Threat Detection Expert

EGSMcLean, VA

About The Position

EGS is looking for a Threat Detection Expert that can build frameworks from the group up. In this role, you will be working with a commercial company's security team to create and build new solutions to challenging problems. This person will be leading the development of new alerting frameworks. You will execute a dual mandate over a designated time period to develop detection logic in the customer SIEM solution, architecting and deploying detections from the ground up, and supporting the migration of logic, queries, and visualizations into a new SIEM solution. You will also work with the customer to improve incident response efficiencies, support the Tier 1 Security Operations Team with investigations and responses, and improve the customer's ability for early detection and mitigation of risks.

Requirements

  • Active TS/SCI clearance with polygraph required.
  • Bachelor's degree in computer science, Engineering, Information Assurance, or a related discipline and 10+ years of related experience. Additional experience may be substituted for a degree.
  • Experience and expertise with SIEM solutions such as Splunk, Kabana, etc.
  • Experience with log telemetry structure and log logic in Windows, Linux, and Containerized environments.
  • Experience with migrating schema mappings from one SIEM solution to another.
  • Ability to demonstrate query language proficiencies.
  • Experience with cloud service providers i.e., Google, AWS, Azure, etc.
  • Experience with the deployment and configuration of data collections from various system components that include operating systems, networking devices, and containerization platforms.
  • Experience creating dashboards, analytics, and alerts within SIEM tools.
  • Experience working with monitoring systems supporting auditing, incident response, and system health.
  • Experience with the OSINT framework and related tools.

Responsibilities

  • Work with the customer to establish a mature Insider threat monitoring capability across multiple windows, Linux, and container environments.
  • Lead the development of new alerting frameworks.
  • Develop detection logic in the customer SIEM solution.
  • Architect and deploy detections from the ground up.
  • Support the migration of logic, queries, and visualizations into a new SIEM solution.
  • Work with the customer to improve incident response efficiencies.
  • Support the Tier 1 Security Operations Team with investigations and responses.
  • Improve the customer's ability for early detection and mitigation of risks.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service