Senior Security Detection Engineer

3 weeks ago


Fairfax, United States ECS Full time

ECS is seeking a Senior Security Detection Engineer to work in our Fairfax, VA office.

Job Description:

At ECS Federal, we're driven by a commitment to excellence and innovation in solving complex challenges. As a premier provider of advanced technology solutions and services, our mission is to secure and optimize the most critical commercial, government, defense, and intelligence projects across the country. Our team is composed of dynamic professionals who thrive in a collaborative and empowering environment, where our team members leverage the latest technologies and insights to make a real-world impact. Join us and be part of a forward-thinking organization that values your expertise and supports your professional growth.

We are seeking a Senior Detection Engineer to serve as a pivotal contributor within our Security Operations Center (SOC). This role demands a strategic thinker and an expert in detection engineering, dedicated to enhancing our cybersecurity posture through advanced threat detection, proactive threat hunting, and automation. You will work closely with our SOC analysts, Incident Response, and Threat Intelligence teams to ensure that our detection mechanisms are always ahead of emerging threats. If you are passionate about developing innovative detection solutions and enhancing security operations, we invite you to bring your expertise to ECS, where your efforts will help secure the future of our clients' digital landscapes.

Responsibilities:

  • Design, develop, and implement advanced detection strategies across a variety of security platforms, including but not limited to SIEMs, EDR, NDR, and SOAR tools.
  • Create and maintain custom detection content (e.g., correlation rules, signatures, alerts) to identify and mitigate emerging threats.
  • Collaborate with Threat Intelligence and Incident Response teams to refine detection logic and ensure security alerts are relevant, actionable, and aligned with the latest threats and overall security strategy.
  • Continuously optimize and tune detection content to reduce false positives and improve detection accuracy.
  • Provide mentorship and technical guidance to junior engineers and analyst, fostering a culture of continuous learning and improvement.
  • Document detection logic, use cases, and operational procedures to ensure consistency and knowledge sharing across teams.
  • Conduct regular tuning of detection content to adapt to evolving threats and changes in the operational environment.
  • Contribute to the development and tracking of key performance indicators (KPIs) related to detection efficacy and response times.
  • Engage with cross-functional teams to ensure seamless integration of detection content within broader security operations.
  • Document and maintain detection methodologies, operational procedures, and best practices to ensure consistency, scalability and knowledge sharing across teams.
Required Skills:
  • Bachelor's degree; preferably in Computer Science, Information Security, or a related field. Will consider experience in lieu of a degree.
  • Minimum of 10 years of experience in cybersecurity, with a strong focus on detection engineering, threat detection, or SOC operations.
  • Proficiency in developing detection content for SIEM platforms such as Splunk, ArcSight, Qradar, Logrhythm, or Securonix
  • Experience with endpoint detection and response (EDR) tools such as CrowdStrike, SentinelOne, or Carbon Black.
  • Expertise in analyzing and interpreting threats from a wide range of data sources, including IDS/IPS, AV, HIDS/HIPS, WAFs, firewalls, web applications, and web proxies, with the ability to identify and mitigate advanced threats.
  • Experience in utilizing technologies such as ElasticSearch, Zeek, SIGMA, Suricata, and YARA for developing and optimizing detection rules, threat hunting, and incident response.
  • Proficiency in leveraging Detection as Code (DaC) practices to automate and standardize detection logic, enabling rapid deployment and consistent threat detection across multiple environments.
  • Comprehensive knowledge of cyber threat tactics, techniques, and procedures (TTPs), with a proven ability to develop and implement effective alerting, countermeasures, and proactive threat-hunting techniques.
  • Proficiency with the MITRE ATT&CK framework and its application in detection strategies.
  • Deep understanding of network security, intrusion detection/prevention systems (IDS/IPS), and malware analysis.
Desired Skills:
  • Certifications such as GCIA/GCIH/GCFA/GNFA/GREM or OSCP.
  • Excellent analytical and problem-solving skills, with the ability to handle complex security challenges and think like an adversary
  • Experience with cloud security platforms (AWS, Azure, GCP) and integrating native security tools.
  • Experience with scripting languages such as Python, PowerShell, or Bash to support automation and custom detection development.
  • Proven track record of performing threat hunting and incident detection in large-scale enterprise environments.
  • Experience leading security projects that have significantly enhanced detection capabilities or reduced incident response times.
  • Strong communication skills, with the ability to articulate complex technical concepts to both technical and non-technical audiences.


