Detection Engineering SME

Softthink SolutionsWashington, DC
Onsite

About The Position

The Detection Engineering SME leads the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules. This role ensures SBA’s threat detection posture is modern, comprehensive, and aligned with current adversary techniques.

Requirements

  • 7+ years of experience in detection engineering, threat hunting, or cyber analytics.
  • Experience authoring SIEM rules and correlation logic.
  • Experience with MITRE ATT&CK, threat intelligence, and adversary emulation.
  • Experience with cloud-native SIEM platforms.

Nice To Haves

  • GIAC Detection Engineering (GCTI, GDAT), CISSP, or equivalent preferred.

Responsibilities

  • Author detection rules for Google SecOps SIEM.
  • Deploy curated detections and validate rule performance.
  • Build multi-event correlation rules aligned to MITRE ATT&CK.
  • Tune detections to meet false-positive thresholds.
  • Integrate threat intelligence sources into detection logic.
  • Support UEBA risk scoring and insider-threat detection.
  • Provide expert guidance during Detect & Tune and Operationalize phases.

Benefits

  • cutting-edge technology
  • training
  • career guidance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service