Cybersecurity Detection Engineer
2 months ago
The detection engineer blends technical skills, threat research experience, and knowledge of adversary techniques to work with new and existing data sources to create high fidelity, actionable alerts the ITSO SOC can use to quickly and effectively identify, analyze, and eradicate cybersecurity threats.
This individual will be familiar with adversary Tactics, Techniques, and Procedures (TTPs), and will identify opportunities to improve the effectiveness of existing detection efforts. They will be responsible for developing methodologies to maintain and maximize the integrity and effectiveness of existing alerting through the creation, periodic review, testing, and validation of custom detection content.
Additionally, they will leverage cybersecurity threat intelligence and collaborate with the SOC's incident response teams to meet operational needs and defend against real-world threats.
The minimum qualifications are as follows:
1. A minimum of three years of experience working in detection engineering, threat hunting, security operations, or incident response using Splunk Enterprise Security or Microsoft Sentinel.
2. Experience with the processes to add/update/delete detection rules in Splunk Enterprise Security and Microsoft Sentinel.
3. Proficient in detection engineering methodologies including SNORT and YARA rules.
4. Proficient in Python programming, Bash, and PowerShell.
5. Proficient in Splunk's Search Processing Language, React, Kusto Query Language, and the Common Information Model (CIM).
6. Knowledgeable and experienced in leveraging cybersecurity threat intelligence, indicators of compromise, STIX/TAXII data feeds, MITRE ATT&CK, and SIEM integrations.
7. Strong experience in networking principles, operating systems (Linux / Windows), and security tools such as IDS/IPS, firewalls, proxy servers and Endpoint Detection and Response (EDR).
8. Knowledge of Windows Sysinternal Suite (including Sysmon) Unix auditd, and how to tune configuration files for identification of malicious activity.
9. At least one of the following certifications: Splunk Enterprise Security Certified Admin credential or have passed the AZ-500 Microsoft Azure Security Technologies exam.
ADDITIONAL QUALIFYING FACTORS:
A satisfactory background screening, negative drug test, positive references and proof of identity and legal authorization to work in the United States and for TTO are required.
The Tatitlek Corporation gives hiring, promotion, training and retention preference to Tatitlek shareholders, shareholder descendants and shareholder spouses who meet the minimum qualifications for the job.
As an equal opportunity employer, The Tatitlek Corporation recognizes that our strength lies in our people. Discrimination and all unlawful harassment, including sexual harassment, in employment is not tolerated. We encourage success based on our individual merits and abilities without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, disability, marital status, citizenship status, military status, protected Veteran's status or employment.
Salary
$155K+ annually
-
Cybersecurity Detection Engineer SME Remote
8 hours ago
Washington, United States Quadtec Solutions, Inc. Full timeJob Description Job Description The detection engineer blends technical skills, threat research experience, and knowledge of adversary techniques to work with new and existing data sources to create high fidelity, actionable alerts the SOC can use to quickly and effectively identify, analyze, and eradicate cybersecurity threats. This individual will be...
-
Cybersecurity Threat Detection Expert
2 days ago
Washington, Washington, D.C., United States Apex Systems Full timeAlex Systems is seeking a highly skilled Cybersecurity Threat Detection and Response Expert to join their team. As a leader in the field of cybersecurity, we are looking for someone with 3+ years of experience in SIEM and security operations, particularly in the public cloud environment (AWS, GCP, Azure). The successful candidate will have expertise in...
-
Cybersecurity Detection Engineer
1 month ago
Washington, United States Pinnacle Group Full timeMust be able to obtain government security clearance. Develop and refine detection techniques to identify malicious activities and security breaches. Analyze descriptions of IOCs and design effective searches to detect these activities in large data sets. Create and maintain detection content, ensuring it is up-to-date with the latest threat intelligence....
-
Head of Cybersecurity Engineering
2 weeks ago
Washington, United States Loginsoft Full timeKey ResponsibilitiesCybersecurity Leadership and Roadmap Development: Lead and leverage expertise in threat intelligence, vulnerability management, cloud security, threat hunting, and threat detection.Cybersecurity Engineering Services Growth and Adoption: Drive the growth and adoption of cybersecurity engineering services by driving penetration of existing...
-
Cybersecurity Engineer
2 weeks ago
Washington, United States Phoenix Cyber Full timeAbout the JobWe are seeking a highly skilled Cybersecurity Engineer to join our team at Phoenix Cyber. As a key member of our cybersecurity services, you will be responsible for architecting results-oriented solutions and ensuring accurate incident detection, enrichment, and response.This is a 100% remote opportunity with a salary range of $120,000 -...
-
Engineer, Cybersecurity III
5 days ago
Washington, United States OneZero Solutions Full timeJob DescriptionJob DescriptionJob Summary:OneZero Solutions, LLC is seeking a Cybersecurity Engineer III to join our team and contribute to critical cybersecurity operations. This role combines technical acumen with operational vigilance to protect data and systems. You will play a key role in isolating, investigating, informing, and implementing measures to...
-
Engineer, Cybersecurity II
5 days ago
Washington, United States OneZero Solutions Full timeJob DescriptionJob DescriptionJob SummaryOneZero Solutions, LLC is seeking a Cybersecurity Engineer II to join our team and contribute to critical cybersecurity operations. This role combines technical acumen with operational vigilance to protect data and systems. You will play a key role in isolating, investigating, informing, and implementing measures to...
