Detection Engineer Analyst Subject Matter Expert (SME)

Resource Management ConceptsQuantico, VA
Onsite

About The Position

Resource Management Concepts, Inc. (RMC) is seeking a Detection Engineer Analyst Subject Matter Expert (SME) to support an active government contract in Quantico, Virginia. This role will provide defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions, contributing to the government's mission to deny, disrupt, and degrade adversaries' cyber activities. The position involves developing detection use cases, reviewing incident reports, managing SIEM/SOAR queues, identifying logging gaps, and implementing new log ingestion. The SME will create and maintain high-fidelity correlation rules, signatures, filters, and automations to ensure a low false-positive rate.

Requirements

  • Active TS/SCI (DoD TOP SECRET clearance with Sensitive Compartmented Information access) eligibility is required.
  • Applicant selected will be subject to security investigation(s) and must maintain eligibility requirements for access to classified information.
  • Bachelor’s in IT or Computer Science OR 5 years’ supporting DCO and/or network systems and technology.
  • DoD 8570 IAT Level III certification.
  • DoD 8570 CSSP Analyst certification.
  • 5 years’ experience with development/refinement of signatures, plays, policies, configurations, scripts and indicators used to identify malicious activity via network and host-based detection on the enterprise network.
  • Experience leading operations and maintenance support for an enterprise-level (50k users) network.
  • Experience writing signatures (e.g., KQL/Snort/ePO/Yara) for network and host IDS/IPS.

Nice To Haves

  • Microsoft Cloud Security training is highly recommended.
  • Microsoft Azure and Microsoft Defender XDR.
  • Microsoft Sentinel Ninja Training.
  • Microsoft Defender For Endpoint Ninja Training.
  • Microsoft Defender For Identity Ninja Training.
  • Microsoft SC-XXX Training (certifications).

Responsibilities

  • Develop detection use cases based on current threats, the MITRE ATT&CK framework, and government direction.
  • Review incident reporting to tune related detection use cases as necessary.
  • Review Security Information and Event Management (SIEM)/ Security Orchestration, Automation, and Response (SOAR) incident queue for unnecessary events and alerts and implement corrective actions.
  • Identify gaps in logging and detection capabilities across the attack surface.
  • Assist in implementing new log ingestion and verify proper parsing and normalization of data in SIEM/SOAR.
  • Create high fidelity correlation rules, signatures, filters, and automations and maintain a low false-positive rate.

Benefits

  • Investment in employee career growth through training, certification, and education.
  • Tuition assistance.
  • Paid relocation.
  • Competitive paid vacation package.
  • 11 paid federal holidays.
  • High-quality, low-deductible healthcare plans.
  • Pet insurance.
  • Competitive 401K package.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service