threat analysis, and incident response.The successful candidate will have experience with...
-
Head of Cybersecurity Engineering
2 days ago
Washington, United States Loginsoft Full timeKey ResponsibilitiesCybersecurity Leadership: Lead and leverage expertise in threat intelligence, vulnerability management, cloud security, threat hunting, and threat detection to address client pain points and stay informed on research, emerging technologies, and industry trends.Cybersecurity Engineering Services Growth: Drive the growth and adoption of...
-
Cybersecurity Threat Detection Specialist
6 days ago
Washington, Washington, D.C., United States Capgemini Government Solutions Full timeCompany OverviewCapgemini Government Solutions is a trusted partner for government clients, offering expert solutions in cybersecurity and threat detection. With a strong 55-year heritage and deep industry expertise, our company is committed to addressing the entire breadth of our clients' business needs.
-
Cybersecurity Software Engineer
2 days ago
Washington, United States Top Secret Clearance Jobs Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Software Engineer to join our team at Top Secret Clearance Jobs. As a key member of our product development team, you will play a critical role in designing and implementing cutting-edge software solutions for national security applications. With a strong focus on threat detection and mitigation,...
-
Cybersecurity Engineering Services Leader
2 days ago
Washington, United States Loginsoft Full timeAbout the RoleLoginSoft is a renowned provider of cybersecurity engineering services, specializing in delivering customized solutions to clients in the cybersecurity industry. We are seeking a highly motivated and experienced Cybersecurity Solutions Officer to spearhead the growth and widespread adoption of our cutting-edge cybersecurity engineering...
-
Cybersecurity Threat Detection Specialist
3 weeks ago
Washington, Washington, D.C., United States RAMPS International Inc. Full timeJob SummaryWe are seeking a highly skilled Cybersecurity Threat Detection Specialist to join our team at RAMPS International Inc. in Washington, D.C.Key Responsibilities:Analyzing and interpreting complex data from various sources to identify potential security threatsDeveloping and implementing effective threat detection strategies to mitigate...
-
Cybersecurity Engineer
1 month ago
Washington, United States Kapili Services, LLC Full timeThe Alaka`ina Foundation Family of Companies (FOCs) is looking for a Cybersecurity Engineer to support our government customer located in Washington, DC. This position is 100% on site.DESCRIPTION OF RESPONSIBILITIES:Responsible for supporting the operations of cybersecurity personnel, applications, and appliances employed to defend the cyber terrain, to...
-
Washington, Washington, D.C., United States Koniag Data Solutions, LLC Full timeCybersecurity Engineering and Operations Specialist LeadJob SummaryKoniag Data Solutions, LLC is seeking a skilled Cybersecurity Engineering and Operations Specialist Lead to support our government customer in Washington, DC. This position is for a Future New Business Opportunity.We offer competitive compensation and an extraordinary benefits package...
-
Chief Cybersecurity Strategist
20 hours ago
Washington, United States Loginsoft Full timeAbout LoginSoftLoginSoft is a leading provider of cybersecurity engineering services, delivering customized solutions to clients in the cybersecurity industry.We partner with top cyber product companies, offering tailored solutions and engineering resources for product development and integrations. Our comprehensive range of security offerings includes SCA,...
-
Washington, United States Tatitlek Business Services, Inc. (TBSI) Full timeCybersecurity Detection Engineer RoleAt Tatitlek Business Services, Inc. (TBSI), we're seeking a highly skilled Cybersecurity Detection Engineer to join our team. As a key member of our cybersecurity team, you will play a critical role in detecting and preventing cyber threats.We offer a competitive salary of $155K+ annually, commensurate with experience, as...
-
Cybersecurity Threat Analyst
3 weeks ago
Washington, Washington, D.C., United States The Tatitlek Corporation Full timeJob Summary:The Cybersecurity Detection Engineer will be responsible for developing and implementing advanced threat detection methods to identify and mitigate potential security risks. This role requires a strong understanding of cybersecurity principles, threat intelligence, and security tools such as Splunk Enterprise Security and Microsoft Sentinel.Key...
-
Cybersecurity Solutions Strategist
7 days ago
Washington, United States Loginsoft Full timeAbout LoginSoftLoginSoft is a leading provider of cybersecurity engineering services, specializing in delivering customized solutions to clients in the cybersecurity industry. With a strong track record of partnering with leading cyber product companies, we have gained their trust in providing tailored solutions and engineering resources for product...
-
Cybersecurity Specialist
3 weeks ago
Washington, Washington, D.C., United States AlmrStaffing Full timeJob Opportunity: Cybersecurity SpecialistWe are seeking a skilled Cybersecurity Specialist to work on government installations, safeguarding national security by detecting and neutralizing unauthorized networks.Key Responsibilities:Conduct routine inspections of office spaces to detect surveillance threats.Follow established protocols and standards for...
-
Chief Cybersecurity Innovation Officer
23 hours ago
Washington, United States Loginsoft Full timeAbout LoginSoftLoginSoft is a renowned provider of cybersecurity engineering services, specializing in delivering customized solutions to clients in the cybersecurity industry.We have gained their trust in providing tailored solutions and engineering resources for product development and integrations. Our comprehensive range of security offerings encompasses...
-
Washington, United States GLO Comms Full timeWe are seeking a skilled Cybersecurity Strategist to join our offensive security team at GLO Comms in Washington, DC. This hybrid role requires a technical leader who can drive advanced red team engagements and coordinate purple team activities to enhance our security posture.Job OverviewThe Senior Security Engineer will conduct thorough adversary emulation...
-
Cybersecurity Engineer
1 day ago
Washington, United States Serigor Inc Full timeJob Title: Cybersecurity EngineerLocation: Washington, DCJob Type: Full-timeSalary: $120,000 - $150,000 per yearIndustry: CybersecurityJob Description:We are seeking an experienced Cybersecurity Engineer to join our team at Serigor Inc. in Washington, DC. As a Cybersecurity Engineer, you will be responsible for designing, implementing, and maintaining our...
-
Cybersecurity Solutions Architect Leader
21 hours ago
Washington, United States Loginsoft Full timeJob OverviewWe are seeking an experienced Chief Cybersecurity Solutions Officer to lead the growth and adoption of our cybersecurity engineering services.Responsibilities:Cybersecurity Leadership: Develop and implement a comprehensive cybersecurity strategy, leveraging expertise in threat intelligence, vulnerability management, cloud security, threat...
-
Chief Cybersecurity Architect
3 weeks ago
Washington, United States SAIC Full timeCompany Overview:SAIC is a premier technology integrator, solving complex modernization and systems engineering challenges across various markets. Our robust portfolio includes high-end solutions in systems engineering and integration; enterprise IT, including cloud services; cyber; software; advanced analytics and simulation; and training.Job Summary:We...