Detection Engineer Cloud

BreakPoint Labs

Charleston (SC)

On-site

USD 100,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BreakPoint Labs is hiring a Detection Engineer in Charleston, SC. This role involves designing and implementing advanced detection tools within cybersecurity. Applicants should have at least 5 years of relevant experience, expertise in cloud security models, and knowledge of signature development in tools like Splunk and Elastic. Required certifications include DoD IAT Level II and a relevant bachelor's degree or equivalent experience. The position may require up to 10% travel and some overtime to support detection efforts.

Qualifications

  • 5+ years of experience in CSSP, SOC, or similar environment.
  • 2+ years of experience with signature development and detection logic.
  • Preferred certifications: AWS Certified Security, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer.

Responsibilities

  • Design and manage detection capabilities for cloud environments.
  • Collaborate with teams to integrate detection mechanisms into workflows.
  • Update detection tools and maintain SOP documentation.

Skills

Expertise in IDS/IPS solutions
Effective communication skills
Independent problem-solving ability
Technical expertise in major cloud provider security models
Experience with signature development
Knowledge of threat intelligence

Education

Bachelor’s Degree in relevant discipline
8 years of experience in relevant environments

Tools

Splunk
Elastic

Job description

Job Description

BreakPoint Labs is seeking a Detection Engineer to be responsible for the design, development, and implementation of advanced detection capabilities within a Cybersecurity Service Provider (CSSP) environment. The candidate will focus on creating and managing IDS/IPS signatures, log correlation rules, and other detection tools based on indicator lifecycle analysis. The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other teams to ensure timely and effective threat detection, adhering to CJCSM 6510.01B reporting requirements and supporting the CSSP’s mission to protect data across a wide spectrum of sources and locations.

Responsibilities include:

  • Acting as the primary SME for cloud log sources, designing efficient detections across multi-cloud environments (Gov. Cloud, AWS, Azure, GCP, etc).
  • Designing and implementing detection logic (KQL, EQL, and/or SPL) tailored to cloud-native threats and cloud infrastructure (e.g., containers like Kubernetes, Docker, etc.).
  • Analyzing threat intelligence to create and refine detection mechanisms tailored to the customer’s environment.
  • Validating and testing detection rules to ensure accuracy, minimize false positive and benign positive matches, and enhance threat identification capabilities.
  • Collaboration with DCO Watch Analysts to integrate detection mechanisms into monitoring and incident response workflows.
  • Maintaining and updating detection tools and signatures in response to evolving threats, ensuring compliance with CJCSM 6510.01B and other applicable directives.
  • Compiling and maintaining standard operating procedure (SOP) documentation for detection creation and implementation processes.
  • Performing log analysis of Splunk and Elastic to support detection development and validation.
    • Coordinating with reporting agencies and subscriber sites to align detection strategies with operational needs and threat intelligence.
  • Participation in program reviews, product evaluations, and onsite certification evaluations to assess detection tool efficacy.
  • Overtime may be required to support detection implementation or incident response actions (Surge).
  • Up to 10% travel may be required

Required Experience:

  • 5+ years of experience working in a CSSP, SOC, or similar environment.
  • 2+ years of experience with signature development, detection logic creation, and optimization on multiple platforms.
  • Technical expertise in major cloud provider security models, services, and logs (Gov. Cloud, AWS, Azure, GCP, etc.).
  • Experience working with and developing signatures for Splunk and Elastic.
  • Experience with threat intelligence platforms and indicator management.
  • Proficient knowledge of detection creation and implementation processes.
  • Expertise in IDS/IPS solutions, including signature development and optimization.
  • Strong understanding of the indicator lifecycle, including initial discovery, development, operational maturity, and long-term sustainment.
  • Effective verbal and written communication skills.
  • Ability to solve complex problems independently.
  • Preferred certifications: AWS Certified Security, Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, or equivalent SANS GIAC certifications.

Certifications Required: DoD 8570 IAT Level II and DoD 8140 CSSP-specific certification.

Security Clearance Required: DoD Secret.

Education Required: Bachelor’s Degree in the Area(s) of relevant discipline and 5 year's experience. OR, at least 8 years of experience working in a CSSP, SOC, or similar environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Cloud Threat Detection
Security Engineer - Cloud Threat Detection

RoShay Services • Hartford (CT)

Hybrid
USD 140,000 - 210,000
Detection Engineer III
Detection Engineer III

OU Health • Oklahoma City (OK)

On-site
USD 110,000 - 140,000
PTO
401(k)
Medical and dental plans
Security Engineer - Cloud Threat Detection
Security Engineer - Cloud Threat Detection

val's services • Charlotte (NC)

Hybrid
USD 120,000 - 150,000
Hybrid work arrangement
In-office three days/week
Detection & Mitigation Engineer
Detection & Mitigation Engineer

United States Digital Space LLC • United States

Hybrid
USD 110,000 - 170,000
Equity plan eligibility
Cloud Security Engineer
Cloud Security Engineer

MANTECH • Herndon (VA)

On-site
USD 120,000 - 170,000
Detection Engineer
Detection Engineer

Openkyber • Alaska

On-site
USD 120,000 - 160,000
Detection Engineer
Detection Engineer

Ampcus, Inc • Jacksonville (FL)

On-site
USD 90,000 - 130,000
Senior Cloud Security Analyst/Engineer
Senior Cloud Security Analyst/Engineer

CMA • United States

On-site
USD 90,000 - 130,000
Splunk Detection Engineer
Splunk Detection Engineer

DivIHN Integration Inc • United States

Remote
USD 100,000 - 130,000
Security Engineer, Detection & Response
Security Engineer, Detection & Response

Scale AI, Inc. • New York (NY)

On-site
USD 237,000 - 297,000
Comprehensive health coverage
Equity options
Paid time off
+2