user avatar

Detection Engineer

Blu Omega LLC

Posted today

Job Requirements

Rockville, MD
Top Secret Polygraph Unspecified
Career Level not specified
$70,000 - $90,000

Job Description

Detection Engineer
Remote

Blu Omega is seeking a Detection Engineer to support a federal program focused on the protection of critical health systems and data. This role operates within a fully remote environment and is responsible for cybersecurity monitoring and detection activities. The position requires experience supporting security operations and detection engineering within a mission-driven environment.

Program Overview
NIH Cybersecurity Operations Center; protection of critical federal health systems/data; 24/7 enterprise cybersecurity operations

Key Details
Location: Remote
Clearance: NIH Public Trust; must be able to obtain and maintain

Responsibilities
Develop and maintain security alerts and detection rules within Splunk
Write and modify SPL queries to identify suspicious or potentially malicious activity
Create and maintain Splunk dashboards, reports, and security analytics
Review and tune existing detections to improve accuracy and reduce false positives
Support phishing detection and analysis using Cofense Triage or similar tools
Assist with the development and maintenance of YARA rules
Use SnapAttack and other security tools to support detection development and analysis
Leverage built-in security analytics and detections across cybersecurity tools
Support threat hunting and investigation of suspicious activity
Apply MITRE ATT&CK concepts to understand attacker behaviors and detection coverage
Work with SOC analysts, incident responders, and other cybersecurity team members to improve monitoring and detection capabilities
Document detection rules, queries, dashboards, and investigative procedures

Required Qualifications
2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
Experience working with Splunk or a comparable SIEM platform
Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
Understanding of common cybersecurity threats and attacker techniques
Experience reviewing or investigating cybersecurity alerts
Strong analytical, troubleshooting, and communication skills

Preferred Qualifications
Experience developing or tuning security detections in Splunk
Familiarity with YARA rules
Experience with Cofense Triage or phishing analysis
Familiarity with SnapAttack
Knowledge of MITRE ATT&CK
Experience with threat hunting, endpoint security, or incident response
Federal cybersecurity experience
Security certification such as Security+, CySA+, CEH, or similar

Salary Range
$70,000.00 - $90,000.00

#CJ
#LI-Remote
group id: 91121246

Similar Jobs


Clearance Level
Top Secret