Washington, DC Metro Area | Primarily Remote
Occasional onsite support may be required
K&A Technologies LLC is seeking an experienced Detection Engineering Lead to support a large-scale enterprise cybersecurity program. This role will provide technical leadership across detection engineering, proactive threat hunting, advanced security analytics, and the development of operational documentation and contract deliverables supporting the detection function.
The ideal candidate will have strong hands‑on experience with Splunk Enterprise Security, advanced SPL development, detection lifecycle management, threat hunting, and identifying sophisticated adversary behavior across large datasets.
Success in this role means building high‑fidelity detections, continuously improving detection coverage, reducing unnecessary alert noise, identifying emerging attacker behavior, and ensuring the detection engineering function is supported by clear, repeatable processes, documentation, and required deliverables.
Responsibilities
- Lead the development, testing, tuning, deployment, and lifecycle management of security detections within Splunk Enterprise Security (ES).
- Develop advanced SPL queries, correlation searches, and security analytics using enterprise-scale security telemetry.
- Conduct hypothesis‑driven threat hunts across endpoint, network, authentication, identity, cloud, and other security data sources.
- Identify suspicious activity associated with advanced persistent threats, attacker behaviors, and emerging TTPs.
- Translate threat intelligence, incident findings, and adversary techniques into new or improved detection logic.
- Map detections and threat‑hunting activities to the MITRE ATT&CK framework and identify gaps in detection coverage.
- Tune existing detections to improve fidelity, reduce false positives, and provide analysts with actionable investigative context.
- Develop scripts, automation, enrichment tools, and supporting utilities using Python and PowerShell.
- Develop, maintain, and update Standard Operating Procedures (SOPs), work instructions, playbooks, technical procedures, process documentation, and other required detection engineering deliverables.
- Ensure detection engineering documentation accurately reflects operational processes, technical procedures, roles, responsibilities, and evolving program requirements.
- Support the preparation, review, and timely completion of recurring and ad hoc contractual or program deliverables assigned to the detection engineering team.
- Collaborate with SOC analysts, incident responders, threat intelligence personnel, and security engineers to strengthen enterprise detection capabilities.
- Provide technical leadership, mentorship, and guidance related to detection engineering and threat hunting.
Qualifications
- Minimum 5 years of Incident Response experience within a large SOC environment supporting more than 5,000 endpoints.
- At least 3 years of experience focused on proactive detection engineering, threat hunting, or adversary emulation.
- At least 3 years of demonstrated experience developing investigative hypotheses, querying large datasets, and identifying sophisticated or APT‑related behavior.
- At least 2 years of hands‑on experience developing detections within a SIEM, with strong preference for Splunk Enterprise Security.
- Strong proficiency developing and optimizing Splunk SPL searches and security detections.
- At least 2 years of demonstrated experience using Python and PowerShell to develop security tools, scripts, or automation.
- Demonstrated ability to develop clear SOPs, work instructions, playbooks, technical documentation, and operational deliverables.
- Strong understanding of threat hunting methodologies, attacker TTPs, incident response, security telemetry, and MITRE ATT&CK.
- Ability to independently analyze complex security activity and convert investigative findings into repeatable detection content and documented operational processes.
- Strong verbal and written communication skills.
Required Certification
Candidates must currently hold at least one of the following certifications:
- OSCP – Offensive Security Certified Professional
- GXPN – GIAC Exploit Researcher and Advanced Penetration Tester
Security Requirement
Candidates must be able to obtain and maintain a U.S. Federal Public Trust for the duration of the engagement.
Preferred Experience
- Splunk Enterprise Security administration or engineering.
- Splunk Risk‑Based Alerting (RBA), correlation searches, CIM, or data models.
- Microsoft Sentinel and KQL.
- Detection‑as‑code, Sigma, Git, or CI/CD workflows.
- Adversary emulation or purple‑team activities.
- Experience supporting large enterprise or federal cybersecurity environments.
- Experience developing documentation and formal deliverables in a government contracting or similarly structured environment.
Anticipated W‑2 Salary Range: $165,000–$190,000 annually, based on experience, technical depth, certification, and overall qualifications.
This position is contingent upon contract award.