ECS is an equal opportunity employer and does not discriminate or allow discrimination on the basis of race, color, religion, sex, age, sexual orientation, gender identity or expression, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, status as a crime victim, disability, protected veteran status, or any other characteristic protected by law. ECS promotes affirmative action for minorities, women, disabled persons, and veterans.

ECS is a leading mid-sized provider of technology services to the United States Federal Government. We are focused on people, values and purpose. Every day, our 3800 employees focus on providing their technical talent to support the Federal Agencies and Departments of the US Government to serve, protect and defend the American People.
  • Security Engineer SME

    2 months ago


    Fairfax, United States Govcio LLC Full time

    Overview: GovCIO is currently hiring for a Security Engineer SME with an active Secret clearance in support of our DEA Bluestone program. Responsibilities: Build culture of security-first development and IT infrastructureDeliver Cybersecurity and IA SOPsDesign enterprise wide security approach to Continuous ATO, based on NIST RMF, across on premise and...

  • Security Engineer SME

    3 months ago


    Fairfax, United States Govcio LLC Full time

    Overview: GovCIO is currently hiring for a Security Engineer SME with an active Secret clearance in support of our DEA Bluestone program. Responsibilities: Build culture of security-first development and IT infrastructureDeliver Cybersecurity and IA SOPsDesign enterprise wide security approach to Continuous ATO, based on NIST RMF, across on premise and...


  • Fairfax, United States ECS Full time

    ECS is seeking a Senior DevOps Engineer to work in our Fairfax, VA office. ECS is seeking talented professionals to join our successful and growing team in building the next-generation Continuous Diagnostics and Mitigation (CDM) Cyber data solution. The CDM Program is the Cybersecurity and Infrastructure Security Agency's (CISA) dynamic approach to...


  • Fairfax, Virginia, United States Northrop Grumman Full time

    Job SummaryNorthrop Grumman is seeking a Senior Principal DevOps Engineer to join our team in the Payload and Ground Systems Division Engineering organization. This position will support a new Ground program and require being onsite.Key ResponsibilitiesPlan and evolve processes and infrastructure to execute programs that support rapid maturation and...


  • Fairfax, United States Lorven Technologies Full time

    Role: Cybersecurity Principal/Architect (Intermediate Level & Senior Level) Location: Fairfax County, VA - Onsite Contract Role Job Description: Execute cybersecurity and information security frameworks organizationally wide to secure enterprise systems and data. Implement, administer, and use cybersecurity tools, systems, and applications; develop...


  • Fairfax, Virginia, United States Azure Summit Technology Full time

    Job Title: Senior Firmware EngineerAzure Summit Technology is a leading provider of advanced RF systems solutions for national security applications. We are seeking a highly skilled Senior Firmware Engineer to join our team in Fairfax, Virginia.About the Role:The selected candidate will be responsible for designing and developing firmware for complex RF...


  • Fairfax, United States Futures Consulting, LLC Full time

    DescriptionAt our firm, we are hiring an experienced Leader in Structural Engineering to join our team in Virginia. As a senior member of our Structures team you will focus on leading a variety of dynamic structural pursuits and projects as it relates to transportation. You should have state (Virginia/VDOT) and municipal experience, be highly proactive, able...


  • Fairfax, United States Futures Consulting, LLC Full time

    DescriptionAt our firm, we are hiring an experienced Leader in Structural Engineering to join our team in Virginia. As a senior member of our Structures team you will focus on leading a variety of dynamic structural pursuits and projects as it relates to transportation. You should have state (Virginia/VDOT) and municipal experience, be highly proactive, able...


  • Fairfax, United States SunPlus Data Group, Inc Full time

    Job DescriptionJob DescriptionSunPlus is looking for a Splunk Cyber Security Engineer for the State of VA in Fairfax, VA.PAY RATE: $100 hourly 1099, $91 W2 hourlyDURATION: 8 months with extension possible if good fitHOURS: Monday – Friday, 40 hrs. per week, Day ShiftJob# 750963100% ON SITE*It usually takes the State Government 2-3 weeks to start...

