Cyber Security Engineer

Career Listings

Columbus (OH)

On-site

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SarelaTech is seeking a Cybersecurity Engineer to support the DLA CSSP program, focusing on enterprise cybersecurity detection capabilities and SIEM content development.

The role involves designing advanced threat detection use cases, automating security processes, and enhancing monitoring across government environments, with collaboration across government stakeholders and cyber operations teams.

Qualifications

  • Active DoD Top Secret clearance with SCI eligibility and IT-I access.
  • Bachelor's degree or equivalent experience in a related field.
  • Minimum five years of IT experience; minimum three with a SIEM in content development, threat detection, or IR.
  • Experience developing SIEM correlation rules, threat detection content, or analytics using SPL and KQL.

Responsibilities

  • Research, develop, and implement new cybersecurity threat detection use cases based on threats and threat intel.
  • Design, develop, and maintain SIEM correlation rules, analytics, dashboards, and detection content.
  • Develop automation scripts using PowerShell or Python to enhance SIEM functionality.
  • Analyze log sources and data quality to improve visibility and event collection.
  • Collaborate with government stakeholders and ops teams to identify critical systems and monitoring needs.
  • Evaluate architectures and telemetry to identify deficiencies and improve detection capabilities.
  • Support MITRE ATT&CK-aligned methodologies and Defense-in-Depth practices.
  • Prepare technical documentation and engineering recommendations for tool enhancements.

Skills

Strong written and verbal comms
SIEM content development
Threat detection engineering
PowerShell scripting
Python scripting
SPL
KQL
Enterprise network architecture
Log analysis

Education

Bachelor's degree in Cybersecurity/IT/CS/CE or related field
DoD 8570 IAT Level II certification
DoD CSSP certification (CSSP-IR/CSSP-A)
GIAC certifications (optional)

Tools

Splunk Enterprise Security

Job description

Benefits
  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Profit sharing
  • Training & development
  • Tuition assistance
  • Vision insurance

SarelaTech is seeking a Cybersecurity Engineer to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide technical expertise in the development, implementation, and enhancement of enterprise cybersecurity detection capabilities by designing advanced threat detection use cases, developing SIEM content, and improving cybersecurity monitoring and analytics across government enterprise environments.

Working closely with cybersecurity operations personnel, Threat Detection Analysts, system administrators, cybersecurity tool SMEs, and government stakeholders, the Cybersecurity Engineer will develop detection logic, automate security processes, enhance SIEM functionality, and improve enterprise visibility into emerging cyber threats while supporting the confidentiality, integrity, availability, and resilience of DLA information systems.

Primary Responsibilities
  • Research, develop, and implement new cybersecurity threat detection use cases based on emerging threats, threat intelligence, and Threat Detection Analyst recommendations.
  • Design, develop, and maintain SIEM correlation rules, analytics, dashboards, and detection content to improve enterprise threat detection and monitoring capabilities.
  • Develop and maintain automation scripts using PowerShell, Python or similar scripting languages to enhance SIEM functionality and streamline cybersecurity operations.
  • Analyze log sources and data quality to identify gaps in visibility, improve event collection, and optimize enterprise cybersecurity monitoring.
  • Collaborate with government stakeholders, cybersecurity tool SMEs, and operational teams to identify critical systems, prioritize monitoring requirements, and develop tailored detection signatures.
  • Evaluate cybersecurity architectures, network traffic, and security telemetry to identify deficiencies in detection capabilities and recommend improvements.
  • Support continuous improvement of cybersecurity monitoring capabilities by implementing detection methodologies aligned with the MITRE ATT&CK framework and Defense-in-Depth principles.
  • Prepare technical documentation, implementation guides, operational procedures, and engineering recommendations supporting cybersecurity tool enhancements.
Required Qualifications
  • Active DoD Top Secret security clearance with SCI eligibility and IT-I access.
  • Bachelor\'s degree in Cybersecurity, Information Technology, Computer Science, Computer Engineering, or related discipline, or equivalent experience.
  • Minimum five (5) years of relevant Information Technology experience.
  • Minimum three (3) years of experience working with a SIEM in a content development, threat detection, or Incident Response role.
  • Minimum three (3) years of experience as a System Administrator and/or Network Administrator.
  • Experience developing SIEM correlation rules, threat detection content, or cybersecurity analytics using SPL and KQL query languages.
  • Strong understanding of enterprise network architecture, cybersecurity monitoring, and log analysis.
  • Experience developing automation scripts using PowerShell, Python or similar scripting languages.
  • Strong written and verbal communication skills
Desired Qualifications
  • Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD cybersecurity organizations.
  • Experience supporting Security Operations Center (SOC), Cyber Security Service Provider (CSSP), or Incident Response operations.
  • Experience working with Splunk Enterprise Security or other enterprise SIEM platforms.
  • Knowledge of the MITRE ATT&CK framework, Cyber Kill Chain, NIST SP 800-53, NIST SP 800-61, and DISA STIGs.
  • Experience integrating threat intelligence into SIEM detection content.
  • Experience developing custom detection signatures, dashboards, automation workflows, or security analytics.
  • Experience evaluating enterprise log sources, telemetry quality, and security monitoring effectiveness.
Certifications
  • DoD 8570 IAT Level II certification (Security+, CySA+, SSCP, GSEC, CCNA, GICSP, or equivalent).
  • DoD 8570 CSSP certification meeting CSSP-IR or CSSP-A requirements.
Preferred
  • Splunk Core Certified Power User
  • Splunk Enterprise Security Certified Administrator
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Enterprise Defender (GCED)
  • Certified Ethical Hacker (CEH)
Preferred Skills
  • SIEM engineering and content development
  • Threat detection engineering
  • Security analytics
  • Threat intelligence integration
  • MITRE ATT&CK framework
  • Incident Response
  • Splunk Enterprise Security
  • Log management and normalization
  • PowerShell, Python, SPL scripting
  • Enterprise network architecture
  • Cybersecurity automation
  • Technical documentation and engineering design
  • NIST and DoD cybersecurity standards
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Computer Network Defense Analyst
Computer Network Defense Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
Cybersecurity Detection Engineer — SIEM & Threat Analytics
Cybersecurity Detection Engineer — SIEM & Threat Analytics

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Sarela Technology Solutions • Columbus (OH)

On-site
USD 100,000 - 150,000
401(k)
401(k) matching
Dental insurance
+6
Cybersecurity Policy Analyst
Cybersecurity Policy Analyst

Career Listings • Columbus (OH)

On-site
USD 90,000 - 130,000
401(k)
401(k) matching
Dental insurance
+6
Computer Network Defense Analyst
Computer Network Defense Analyst

Sarela Technology Solutions • Columbus (OH)

On-site
USD 90,000 - 130,000
401(k)
401(k) matching
Dental insurance
+6
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Engineer
Cybersecurity Engineer

Akaasa Technologies • Richmond (VA)

On-site
USD 120,000 - 150,000