Cyber Threat Detection Engineer (SIEM/Signatures)

RISA

St. Louis (MO)

On-site

USD 78,000 - 86,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
11 paid Federal Holidays

Job summary

RISA, located in St. Louis, MO, is seeking an experienced Cyber Threat Detection Engineer to develop and tune SIEM rules, signatures, and scripts.

You will participate in a Fusion model with Defensive Cyber Operations, focusing on hunt and detection engineering rather than queue-clearing. You will analyze trends, convert intelligence into deployed logic, and run Purple Team exercises while supporting the Cyber Incident Response Team during live activity.

Qualifications

  • U.S. citizenship and an active TS/SCI clearance
  • Ability to obtain and maintain a Government polygraph after hire
  • Bachelor's degree in a field relevant to the position plus 6 years of experience (equivalents accepted)
  • 8+ years of advanced cyber security analytics experience
  • DoD 8140.01 / 8570.01-M IAT III and CSSP Analyst certification
  • Data mining or query building in a SIEM
  • Strong signature development, tuning and network protocol analysis
  • Good knowledge of regular expressions

Responsibilities

  • Analyze trends to identify and predict events, then develop or tune rules, signatures, and scripts
  • Convert intelligence and incident reports into deployed detection logic
  • Run regular Purple Team exercises and validate countermeasures
  • Collaborate with Cyber Data Analytics on SIEM alert efficiency
  • Support the Incident Response Team during live activity and assist triage
  • Document work in the ticketing system for traceability

Skills

U.S. citizenship
Active TS/SCI clearance
DoD 8140/8570 IAT III / CSSP Analyst
SIEM data mining / query building
Signature development & tuning
Regex / protocol analysis

Education

Bachelor's degree + 6 years experience
Master's + 4 years

Tools

Python
Bash
PowerShell

Job description

Cyber Threat Detection Engineer (SIEM / Signature Development)
Cyber Security Operations Specialist III - Advanced Cyber Analytics

Location: St. Louis, MO - on site

Time Type: Full time, Exempt

Clearance Required to Start: Active TS/SCI (U.S. citizenship required)

Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)

Travel: None

Salary Range: $78,000 – $86,000

Adversaries are already inside somebody's enterprise. Make sure it isn't this one.

RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.

What You Will Do
  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
  • Turn intelligence and incident reporting into deployed detection logic.
  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.
  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.
What You'll Bring
  • S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
  • 8+ years of related advanced cyber security analytics experience.
  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
  • Data mining or query building in a SIEM.
  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
  • Static file signatures (magic numbers) and good working knowledge of regular expressions.
Nice to Have
  • Hex editor comfort; Python, Bash, or PowerShell scripting.
  • Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.
About RISA

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.

Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.

RISA is an Equal Opportunity Employer.

  • Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Cyber Implementation Engineer III
Cyber Implementation Engineer III

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
+1
Cybersecurity Implementation Engineer (EDR, NDR, AWS)
Cybersecurity Implementation Engineer (EDR, NDR, AWS)

RISA • Springfield (VA)

On-site
USD 117,000 - 128,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Cyber Threat Detection Engineer III - SIEM Signatures
Cyber Threat Detection Engineer III - SIEM Signatures

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
On-Site Cyber Threat Detection Engineer (SIEM/Signatures)
On-Site Cyber Threat Detection Engineer (SIEM/Signatures)

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
+1
CSOC Tier 3 Analyst III
CSOC Tier 3 Analyst III

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Cyber Incident Responder / Malware Analyst (CSOC)
Cyber Incident Responder / Malware Analyst (CSOC)

RISA • Springfield (VA)

On-site
USD 87,000 - 95,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Endpoint Security Engineer III
Endpoint Security Engineer III

RISA • St. Louis (MO)

On-site
USD 101,000 - 111,000
Medical, dental, and vision insurance
401(k) and Roth; Paid Time Off
11 paid Federal Holidays
+1
Endpoint Security Engineer (Trellix/HBSS, Tanium)
Endpoint Security Engineer (Trellix/HBSS, Tanium)

RISA • St. Louis (MO)

On-site
USD 101,000 - 111,000
Medical, dental, and vision insurance
401(k) and Roth
Paid Time Off
+1
Cybersecurity Operations Specialist -SIEM Services (Evergreen)
Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics Corporation • Springfield (VA)

On-site
USD 128,000 - 173,000