  • Systems Engineer

    1 month ago


    Fairfax, United States TapHere! Technology, LLC Full time

    TapHere is looking for a self-starting, team-oriented Mid-to-Senior System Engineer to join our dynamic team in supporting a Government customer.The engineer will be working with a large-scale enterprise applications using web technologies, distributed computation and storage frameworks with the system hosted on virtualized and cloud-computing platforms.The...


  • Fairfax, United States DSA Full time

    DSA is hiring a Senior Information Security Analyst. This is a full-time position in the DC Area. This position supports the Environmental Protection Agency (EPA). DSA is the Prime and has been working with this customer on this contract for more than 13 years. It is a dynamic team with a passion for supporting Federal programs that serve US Citizens....


  • Fairfax, United States SITEC Consulting LLC Full time

    ABOUT SITEC SITEC is an employee and customer focused Information Technology and Professional Services Firm specializing in design, development, and delivery of state-of-the-art technology solutions, as well as cybersecurity, software and systems engineering services. Join the and be part of a long-term contract supporting the. We are seeking a Network...


  • Fairfax, United States Erickson senior Living Full time

    Location:Woodleigh Chase by Erickson Senior LivingWoodleigh Chase is a beautiful 42-acre continuing care retirement community located in Fairfax, Virginia.  We’re part of a growing network of communities developed and managed by Erickson Senior Living, a national provider of senior living and health care with campuses in 11 states—and growing. The...


  • Fairfax, Virginia, United States Azure Summit Technology Full time

    Job DescriptionAzure Summit Technology is a leading provider of innovative RF hardware, firmware, and software products, as well as multi-function RF systems solutions that address emerging missions of national importance for customers across the Department of Defense.We are a diverse team of highly qualified RF systems engineers and mission subject matter...


  • Fairfax, United States Excel Hire Staffing, LLC Full time

    Splunk Cyber Security Engineer (6 months+ Contract Assignment) Location: 4890 Alliance Dr, Fairfax, Va 22030 (Hybrid - 2/3 days in the office – Must live local) ContractSplunk Cyber Security Engineer will be responsible for engineering data ingestion into Virginia Department of Transportation Splunk instance is configured and maintained properly. This...

  • Senior Civil Engineer

    3 months ago


    Fairfax, United States The Judge Group Full time

    Senior Civil EngineerFairfax, VASeeking an energetic, highly motivated Senior Civil Engineer to join our Fairfax, Virginia office.Function:Provide Technical knowledge and project management of design, production, and coordination of conceptual and final design of civil engineering tasks. Advise and recommend design procedures and interface with clients and...

  • Security Officer

    4 weeks ago


    Fairfax, Virginia, United States Allied Universal® Full time

    Job OverviewAllied Universal, a leading security and facility services company, offers a dynamic and inclusive work environment that fuels a culture of purpose and community service. Our team members enjoy a range of benefits, including medical, dental, and vision coverage, life insurance, retirement plan, employee assistance programs, company discounts, and...

  • Senior Civil Engineer

    1 month ago


    Fairfax, United States The Judge Group Full time

    Senior Civil EngineerFairfax, VASeeking an energetic, highly motivated Senior Civil Engineer to join our Fairfax, Virginia office.Function:Provide Technical knowledge and project management of design, production, and coordination of conceptual and final design of civil engineering tasks. Advise and recommend design procedures and interface with clients and...


  • Fairfax, United States Rose International Full time

    Date Posted: 11/19/2024Hiring Organization: Rose InternationalPosition Number: 474584Job Title: Splunk Cyber Security EngineerJob Location: Fairfax, VA, USA, 22030Work Model: HybridEmployment Type: TemporaryEstimated Duration (In months): 8Min Hourly Rate($): 70.00Max Hourly Rate($): 80.00Must Have Skills/Attributes: Linux, Networking, Red Hat, Splunk Job...


  • Fairfax, United States DataStaff, Inc. Full time

    DataStaff, Inc. is seeking a Splunk Cyber Security Engineer for a long-term contract opportunity with one of our direct clients in Fairfax, VA.*This role is hybridResponsibilities:Splunk Cyber Security Engineer will be responsible for engineering data ingestion into Splunk instance is configured and maintained properly. This includes but is not limited to...