CareerPlanSign in

Threat Detection Engineer (Cloud Security)

Ogden, UT💼 Full-time💰 $100,000–$100,000🗓 2026-08-31 → 2026-09-26

Core

Design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments to proactively engineer high-fidelity alerts and automate response workflows.

Role type

Senior IC threat detection engineer (cloud security)

Builds

Automated detection signatures, incident response playbooks, and threat hunting capabilities for cloud-native and host-level security

Domain

Cloud security, DoD cybersecurity, AWS GovCloud

Deliverable

production ML models | product features

Required skills

Detection-as-Code, Splunk Enterprise, ELK Stack, AWS GovCloud security telemetry, GitLab CI/CD, MITRE ATT&CK Cloud Matrix, DoD cybersecurity policies, root-cause analysis, AI-assisted analysis

Preferred skills

Infrastructure as Code (Terraform/CloudFormation), container runtime security (Falco, eBPF, Docker), Kubernetes threat modeling, RHEL, post-incident forensics

Technologies

Splunk, Elasticsearch, Logstash, Kibana, AWS CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs, GitLab, Terraform, CloudFormation, Falco, eBPF, Docker, Kubernetes, RHEL

Responsibilities

Designing and deploying detection logic across on-prem and cloud environments; writing custom detection signatures for cloud-native and host-level behavior; ingesting and normalizing AWS security logs into SIEM and data lakes; proactively hunting for malicious activity and adversary TTPs; partnering to develop automated remediation playbooks; conducting root-cause analysis on false positives/negatives; utilizing AI/ML to enhance query generation and threat intelligence correlation; developing DCO concepts of operations and TTPs; supporting vulnerability management mitigations.

Seniority

Senior, hands-on IC

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.