Senior Detection Engineer

SkyePoint DecisionsArlington, VA
Onsite

About The Position

SkyePoint Decisions is seeking an experienced Senior Detection Engineer for their customer's Federal Strategic Cyber Group. This position is contingent upon customer approval and is located in Rosslyn, VA with a secondary location of Beltsville, MD. The role involves performing advanced custom development and implementation of cybersecurity alerts, developing and tuning cyber security tools, integrating security alerts into SOAR and SIEM systems, and automating workflows to enhance threat response. The engineer will analyze systems for optimal logging and alerting, provide technical expertise in various coding languages, and support the security operations center through security development and cross-team collaboration. The goal is to enhance the customer’s defense against advanced cyber adversaries by implementing and refining cyber monitoring, analysis, and response capabilities.

Requirements

  • Bachelor’s degree and minimum of 9 years of relevant experience; 7 years with Masters degree; 4 years with PhD. An additional 4 years of relevant experience will be substituted in lieu of the degree requirement.
  • To be considered for this position, you must either currently hold one of the professional certifications listed below or obtain one prior to their start date. Continued certification is required as a condition of employment: CASP+ CE, CCNA Cyber Ops, CCNA-Security, CCNP Security, CEH, CFR, CISA, CISSP (or Associate), Cloud+, CySA+, GCED, GCIA, GCIH, GICSP, SCYBER, VCA DCV, PPDA, Agile IC, SNOW App Dev
  • U.S. citizenship required.
  • Active Secret security clearance.
  • Ability to obtain final Top Secret clearance.

Nice To Haves

  • A solid understanding of the MITRE ATT&CK Framework
  • A solid understanding of Splunk Enterprise Security
  • A solid understanding of Cybersecurity Incident Response
  • A solid understanding of Cloud Development with Microsoft Azure/MDE.
  • A solid understanding of Machine Learning and User and Entity Behavior Analytics.

Responsibilities

  • Perform advanced custom development and implementation of cybersecurity alerts
  • Develop, configure, and tune cyber security tools, alerts, and response capabilities
  • Integrate security alerts and process workflows into SOAR and SIEM systems
  • Automate and optimize security alert workflows to enhance threat response capabilities and enhance efficiency throughout the Incident Response lifecycle
  • Analyze systems and environments to determine necessary logging and alerting to optimize cyber security monitoring in an ever-changing cyber threat landscape
  • Provide technical expertise for Splunk, Python, JavaScript, PowerShell, and similar coding languages
  • Support the security operations center through security development
  • Support cross team collaboration efforts to enhance the customer’s defense against advanced cyber adversaries
  • Implement cyber monitoring, analysis, and response capabilities within our SIEM, SOAR, and detection tools.
  • Develop and enhance threat detections and advanced analysis capabilities.
  • Provide tuning of threat detections.
  • On-board and integrate cyber monitoring tools from the analyst’s perspective.
  • Coordinate with engineers to assist in building and maintaining platforms.
  • Coordinate with cyber threat experts to implement the latest signatures.
  • Create and maintain various security dashboards, alerts, and reports.
  • Write Zeek (Bro), Suricata and Snort signatures.
  • Maintain Python and JavaScript based detections and automation capabilities within our tools.

Benefits

  • Certification incentive program
  • PTO
  • Floating federal holiday options
  • Several insurance options including HMO and and High Deductible plans with Health Savings Accounts [HSAs]
  • Flex Spending Accounts [FSAs]
  • Full Dental Plans
  • Vision
  • ST/LT Disability
  • Life Insurance
  • 401k matched
  • Flexible Work Environment
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service