Jobs · Engineering · Maryland

Detection Engineer

Edgewater Federal Solutions, Inc. · Bethesda, MD · 3 wk ago
Engineering$120k–$140k/yrFull-time

About the Role

Join a Cyber Security Operations organization supporting a leading federal healthcare client as a Splunk User and Entity Behavior (UBA) Engineer. This role involves maintaining and operating the Splunk application monitoring tool within the Threat Monitoring and Incident Response (TMIR) team.

Responsibilities

  • Maintain and operate Splunk as part of the client’s Cybersecurity network and application audit and monitoring program.
  • Apply strategic, operational, and tactical cyber intelligence to enhance security operations.
  • Lead and/or support efforts to prepare for, monitor, detect, analyze/confirm, contain, remediate, and recover from security incidents.
  • Develop and implement actionable alerts and workflows for Splunk as a CISO monitoring tool.
  • Develop and implement Splunk Apps and Knowledge Objects (KO), such as dashboards, reports, and data models.
  • Provide analyst training and workshops on using Splunk.
  • Develop and implement automation and efficiencies within Splunk.
  • Communicate with customer stakeholders, including leadership, support teams, and system administrators.
  • Conduct deep analysis and hunting operations.
  • Configure incident response and remediation workflows for Enterprise Security (ES).
  • Perform TMIR technical writing and create formal documentation, such as reports, training materials, and architecture diagrams.
  • Develop and build excellent relationships with prospects, clients, and internal team members.
  • Co-lead client calls and communications, including developing presentations, status reports, and requirements documents.
  • Take direction to achieve quality results while independently striving for personal excellence in task completion.

Requirements

  • U.S. Citizenship is required to obtain and maintain a U.S. security clearance.
  • At least 5 years of Splunk and SIEM experience.
  • At least 3 years of experience in trend spotting, identifying intelligence knowledge gaps, and analyzing threat data.
  • At least 3 years of endpoint/host forensics experience.
  • Strong understanding of adversary TTPs, network, and host security.
  • High technical ability/aptitude, demonstrated through prior technical experience and accomplishment.
  • One or more certifications in information security (e.g., GCIA, GCIH, CEH, CISSP, SSCP, Sec+).
  • Excellent verbal, written, and interpersonal skills, with a command of the English language.
  • Strong written and verbal communication skills to effectively engage at all levels in government and industry.
  • Exceptionally self-motivated, directed, and detail-oriented.
  • Ability to learn, understand, and apply new technologies.
  • Excellent organizational, analytical, and problem-solving abilities.
  • Working knowledge of Microsoft Office (Outlook, Word, Excel, PowerPoint, Project, and SharePoint).
  • Experience in a rapid-paced, time-sensitive, high-quality environment.
  • History of ethical performance.
  • Exhibit client delivery, business development, and proposal development experience.
  • Strong management, teamwork, and interpersonal skills, especially under tight deadlines.
  • Strong customer service focus to meet internal and external customer needs.
  • Professional, pleasant, and polished demeanor.
  • Ability to work collaboratively with others.
  • Ability to maintain confidentiality of sensitive information within and external to Edgewater, using sound judgment.
  • Strong attention to detail.

Desired Qualifications

  • Ten or more years of cybersecurity work experience in Threat Hunting, Splunk Content Development, and Incident Response.
  • Active Public Trust clearance.
  • Experience and effective participation in hunt, computer network defense, real-time analysis, and incident response activities, including reconstructing events from network, endpoint, and log data.
  • Experience and understanding of host-based/endpoint protection systems.

Pay

$120,000 - $140,000

About Us

Edgewater Federal Solutions is a privately held government contracting firm located in Frederick, MD. Founded in 2002, the company is recognized for supporting customer missions through employee empowerment, exceptional services, and timely delivery. Edgewater is ISO 9001, 20000-1, and 27001 certified, appraised at CMMI Level 3 Maturity for Development and Services, and has been named in the Top Workplaces in the Greater Washington Area Small Companies since 2018.

Similar jobs

Detection Engineer

NelnetUnited States· 2 mo ago
RemoteEngineering$100k–$110k/yrapply on nelnet.wd1.myworkdayjobs.com

Detection Engineer

Electronic Arts (EA)Orlando, FL· 1 mo ago
Engineeringapply on jobs.ea.com

Detection Engineer

Tempus AIChicago, IL· 1 mo ago
Engineering$100k–$140k/yrapply on tempus.wd5.myworkdayjobs.com

Detection Engineer

Accenture Federal ServicesArlington, VA· 2 mo ago
Information Technology$91k–$221k/yrapply on boards.greenhouse.io