Detection Engineer - Threat Hunter

ECS Corporate Services

Arlington (VA)

Hybrid

USD 170,000 - 190,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Top Secret Clearance

Job summary

Everforth ECS in Arlington, VA (Hybrid) seeks a Detection Engineer - Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise. The role blends threat hunting, detection engineering, and security analytics to improve proactive defense across endpoints, networks, and cloud.

Collaboration with SOC, IR, and threat intel teams is essential to mature detection capabilities.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.
  • 7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with SIEM platforms and security analytics tools.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry.
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages.

Responsibilities

  • Threat Hunting: Conduct proactive hunting across enterprise networks, endpoints, cloud, and applications.
  • Detection Engineering: Design, test, and maintain detection content across SIEM, EDR/XDR, and cloud platforms.
  • Security Analytics: Analyze large telemetry sets and develop detection metrics and dashboards.
  • Incident Response Support: Assist with investigations and post-incident detection improvements.
  • Threat Intelligence Integration: Map intelligence to controls and detection opportunities.
  • Continuous Improvement: Assess detections for gaps and reduce false positives.

Skills

Threat Hunting
Detection Engineering
Security Operations
Incident Response
MITRE ATT&CK
TTPs
Scripting
Python
PowerShell
KQL

Education

Bachelor's degree in cybersecurity or related field

Tools

SIEM platforms
EDR/XDR
Sigma rules
YARA signatures
Threat Intelligence platforms
Cloud security tools
KQL

Job description

Everforth ECS is seeking a Detection Engineer - Threat Hunter to join our team in Arlington, VA (Hybrid). This position is contingent upon award. We are seeking a highly motivated Detection Engineer / Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise environment. This role combines threat hunting, detection engineering, and security analytics to improve the organization’s ability to identify malicious activity before it results in business impact. The ideal candidate will have experience working within Security Operations Centers (SOC), Incident Response, Detection Engineering, or Threat Hunting teams and possess strong analytical skills, knowledge of adversary tactics and techniques, and expertise in developing high-fidelity security detections.

Key Responsibilities
  • Threat Hunting
    Conduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications. Leverage threat intelligence, behavioral analytics, and emerging threat research to develop hunting hypotheses. Investigate anomalous events and indicators that may represent compromise or active threats and translate findings into formal hunt/detection guidance. Document threat hunting methodologies, findings, and recommendations.
  • Detection Engineering
    Design, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms. Create and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations. Develop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks. Continuously improve detection coverage using MITRE ATT&CK and industry threat frameworks. Define and validate true-positive criteria and effectively tunes/retires weak detections.
  • Security Analytics
    Analyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications. Correlate threat intelligence with internal security data to identify emerging threats. Perform root cause analysis and provide actionable recommendations to improve detection effectiveness. Develop metrics and dashboards that measure detection coverage and security monitoring effectiveness.
  • Incident Response Support
    Partner with Incident Response and SOC teams during active investigations. Provide advanced threat analysis and forensic context during security incidents. Assist with containment, eradication, and recovery efforts when necessary. Create post-incident detection enhancements to prevent adversary re-entry.
  • Threat Intelligence Integration
    Consume and operationalize threat intelligence from commercial, government, open-source, and internal sources. Map intelligence findings to security controls and detection opportunities. Identify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs). Collaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.
  • Continuous Improvement
    Assess existing detections for effectiveness and false-positive reduction opportunities. Conduct adversary emulation and purple team exercises to validate detection capabilities. Identify visibility gaps and recommend additional logging, telemetry, and monitoring controls. Stay current on emerging cyber threats, attacker methodologies, and detection technologies.

Salary Range: $170,000 - $190,000

General Description of Benefits
  • Top Secret Clearance
Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.
  • 7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with SIEM platforms and security analytics tools.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry.
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages.
  • Strong critical-thinking, investigative, and problem-solving skills.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

ECS • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Senior Threat Hunter & Detection Engineer (Hybrid)
Senior Threat Hunter & Detection Engineer (Hybrid)

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Senior Threat Hunter & Detection Engineer (Hybrid)
Senior Threat Hunter & Detection Engineer (Hybrid)

ECS Corporate Services • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Top Secret Clearance
Detection Engineer - Threat Hunter with Security Clearance - ECS
Detection Engineer - Threat Hunter with Security Clearance - ECS

OpenTalent • West Virginia

Hybrid
USD 100,000 - 130,000
Senior Cyber Threat Intelligence (CTI) Analyst
Senior Cyber Threat Intelligence (CTI) Analyst

ECS Corporate Services • Arlington (VA)

Hybrid
USD 160,000 - 180,000
Top Secret Clearance
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Mid Cyber Threat Intelligence (CTI) Analyst
Mid Cyber Threat Intelligence (CTI) Analyst

Socket.dev • Arlington (VA)

Hybrid
USD 140,000 - 160,000
Hybrid work arrangement
Detection Engineering Lead - MANTECH
Detection Engineering Lead - MANTECH

OpenTalent • McLean (VA)

On-site
USD 120,000 - 160,000