Detection Engineer
$120,000–$140,000 year
RemoteUnited States or Edgewater, Illinois, United States
Job Summary
Maintain and operate Splunk application monitoring tools within the Threat Monitoring and Incident Response team to detect, analyze, contain, and remediate security incidents. Develop actionable alerts, workflows, and knowledge objects like dashboards and reports while conducting deep analysis and hunting operations to improve security operations. Lead analyst training, implement automation efficiencies, and perform incident response and remediation workflows. Communicate with customer stakeholders, co-lead client calls, and produce formal documentation including reports and architecture diagrams. Requires U.S. citizenship for security clearance, 5+ years of Splunk and SIEM experience, and 3+ years of endpoint forensics. Salary is $120,000-$140,000.
Required Qualifications
- U.S. Citizenship
- U.S. security clearance
- At least 5 years of strong problem-solving capabilities
- Ability to effectively communicate solutions
- One or more certifications in information security (such as GCIA, GCIH, CEH, CISSP, SSCP, Sec+, etc)
- Sound cyber security knowledge foundation
- Understanding of Adversary TTPs
- Understanding of Network & Host Security
- At least 5 years of Splunk and SIEM experience
- At least 3 years of Trend spotting, identifying intelligence knowledge gaps, and performing analysis on threat data
- High technical ability/aptitude
- Prior technical experience and accomplishment
- At least 3 years of Endpoint/host forensics experience
- Excellent verbal, written, and interpersonal skills
- Command of English language
- Strong written and verbal skills to effectively communicate at all levels in government and industry
- Exceptionally self-motivated
- Directed
- Detail oriented
- Ability to learn, understand and apply new technologies
- Excellent organizational, analytical and problem-solving abilities
- Working knowledge of Microsoft Office (Outlook, Word, Excel, PowerPoint, Project, and SharePoint)
- History of ethical performance
- Exhibit considerable client delivery, business development, and proposal development experience
- Strong management, teamwork, and interpersonal skills
- Ability to meet the needs of internal and external customers
- Professional, pleasant, and polished demeanor
- Ability to work collaboratively with others
- Ability to maintain confidentiality of sensitive information within and external to EdgeWater
- Strong eye for small details that make a difference
Desired Qualifications
- Ten or more years of cyber security work experience in Threat Hunting, Splunk Content Development, and Incident Response
- Active Public Trust clearance
- Experience and effective participation in hunt, computer network defense, real-time analysis and incident response activities
- Ability to reconstruct events from network, endpoint, and log data
- Experience and understanding of host-based/endpoint protection systems
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.