Detection Analyst (Elastic)

BreakPoint Labs LLC

Charleston, Northern (SC, KY)

Hybrid

USD 110,000 - 140,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BreakPoint Labs LLC is seeking a Detection Engineer specializing in Elastic to design and implement detection mechanisms for cyber threats within a CSSP environment. You will develop IDS/IPS signatures, log correlation rules, and detection tools guided by the MITRE ATT&CK framework and indicator lifecycle.

The role requires 5+ years in CSSP/SOC and hands-on Elastic Stack expertise. DoD 8570 IAT II and CSSP certifications are expected, with DoD Secret Clearance as a potential requirement.

Qualifications

  • 5+ years in a CSSP, SOC or similar environment.
  • 2+ years developing and optimizing detection signatures across platforms.
  • Hands-on experience with Elastic Stack, KQL/EQL and Elastic Defend.
  • Experience with threat intelligence platforms and indicator management.
  • Expertise in IDS/IPS signature development and optimization.
  • Strong understanding of the indicator lifecycle.
  • Certifications: Elastic Certified Analyst/SIEM/Engineer; DoD 8570 IAT II; DoD 8140 CSSP-specific.

Responsibilities

  • Develop, implement, and maintain high-fidelity detection rules in Elastic for MITRE ATT&CK mapped adversary TTPs.
  • Prioritize risk-based alerting aligned with risk assessments.
  • Analyze threat intelligence to tailor detections to customer environments.
  • Test rules to minimize false positives and improve detection accuracy.
  • Collaborate with DCO Watch Analysts to integrate detections into monitoring workflows.
  • Maintain detection tooling and SOP documentation; ensure compliance with directives.
  • Coordinate with reporting agencies and sites on detection strategies.
  • Support program reviews and certification evaluations; possible surge work; up to 10% travel.

Skills

Threat detection
Threat hunting
Problem solving
Communication
Independent work

Education

Bachelor's degree in a relevant discipline
CSSP/SOC experience (8+ years)

Tools

Elastic Stack
Kibana/KQL
EQL
ES|QL
Elastic Defend
IDS/IPS concepts

Job description

BreakPoint Labs is seeking a Detection Engineer with an expertise in Elastic to design, develop, and implement detection mechanisms to identify cyber threats within a Cybersecurity Service Provider (CSSP) environment. The candidate will focus on creating and managing IDS/IPS signatures, log correlation rules, and other detection tools based on indicator lifecycle analysis. The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other teams to ensure timely and effective threat detection, adhering to CJCSM 6510.01B reporting requirements and supporting the CSSP’s mission to protect data across a wide spectrum of sources and locations.

Responsibilities include:
  • Develop, implement, and maintain custom, high-fidelity detection rules and logic in the Elastic Security platform specifically targeting adversary TTPs mapped to the MITRE ATT&CK® framework.
  • Develop and prioritize risk-based alerting mechanisms to focus detection efforts on high-impact threats, aligning with organizational risk assessments.
  • Analyze threat intelligence to create and refine detection mechanisms tailored to the customer’s environment.
  • Validate and test detection rules to ensure accuracy, minimize false positive and benign positive matches, and enhance threat identification capabilities.
  • Collaborate with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.
  • Maintain and update detection tools and signatures in response to evolving threats, ensuring compliance with CJCSM 6510.01B and other applicable directives.
  • Compile and maintain internal standard operating procedure (SOP) documentation for detection creation and implementation processes.
  • Coordinate with reporting agencies and subscriber sites to align detection strategies with operational needs and threat intelligence.
  • Participate in program reviews, product evaluations, and onsite certification evaluations to assess detection tool efficacy.
  • Overtime may be required to support detection implementation or incident response actions (Surge).
  • Up to 10% travel may be required.
Required Experience:
  • 5+ years of experience working in a CSSP, SOC, or similar environment.
  • 2+ years of experience with signature development, detection logic creation and optimization on multiple platforms.
  • Experience in threat detection engineering, threat hunting, or a related role with hands-on experience using the Elastic Stack, Kibana Query Language (KQL), Event Query Language (EQL), Elasticsearch Query Language (ES|QL) and/or Elastic Defend.
  • Experience with threat intelligence platforms and indicator management.
  • Proficient knowledge of detection creation and implementation processes.
  • Expertise in IDS/IPS solutions, including signature development and optimization.
  • Strong understanding of the indicator lifecycle, including initial discovery, development, operational maturity, and long-term sustainment.
  • Effective verbal and written communication skills.
  • Ability to solve complex problems independently.
  • Preferred certifications: Elastic Certified Analyst; Elastic Certified SIEM Analyst, Elastic Certified Engineer.

Certifications Required: DoD 8570 IAT Level II and DoD 8140 CSSP-specific certification.

Security Clearance Required: DoD Secret Clearance.

Education Required: Bachelor’s Degree Area(s) of Study of relevant discipline and 5 years of experience. OR, at least 8 years of experience working in a CSSP, SOC, or similar.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Elastic Threat Detection Engineer - CSSP & DoD Security
Elastic Threat Detection Engineer - CSSP & DoD Security

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Detection Engineer (Cloud)
Detection Engineer (Cloud)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

Valiant Solutions • South Carolina

On-site
USD 80,000 - 110,000
Detection Engineering Lead
Detection Engineering Lead

ManTech • McLean (VA)

On-site
USD 140,000 - 190,000
Sr Security Analyst
Sr Security Analyst

ECS • Shiloh (IL)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Senior Security Engineer – Elastic
Senior Security Engineer – Elastic

5ironCyber • Franklin (TN)

On-site
USD 110,000 - 140,000
Company-paid health, dental and vision insurance
Up to a 4% 401k company match
Generous paid time off
+3
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Darkwolfsolutions • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 100,000 - 160,000