Detection Engineering SME

Softthink Solutions

Washington (District of Columbia)

On-site

USD 150,000 - 210,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Softthink Solutions in Washington, DC seeks a Detection Engineering SME to lead the creation of detection content for our security operations. You will author up to 3,500 single-event rules and 200 multi-event correlations, ensuring our threat detections remain modern and effective against current adversary techniques.

You will deploy detections, validate performance, and tune thresholds while integrating threat intelligence sources. Prior experience with cloud-native SIEMs is required.

Qualifications

  • 7+ years of experience in detection engineering, threat hunting, or cyber analytics.
  • Experience authoring SIEM rules and correlation logic.
  • Experience with MITRE ATT&CK, threat intelligence, and adversary emulation.
  • Experience with cloud-native SIEM platforms.

Responsibilities

  • Author detection rules for Google SecOps SIEM.
  • Deploy curated detections and validate rule performance.
  • Build multi-event correlation rules aligned to MITRE ATT&CK.
  • Tune detections to meet false-positive thresholds.
  • Integrate threat intelligence sources into detection logic.
  • Support UEBA risk scoring and insider-threat detection.
  • Provide expert guidance during Detect & Tune and Operationalize phases.

Skills

Detection engineering
SIEM rule authoring
MITRE ATTCK framework
Cloud-native SIEM platforms

Education

Bachelor's degree in Cybersecurity/CS

Job description

Detection Engineering SME

Location: Washington, DC

Work Authorization: US Citizen

Role Summary

The Detection Engineering SME leads the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules. This role ensures SBA’s threat detection posture is modern, comprehensive, and aligned with current adversary techniques.

Roles & Responsibilities
  • Author detection rules for Google SecOps SIEM.
  • Deploy curated detections and validate rule performance.
  • Build multi-event correlation rules aligned to MITRE ATT&CK.
  • Tune detections to meet false-positive thresholds.
  • Integrate threat intelligence sources into detection logic.
  • Support UEBA risk scoring and insider-threat detection.
  • Provide expert guidance during Detect & Tune and Operationalize phases.
Professional Experience Required
  • 7+ years of experience in detection engineering, threat hunting, or cyber analytics.
  • Experience authoring SIEM rules and correlation logic.
  • Experience with MITRE ATT&CK, threat intelligence, and adversary emulation.
  • Experience with cloud-native SIEM platforms.
Educational Qualification
  • Bachelor’s degree in Cybersecurity, Computer Science, or related field.
Certifications
  • GIAC Detection Engineering (GCTI, GDAT), CISSP, or equivalent preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineering SME
Detection Engineering SME

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Detection Engineering SME: SIEM Rules & Threat Detection Lead
Detection Engineering SME: SIEM Rules & Threat Detection Lead

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Senior Detection Engineer & SIEM SME
Senior Detection Engineer & SIEM SME

Softthink Solutions • Washington

On-site
USD 150,000 - 210,000
Security Operations Engineer - Level 3
Security Operations Engineer - Level 3

Veriipro • Blue Ash (OH)

On-site
USD 105,000 - 145,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Cyber Security Engineer – Threat Detection (1401)
Cyber Security Engineer – Threat Detection (1401)

Sharp Decisions • Charlotte (NC)

Hybrid
USD 105,000 - 145,000
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Detection and platform engineer
Detection and platform engineer

Tixy Services LLC • Town of Texas (WI), Fort Worth (TX)

Hybrid
USD 120,000 - 180,000
AOUSC - Detection Engineering Lead
AOUSC - Detection Engineering Lead

cFocus Software Incorporated • Washington

Hybrid
USD 130,000 - 170,000