-
Engineer, Cybersecurity I
5 days ago
Washington, United States OneZero Solutions Full timeJob DescriptionJob DescriptionJob SummaryOneZero Solutions, LLC is seeking a Cybersecurity Engineer I to join our team and contribute to critical cybersecurity operations. This role combines technical acumen with operational vigilance to protect data and systems. You will play a key role in isolating, investigating, informing, and implementing measures to...
-
Cybersecurity Threat Detection Specialist
8 hours ago
Washington, Washington, D.C., United States Leidos Holding Full timeLeidos is a Fortune 500 innovation company that rapidly addresses the world's most vexing challenges in national security and health.About the RoleThis position involves managing and conducting hands-on technical detection, analysis, containment, eradication, and remediation as a member of the Incident Response team. The ideal candidate will have extensive...
-
Lead Security Engineer
6 days ago
Port Washington, United States Cox Full timeThe Lead Cybersecurity Detection Engineering will be a part of a team of Detection Engineers to design, implement, and maintain advanced detection capabilities, protecting the organization from emerging cyber threats. This crucial role will enhance Cox Automotive's next-generation Cyber Defense practice, enabling rapid threat response and automated...
-
Head of Cybersecurity Engineering
3 weeks ago
Washington, United States Loginsoft Full timeKey ResponsibilitiesCybersecurity Leadership: Lead and leverage expertise in threat intelligence, vulnerability management, cloud security, threat hunting, and threat detection to address client pain points and stay informed on research, emerging technologies, and industry trends.Cybersecurity Engineering Services Growth: Drive the growth and adoption of...
-
Cybersecurity Threat Detection Specialist
4 weeks ago
Washington, Washington, D.C., United States Capgemini Government Solutions Full timeCompany OverviewCapgemini Government Solutions is a trusted partner for government clients, offering expert solutions in cybersecurity and threat detection. With a strong 55-year heritage and deep industry expertise, our company is committed to addressing the entire breadth of our clients' business needs.
-
Cybersecurity Software Engineer
3 weeks ago
Washington, United States Top Secret Clearance Jobs Full timeAbout the RoleWe are seeking a highly skilled Cybersecurity Software Engineer to join our team at Top Secret Clearance Jobs. As a key member of our product development team, you will play a critical role in designing and implementing cutting-edge software solutions for national security applications. With a strong focus on threat detection and mitigation,...
-
Cybersecurity Engineer
5 days ago
Washington, United States MetroStar Full timeAs Cybersecurity Engineer, you’ll play a pivotal role in safeguarding our organization's digital assets and sensitive information. The ideal candidate is a dedicated professional with a strong background in cybersecurity, a deep understanding of current threats and vulnerabilities, and the ability to implement robust security measures. As a Cybersecurity...
-
Cybersecurity Expert
2 weeks ago
Washington, United States Anduril Full timeJob OverviewWe are seeking an experienced Cybersecurity Expert to join our team at Anduril Industries, Inc. as a Threat Detection Specialist.About AndurilAnduril is a defense technology company that specializes in advanced autonomous systems. Our mission is to transform U.S. and allied military capabilities with cutting-edge technology. By combining...
-
Cybersecurity Engineering Services Leader
3 weeks ago
Washington, United States Loginsoft Full timeAbout the RoleLoginSoft is a renowned provider of cybersecurity engineering services, specializing in delivering customized solutions to clients in the cybersecurity industry. We are seeking a highly motivated and experienced Cybersecurity Solutions Officer to spearhead the growth and widespread adoption of our cutting-edge cybersecurity engineering...
-
Cybersecurity Specialist
2 weeks ago
Washington, Washington, D.C., United States RAMPS International Inc. Full timeWe are seeking a highly skilled Cybersecurity Specialist to join our team at RAMPS International Inc. in Washington, D.C.Job Description:The ideal candidate will have a strong background in cybersecurity, with experience in threat detection and response. Key responsibilities include defining and implementing security configurations for threat...
-
Cybersecurity Engineer
7 days ago
Washington, United States Phoenix Cyber Full timeJob DescriptionJob DescriptionPhoenix Cyber is looking for Cybersecurity Engineers to join our client delivery team. This is a remote, work-from-home position with the possibility of minimal travel within the continental United States.Requirements:Degree in a STEM related discipline and/or a minimum 5 years of experienceTen (10) years of relevant IT...
-
Cybersecurity Threat Hunter
9 hours ago
Washington, Washington, D.C., United States Quadtec Solutions, Inc. Full timeJob OverviewCybersecurity threats are becoming increasingly sophisticated, making it essential to have a dedicated professional who can identify and mitigate potential risks. At Quadtec Solutions, Inc., we are seeking a highly skilled Detection Engineer SME to join our team of experts in cybersecurity detection engineering.About the RoleThe Detection...
-
Cybersecurity Engineer
2 days ago
Washington, Washington, D.C., United States Apex Systems Full timeCybersecurity Engineer - Cloud SIEMAlex Systems is seeking a highly skilled Cybersecurity Engineer to join our team. As a key member of our cybersecurity team, you will be responsible for designing and implementing secure cloud-based systems and architectures that meet security and compliance requirements.Key Responsibilities:Collaborate with internal...