user avatar

Senior Cybersecurity Detections Engineer

ShorePoint, Inc

Today
Top Secret/SCI
Unspecified
Unspecified
IT - Security
Springfield, VA (On-Site/Office)

Who we are:

ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers. We are equally passionate about an environment that supports creativity, accountability, diversity, inclusion and a focus on giving back to our community.

The Perks:

As recognized members of the Cyber Elite, we work together in partnership to defend our nation's critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individuals technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, including major carriers for health care providers. Highlighted benefits offered: 18 days of PTO, 11 holidays, 85% of insurance premium covered, 401k, continued education, certifications maintenance and reimbursement and more.

Who we're looking for:

We are seeking a Senior Cybersecurity Detections Engineer to support our Cyber Operations mission by developing, deploying and optimizing detection and response capabilities. The ideal candidate will create advanced detection content, analyze complex cyber incidents and strengthen enterprise defenses against evolving threats. The Sr. Cybersecurity Detections Engineer role provides the opportunity to directly contribute to national security while working in a growth-oriented, innovative environment. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.

What you'll be doing:
  • Formulate and publish custom Security Information and Event Management (SIEM) content and IDS/IPS signatures to address emerging threats.
  • Perform security event and incident correlation using data from multiple enterprise sources.
  • Analyze and assess impact to data and infrastructure resulting from cyber incidents.
  • Conduct cyber incident trend analysis and prepare reports to inform leadership.
  • Characterize and analyze network traffic and system data to detect anomalous activity and potential threats.
  • Provide detection, identification and reporting of possible cyber-attacks, intrusions, anomalous activity and misuse.
  • Create, deploy and implement threat-based signatures and detection rules for intrusion detection capabilities.

What you need to know:
  • Strong knowledge of modern Windows, UNIX and network operating systems.
  • Familiarity with databases and virtual computing environments.
  • Knowledge of countermeasures and mitigating controls.
  • Experience with enterprise security tools including SIEMs, Threat Intelligence Platforms and network monitoring solutions.
  • Proficiency in creating, modifying and tuning IDS signatures, SIEM correlation searches and other detection signatures.

Must have's:
  • Bachelor's degree or 4+ years of additional cyber experience in lieu of degree.
  • DoD 8570 certification meeting IAT Level II requirements (e.g., GSEC, Security+, SSCP or CCNA-Security).
  • 5+ years of relevant experience.
  • Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.
  • Knowledge of countermeasures and mitigating controls.
  • Experience with enterprise security tools, including SIEMs, Threat Intelligence Platforms (TIPs) and network monitoring solutions.
  • Proficiency in creating, modifying and tuning IDS signatures, SIEM correlation searches and other detection signatures.
  • Must possess an active TS/SCI clearance with Polygraph.

Beneficial to have:
  • Advanced Linux/Unix command line proficiency used within the last six months.

Where it's done:
  • Onsite (Springfield, VA).
group id: 91085370
N
Name HiddenRecruiter

Match Score

Powered by IntelliSearchâ„¢
image match score
Create an account or Login to see how closely you match to this job!

Similar Jobs


Job Category
IT - Security
Clearance Level
Top Secret/SCI