Cloud Detection Engineer – Signatures & SIEM Expert

BreakPoint Labs, LLC

South Carolina

On-site

USD 110,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

BreakPoint Labs is seeking a Detection Engineer to design and implement advanced detection capabilities in a CSSP environment. You will focus on IDS/IPS signatures, log correlation rules, and cloud-native detections across Gov.

Cloud, AWS, Azure, and GCP. Responsibilities include crafting detection logic with KQL/EQL/SPL, testing to reduce false positives, and collaborating with DCO Watch Analysts to integrate detections into incident response.

Qualifications

  • Requires 5+ years in CSSP/SOC or similar environment.
  • 2+ years in signature development and detection logic on multiple platforms.
  • Experience with cloud provider security models, logs, and governance.

Responsibilities

  • Design, develop, and implement detection capabilities across multi-cloud environments.
  • Create and manage IDS/IPS signatures and log correlation rules.
  • Analyze threat intelligence to tailor detections to customer environments.
  • Validate detection rules to minimize false positives and enhance threat detection.
  • Collaborate with DCO Watch Analysts to integrate detections into monitoring workflows.
  • Maintain and update detection tools while ensuring CJCSM 6510.01B compliance.
  • Produce SOP documentation for detection creation processes.
  • Perform log analysis in Splunk and Elastic to support detection development.
  • Coordinate with reporting agencies and subscriber sites on detection strategies.
  • Participate in program reviews and tool evaluations; assist with surge actions as needed.

Skills

CSSP/SOC experience
Signature development
Cloud security
Splunk/Elastic signatures
Threat intelligence
Indicator lifecycle
DoD 8570 IAT II
DoD CSSP certifications

Education

Bachelor’s Degree
CSSP/SOC experience (8+ years)

Tools

Splunk
Elastic

Job description

BreakPoint Labs is seeking a Detection Engineer to design and implement advanced detection capabilities in a CSSP environment. You will focus on IDS/IPS signatures, log correlation rules, and cloud-native detections across Gov.

Cloud, AWS, Azure, and GCP. Responsibilities include crafting detection logic with KQL/EQL/SPL, testing to reduce false positives, and collaborating with DCO Watch Analysts to integrate detections into incident response.

Get your free, confidential resume review.

or drag and drop your file here.