Cloud Detection Engineer — IDS/IPS & Cloud Logs

BreakPoint Labs LLC

Charleston, Northern (SC, KY)

Hybrid

USD 120,000 - 150,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BreakPoint Labs LLC seeks a Detection Engineer to design, develop, and implement advanced detection capabilities within a CSSP environment. You will focus on IDS/IPS signatures, log correlation rules, and detection tools across multi-cloud environments.

You will analyze threat intel to tailor detection mechanisms, validate rules to minimize false positives, and collaborate with DCO Watch Analysts to integrate detections into monitoring and incident response workflows.

Qualifications

  • 5+ years in a Cloud CSSP, SOC, or similar environment.
  • 2+ years in signature development and detection logic on multiple platforms.
  • Experience with major cloud provider security models, services and logs.
  • Experience with threat intelligence platforms and indicator management.

Responsibilities

  • Act as the primary SME for cloud log sources, designing efficient detections across multi-cloud environments.
  • Designing and implementing detection logic (KQL, EQL, and SPL) for cloud threats and infrastructure.
  • Analyzing threat intelligence to tailor detections to customer environments.
  • Validating detection rules to minimize false positives and enhance threat identification.
  • Collaborating with DCO Watch Analysts to integrate detections into monitoring workflows.

Skills

IDS/IPS
Threat detection
Splunk
Elastic
KQL/EQL/SPL
Cloud security
Indicator lifecycle
SOP documentation
Communication
Problem solving

Education

Bachelor’s Degree

Tools

Splunk
Elastic

Job description

BreakPoint Labs LLC seeks a Detection Engineer to design, develop, and implement advanced detection capabilities within a CSSP environment. You will focus on IDS/IPS signatures, log correlation rules, and detection tools across multi-cloud environments.

You will analyze threat intel to tailor detection mechanisms, validate rules to minimize false positives, and collaborate with DCO Watch Analysts to integrate detections into monitoring and incident response workflows.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer (Cloud)
Detection Engineer (Cloud)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Elastic Threat Detection Engineer - CSSP & DoD Security
Elastic Threat Detection Engineer - CSSP & DoD Security

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Detection Engineer, Cloud Security & IR
Detection Engineer, Cloud Security & IR

Intermedia Lab • San Francisco (CA)

On-site
USD 230,000 - 260,000
Competitive cash compensation
Equity
Full benefits
Cloud Security Detection Engineer – IR & Threat Hunting
Cloud Security Detection Engineer – IR & Threat Hunting

IBM • Lowell (MA)

On-site
USD 140,000 - 190,000
Senior SIEM/SOAR Engineer (Elastic & Splunk)
Senior SIEM/SOAR Engineer (Elastic & Splunk)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 90,000 - 130,000
Staff Cloud Detection & Response Security Engineer
Staff Cloud Detection & Response Security Engineer

Australian Competition and Consumer Commission • Pittsburgh

Hybrid
USD 171,000 - 273,000
Staff Cloud Detection & Response Engineer
Staff Cloud Detection & Response Engineer

AURORA • Pittsburgh

Hybrid
USD 171,000 - 273,000
Annual bonus
Equity compensation
Benefits
Cybersecurity Analyst
Cybersecurity Analyst

BreakPoint Labs LLC • Fort Belvoir (VA), Northern (KY)

Hybrid
USD 90,000 - 130,000
Staff Cloud Detection & Response Engineer
Staff Cloud Detection & Response Engineer

Aurora • Mountain View (CA)

Hybrid
USD 189,000 - 303,000
Hybrid work model
Bonus and equity
Benefits package