Detection Engineering Lead — Hybrid DC (Public Trust)

cFocus Software Incorporated

Washington (District of Columbia)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

cFocus Software Incorporated in Washington, DC is seeking a Detection Engineering Lead to join the AOUSC program. The role is hybrid, with onsite work in Washington, DC and requires a Public Trust clearance.

You will lead detection engineering operations, develop SIEM detections, coordinate with SOC teams, and drive analytics across judiciary systems to improve threat visibility and reduce analyst burden.

Qualifications

  • Active Public Trust clearance.
  • B.S. Computer Science, Information Technology, or a related field.
  • 5+ years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on proactive detection engineering, threat hunt, or adversary emulation.
  • 3+ years of experience with demonstrated proficiency in forming hypothesis, querying large datasets and identifying APT behavior.
  • 2+ years’ experience with demonstrated proficiency in scripting languages including Python and PowerShell to develop new tools.
  • 2+ years’ experience with demonstrated proficiency developing detections in a SIEM (utilizing Splunk ES or Microsoft Sentinel).
  • Active OSCP or GXPN certification

Responsibilities

  • Lead Detection Engineering operations supporting AOUSC Security Operations Division (SOD) mission objectives and defensive cybersecurity operations.
  • Provide full lifecycle support for cybersecurity detection engineering activities, including research, testing, implementation, tuning, deployment, and maintenance of detection capabilities.
  • Research emerging cyber threats, adversary capabilities, attack methodologies, and TTPs to improve detection coverage and SOC visibility.
  • Develop, test, validate, and deploy new SIEM detection signatures, analytics, rules, and workflows to enhance threat detection capabilities and minimize analyst burden.
  • Maintain and manage the Risk Based Alerting (RBA) framework within the Judiciary SIEM environment to ensure effective detection of risky or malicious activity.
  • Coordinate weekly meetings with SOC analysts and stakeholders to review alert performance, analyst feedback, false positives, and detection tuning requirements.
  • Analyze all false positive alerts to determine necessary tuning, whitelisting, suppression logic, and gaps in security monitoring or analytics.
  • Develop and maintain detailed documentation for all detection engineering changes, configuration updates, rule logic, workflows, and implementation procedures.
  • Coordinate with Threat Hunting, Cyber Threat Intelligence (CTI), Cybersecurity Triage, Incident Response, and Blue Team personnel to operationalize intelligence-driven detections.
  • Develop new alerts and detections in response to emerging cybersecurity threats, active vulnerabilities, malicious campaigns, and government-directed priorities.
  • Ensure critical vulnerability-related detections are deployed within required service level timelines, including 24-hour implementation for critical severity alerts.
  • Conduct analysis and validation of new alerts from security devices and external telemetry sources to determine operational impact, detection value, and analyst workflow considerations.
  • Track all detection engineering changes, modifications, additions, and removals through Jira stories and established Agile workflows.
  • Develop weekly operational reports summarizing security events, alert dispositions, workforce metrics, tuning activities, detection improvements, and outstanding issues.
  • Document and maintain all detection framework changes within configuration files, knowledge management portals, and operational repositories.
  • Support development and implementation of detection engineering execution plans aligned to AOUSC operational priorities, organizational risks, and emerging threat vectors.
  • Provide recommendations for improving telemetry collection, log visibility, event correlation, and security monitoring effectiveness across Judiciary systems and cloud environments.
  • Collaborate with Blue Team personnel to improve detection coverage associated with Red Team findings, adversary emulation, and cyber exercises.
  • Prepare and deliver technical briefings, operational status reports, executive summaries, and stakeholder presentations.
  • Support transition-in, transition-out, operational readiness, and knowledge transfer activities in accordance with AOUSC requirements.

Skills

Proactive detection engineering
Threat hunting
Adversary emulation
Hypothesis formation
Python scripting
PowerShell scripting

Education

B.S. Computer Science/Information Technology or related field

Tools

Python
PowerShell
Splunk ES
Microsoft Sentinel

Job description

cFocus Software Incorporated in Washington, DC is seeking a Detection Engineering Lead to join the AOUSC program. The role is hybrid, with onsite work in Washington, DC and requires a Public Trust clearance.

You will lead detection engineering operations, develop SIEM detections, coordinate with SOC teams, and drive analytics across judiciary systems to improve threat visibility and reduce analyst burden.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AOUSC - Detection Engineering Lead
AOUSC - Detection Engineering Lead

cFocus Software Incorporated • Washington

Hybrid
USD 130,000 - 170,000
Hybrid DC Digital Forensics Analyst (Public Trust)
Hybrid DC Digital Forensics Analyst (Public Trust)

cFocus Software Incorporated • Washington

Hybrid
USD 90,000 - 120,000
Threat Hunt Lead - Proactive Cyber Defense & APT Analysis
Threat Hunt Lead - Proactive Cyber Defense & APT Analysis

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 170,000
Hybrid Cybersecurity Shift Lead — DC (Public Trust)
Hybrid Cybersecurity Shift Lead — DC (Public Trust)

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 150,000
Detection Engineering Manager - Security Lead (Hybrid NYC)
Detection Engineering Manager - Security Lead (Hybrid NYC)

United States Digital Space LLC • New York (NY)

Hybrid
USD 175,000 - 215,000
Medical, dental, and vision coverage
Equity for all employees
Day-one 401(k) match
+2
Hybrid Federal SOC Manager – Public Trust Clearance
Hybrid Federal SOC Manager – Public Trust Clearance

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 190,000
Hybrid Insider Threat Analyst - Public Trust Clearance
Hybrid Insider Threat Analyst - Public Trust Clearance

cFocus Software Incorporated • Washington

Hybrid
USD 80,000 - 100,000
AOUSC - Cybersecurity Shift Lead
AOUSC - Cybersecurity Shift Lead

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 150,000
AOUSC - Threat Hunt Lead
AOUSC - Threat Hunt Lead

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 170,000
Public Trust CTI Analyst — Threat Intel & Data Insights (Hybrid DC)
Public Trust CTI Analyst — Threat Intel & Data Insights (Hybrid DC)

cFocus Software Incorporated • Washington

Hybrid
USD 90,000 - 120,000