Detection Engineer

Blu Omega LLC

Rockville (MD)

Remote

USD 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Blu Omega LLC is seeking a Detection Engineer for a fully remote role supporting a federal program focused on protecting critical health systems and data. The position involves cybersecurity monitoring, detection engineering, and collaboration with a mission-driven team.

The role requires experience in security operations, detecting threats, and implementing detections within Splunk. NIH Public Trust clearance is noted as a requirement, with opportunities to influence threat detection across the

Qualifications

  • 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering.
  • Experience working with Splunk or a comparable SIEM platform.
  • Familiarity with SPL and security-focused searches or queries.
  • Understanding of common cybersecurity threats and attacker techniques.
  • Experience reviewing or investigating cybersecurity alerts.
  • Strong analytical, troubleshooting, and communication skills.

Responsibilities

  • Develop and maintain security alerts and detection rules within Splunk.
  • Write and modify SPL queries to identify suspicious or potentially malicious activity.
  • Create and maintain Splunk dashboards, reports, and security analytics.
  • Review and tune existing detections to improve accuracy and reduce false positives.
  • Support phishing detection and analysis using Cofense Triage or similar tools.
  • Assist with the development and maintenance of YARA rules.
  • Use SnapAttack and other security tools to support detection development and analysis.
  • Leverage built-in security analytics and detections across cybersecurity tools.
  • Support threat hunting and investigation of suspicious activity.
  • Apply MITRE ATT&CK concepts to understand attacker behaviors and detection coverage.
  • Work with SOC analysts, incident responders, and other cybersecurity team members to improve monitoring and detection capabilities.
  • Document detection rules, queries, dashboards, and investigative procedures.

Skills

Analytical skills
Troubleshooting
Communication skills

Tools

Splunk
SPL
Cofense Triage
YARA
SnapAttack
MITRE ATT&CK

Job description

Back Detection Engineer
Cloud/Infrastructure Rockville , Maryland Sep 3, 2026

Detection Engineer
Remote

Blu Omega is seeking a Detection Engineer to support a federal program focused on the protection of critical health systems and data. This role operates within a fully remote environment and is responsible for cybersecurity monitoring and detection activities. The position requires experience supporting security operations and detection engineering within a mission-driven environment.

Program Overview

NIH Cybersecurity Operations Center; protection of critical federal health systems/data; 24/7 enterprise cybersecurity operations

Key Details

Location: Remote
Clearance: NIH Public Trust; must be able to obtain and maintain

Responsibilities
  • Develop and maintain security alerts and detection rules within Splunk
  • Write and modify SPL queries to identify suspicious or potentially malicious activity
  • Create and maintain Splunk dashboards, reports, and security analytics
  • Review and tune existing detections to improve accuracy and reduce false positives
  • Support phishing detection and analysis using Cofense Triage or similar tools
  • Assist with the development and maintenance of YARA rules
  • Use SnapAttack and other security tools to support detection development and analysis
  • Leverage built-in security analytics and detections across cybersecurity tools
  • Support threat hunting and investigation of suspicious activity
  • Apply MITRE ATT&CK concepts to understand attacker behaviors and detection coverage
  • Work with SOC analysts, incident responders, and other cybersecurity team members to improve monitoring and detection capabilities
  • Document detection rules, queries, dashboards, and investigative procedures
Required Qualifications
  • 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
  • Experience working with Splunk or a comparable SIEM platform
  • Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
  • Understanding of common cybersecurity threats and attacker techniques
  • Experience reviewing or investigating cybersecurity alerts
  • Strong analytical, troubleshooting, and communication skills
Preferred Qualifications
  • Experience developing or tuning security detections in Splunk
  • Familiarity with YARA rules
  • Experience with Cofense Triage or phishing analysis
  • Familiarity with SnapAttack
  • Knowledge of MITRE ATT&CK
  • Experience with threat hunting, endpoint security, or incident response
  • Federal cybersecurity experience
  • Security certification such as Security+, CySA+, CEH, or similar
Salary Range

$70,000.00 - $90,000.00

#CJ

#LI-Remote

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Detection Engineer: Splunk & Threat Hunting
Remote Detection Engineer: Splunk & Threat Hunting

Blu Omega LLC • Rockville (MD)

Remote
USD 70,000 - 90,000
Remote Detection Engineer — Security Cleared
Remote Detection Engineer — Security Cleared

OpenTalent • Derwood (MD)

On-site
USD 120,000 - 150,000
Remote Detection Engineer: SIEM & Threat Hunting
Remote Detection Engineer: SIEM & Threat Hunting

OpenTalent • Rockville (MD)

On-site
USD 70,000 - 90,000
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Detection Engineer (Cloud)
Detection Engineer (Cloud)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Detection Engineer - Threat Hunter
Detection Engineer - Threat Hunter

ECS Corporate Services • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Top Secret Clearance
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Darkwolfsolutions • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 150,000