Cyber Threat Detection Engineer (SIEM / Signatures)

RISA

St. Louis (MO)

On-site

USD 78,000 - 86,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Rolston Information Systems Assurance (RISA) in St. Louis, MO, is seeking a Cyber Threat Detection Engineer (SIEM/Signatures) on-site. You will craft and tune detection logic, analyze incidents, and run Purple Team exercises to outpace adversaries.

Active TS/SCI clearance and the ability to obtain a polygraph are required. Required is a Bachelor's degree with 6+ years of relevant experience (or equivalent), DoD 8140/8570-M IAT III/CSSP Analyst certification, and strong data-mining, regex, and

Qualifications

  • U.S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Bachelor's degree in a field applicable to the position plus 6 years of relevant experience; equivalents accepted - Master's +4, Associate +8, or High School diploma/GED +10.
  • 8+ years of related advanced cyber security analytics experience.
  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
  • Data mining or query building in a SIEM.
  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
  • Static file signatures (magic numbers) and good working knowledge of regular expressions.

Responsibilities

  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
  • Turn intelligence and incident reporting into deployed detection logic.
  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.
  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.

Skills

SIEM data mining
Signature development
Regex patterns
Network protocol analysis
Scripting (Python/Bash/PowerShell)
DoD 8140/8570-M IAT III CSSP Analyst

Education

Bachelor's degree + 6 years experience; Master’s +4; Associate +8; HS diploma + 10

Tools

Protocol analyzers
SIEM tooling

Job description

Cyber Threat Detection Engineer (SIEM / Signatures)


Location: St. Louis, MO - on site


Time Type: Full time, Exempt


Clearance Required to Start: Active TS/SCI (U.S. citizenship required)


Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)


Travel: None


Salary Range: $78,000 – $86,000


Adversaries are already inside somebody's enterprise. Make sure it isn't this one.


RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.


What You Will Do


  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.

  • Turn intelligence and incident reporting into deployed detection logic.

  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.

  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.

  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.

  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.


What You'll Bring


  • U.S. citizenship and an active TS/SCI.

  • Ability to successfully obtain and maintain a Government polygraph after hire.

  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.

  • 8+ years of related advanced cyber security analytics experience.

  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.

  • Data mining or query building in a SIEM.

  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.

  • Static file signatures (magic numbers) and good working knowledge of regular expressions.


Nice to Have


  • Hex editor comfort; Python, Bash, or PowerShell scripting.

  • Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.


About RISA

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.


Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.


RISA is an Equal Opportunity Employer.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Cyber Threat Detection Engineer III - SIEM Signatures
Cyber Threat Detection Engineer III - SIEM Signatures

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Threat Detection Engineer — SIEM Signatures (TS/SCI, Onsite)
Threat Detection Engineer — SIEM Signatures (TS/SCI, Onsite)

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Advanced Cyber Security Analytics Engineer with Security Clearance
Advanced Cyber Security Analytics Engineer with Security Clearance

D2 Consulting • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Cybersecurity Operations Specialist -SIEM Services (Evergreen)
Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics Corporation • Springfield (VA)

On-site
USD 128,000 - 173,000
Cross Domain Systems Engineer III
Cross Domain Systems Engineer III

RISA • St. Louis (MO)

On-site
USD 101,000 - 111,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Cross Domain Solutions Engineer (CDS)
Cross Domain Solutions Engineer (CDS)

RISA • St. Louis (MO)

On-site
USD 101,000 - 111,000
Medical Insurance
Dental Insurance
Vision Insurance
+1
Advanced Cyber Security Analytics Engineer
Advanced Cyber Security Analytics Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Advanced Cyber Security Analytics Engineer
Advanced Cyber Security Analytics Engineer

D2 Technical Services • St. Louis (MO)

On-site
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Cyber Data Analyst Engineer III
Cyber Data Analyst Engineer III

RISA • St. Louis (MO)

On-site
USD 101,000 - 111,000
Medical insurance
Dental insurance
Vision insurance
+3