Threat Detection Engineer (Cloud Security)
Core
Design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments to proactively engineer high-fidelity alerts and automate response workflows.
Role type
Senior IC threat detection engineer (cloud security)
Builds
Automated detection signatures, incident response playbooks, and threat hunting capabilities for cloud-native and host-level security
Domain
Cloud security, DoD cybersecurity, AWS GovCloud
Deliverable
production ML models | product features
Required skills
Detection-as-Code, Splunk Enterprise, ELK Stack, AWS GovCloud security telemetry, GitLab CI/CD, MITRE ATT&CK Cloud Matrix, DoD cybersecurity policies, root-cause analysis, AI-assisted analysis
Preferred skills
Infrastructure as Code (Terraform/CloudFormation), container runtime security (Falco, eBPF, Docker), Kubernetes threat modeling, RHEL, post-incident forensics
Technologies
Splunk, Elasticsearch, Logstash, Kibana, AWS CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs, GitLab, Terraform, CloudFormation, Falco, eBPF, Docker, Kubernetes, RHEL
Responsibilities
Designing and deploying detection logic across on-prem and cloud environments; writing custom detection signatures for cloud-native and host-level behavior; ingesting and normalizing AWS security logs into SIEM and data lakes; proactively hunting for malicious activity and adversary TTPs; partnering to develop automated remediation playbooks; conducting root-cause analysis on false positives/negatives; utilizing AI/ML to enhance query generation and threat intelligence correlation; developing DCO concepts of operations and TTPs; supporting vulnerability management mitigations.
Seniority
Senior, hands-on IC
