Detection Engineer – Threat Hunter

ECS

Arlington (VA)

Hybrid

USD 170,000 - 190,000

Full time

33 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

ECS Federal LLC is seeking a Detection Engineer / Threat Hunter in Arlington, VA (Hybrid) to proactively identify and mitigate advanced cyber threats. The role combines threat hunting, detection engineering, and security analytics to improve proactive defense across enterprise environments.

Responsibilities include developing detection content for SIEM/EDR/Cloud, leveraging MITRE ATT&CK, and supporting incident response with actionable insights and persistent improvements across security

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field.
  • 7+ years of cybersecurity experience with Threat Hunting, Detection Engineering, SOC, or Incident Response.
  • Strong understanding of attacker TTPs and threat frameworks (MITRE ATT&CK).

Responsibilities

  • Conduct proactive threat hunting to identify malicious activity across networks, endpoints, cloud, and apps.
  • Design, test, and maintain detection content for SIEM, EDR/XDR, NDR, and cloud platforms.
  • Develop Sigma rules, YARA signatures, SIEM queries, and detection playbooks.
  • Tune detections and define true-positive criteria to reduce noise.
  • Analyze large security telemetry and correlate threat intelligence with internal data.
  • Support Incident Response and post-incident detection enhancements.

Skills

Threat hunting
Detection engineering
Security analytics
Incident response
MITRE ATT&CK knowledge

Education

Bachelor's degree in Cybersecurity/CS/IT or related field

Tools

SIEM platforms
Threat intelligence tools

Job description

Detection Engineer - Threat Hunter

Location: Arlington, VA (Hybrid)

We are seeking a highly motivated Detection Engineer / Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise environment. This role combines threat hunting, detection engineering, and security analytics to improve the organization's ability to identify malicious activity before it results in business impact.

Key Responsibilities
Threat Hunting
  • Conduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications.
  • Leverage threat intelligence, behavioral analytics, and emerging threat research to develop hunting hypotheses.
  • Investigate anomalous events and indicators that may represent compromise or active threats and translate findings into formal hunt/detection guidance.
  • Document threat hunting methodologies, findings, and recommendations.
Detection Engineering
  • Design, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms.
  • Create and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations.
  • Develop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks.
  • Continuously improve detection coverage using MITRE ATT&CK and industry threat frameworks.
  • Define and validate true-positive criteria and effectively tunes/retires weak detections.
Security Analytics
  • Analyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications.
  • Correlate threat intelligence with internal security data to identify emerging threats.
  • Perform root cause analysis and provide actionable recommendations to improve detection effectiveness.
  • Develop metrics and dashboards that measure detection coverage and security monitoring effectiveness.
Incident Response Support
  • Partner with Incident Response and SOC teams during active investigations.
  • Provide advanced threat analysis and forensic context during security incidents.
  • Assist with containment, eradication, and recovery efforts when necessary.
  • Create post-incident detection enhancements to prevent adversary re-entry.
Threat Intelligence Integration
  • Consume and operationalize threat intelligence from commercial, government, open-source, and internal sources.
  • Map intelligence findings to security controls and detection opportunities.
  • Identify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs).
  • Collaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.
Continuous Improvement
  • Assess existing detections for effectiveness and false-positive reduction opportunities.
  • Conduct adversary emulation and purple team exercises to validate detection capabilities.
  • Identify visibility gaps and recommend additional logging, telemetry, and monitoring controls.
  • Stay current on emerging cyber threats, attacker methodologies, and detection technologies.

Salary Range: $170,000 - $190,000

General Description Of Benefits

Required Skills

  • Top Secret Clearance
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.
  • 7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with SIEM platforms and security analytics tools.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry.
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages.
  • Strong critical-thinking, investigative, and problem-solving skills.
Desired Skills
  • Experience in enterprise SOC, Managed Detection & Response (MDR), or Cyber Defense operations.
  • Knowledge of cloud security monitoring within Azure, AWS, or Google Cloud.
  • Experience conducting proactive threat hunts against advanced adversaries.
  • Familiarity with adversary emulation and purple team exercises.
  • Understanding of malware analysis, digital forensics, and cyber threat intelligence.
  • Experience supporting zero-trust and cloud-native security initiatives.

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven

Meet the challenge. Make a difference with Everforth ECS!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Incident Response Lead
Incident Response Lead

ECS • Washington

Hybrid
USD 140,000 - 150,000
Senior Cyber Threat Intelligence (CTI) Analyst
Senior Cyber Threat Intelligence (CTI) Analyst

ECS • Arlington (VA)

Hybrid
USD 160,000 - 180,000
Mid Cyber Threat Intelligence (CTI) Analyst
Mid Cyber Threat Intelligence (CTI) Analyst

ECS • Arlington (VA)

Hybrid
USD 140,000 - 160,000
Senior Security Engineer
Senior Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000
Enterprise Vulnerability Assessment Program- AI Focused
Enterprise Vulnerability Assessment Program- AI Focused

ECS • Washington

On-site
USD 160,000 - 205,000
Cyber Threat Intelligence (CTI) SME (Team Lead)
Cyber Threat Intelligence (CTI) SME (Team Lead)

ECS • Arlington (VA)

Hybrid
USD 165,000 - 185,000
SIEM Engineer - Mid
SIEM Engineer - Mid

ECS • Washington

On-site
USD 108,000 - 125,000
Detection Engineer - Threat Hunter with Security Clearance - ECS
Detection Engineer - Threat Hunter with Security Clearance - ECS

OpenTalent • West Virginia

Hybrid
USD 100,000 - 130,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

ECS • Virginia (MN)

On-site
USD 130,000 - 160,000