Cybersecurity Engineer (Detection Engineering)
Core
Develop, implement, and tune security detection rules and playbooks for SIEM and EDR systems to identify threats targeting government networks, endpoints, and cloud environments.
Role type
Detection Engineering Engineer
Builds
Production detection rules, playbooks, and automated alerting workflows for government security operations centers
Domain
Government cybersecurity, threat detection, SIEM/EDR operations
Deliverable
production ML models | product features | dashboards & analysis
Required skills
Sigma, KQL, SPL, EQL, YARA, MITRE ATT&CK, threat intelligence analysis, log analysis, incident response protocols, automation scripting
Preferred skills
Python, PowerShell, SOAR, detections as code, version control workflows
Technologies
SIEM, EDR, SOAR, Sigma, KQL, SPL, EQL, YARA
Responsibilities
Develop and document security detection rules and playbooks; analyze security logs and alerts to differentiate true threats from benign activity; continuously improve detection capabilities through threat research and rule tuning; collaborate with analysts on incident response protocols; integrate detection systems and define requirements to optimize tool usage
Seniority
Mid-level, hands-on IC