Detection Engineering SME: SIEM Rules & Threat Detection Lead

Softthink Solutions Inc

Washington (District of Columbia)

On-site

USD 150,000 - 190,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Softthink Solutions Inc in Washington, DC is seeking a Detection Engineering SME to lead the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules, ensuring a modern threat posture.

You will author rules for Google SecOps SIEM, deploy detections, and build MITRE ATT&CK aligned correlations, while tuning rules to minimize false positives and integrating threat intelligence.

Qualifications

  • 7+ years of experience in detection engineering, threat hunting, or cyber analytics.
  • Experience authoring SIEM rules and correlation logic.
  • Experience with MITRE ATT&CK, threat intelligence and adversary emulation.
  • Experience with cloud-native SIEM platforms.

Responsibilities

  • Author detection rules for Google SecOps SIEM.
  • Deploy curated detections and validate rule performance.
  • Build multi-event correlation rules aligned to MITRE ATT&CK.
  • Tune detections to meet false-positive thresholds.
  • Integrate threat intelligence sources into detection logic.
  • Support UEBA risk scoring and insider-threat detection.
  • Provide expert guidance during Detect & Tune and Operationalize phases.

Skills

Detection engineering
Threat hunting
SIEM rules
MITRE ATT&CK
Cloud-native SIEM
Threat intelligence
UEBA risk scoring

Education

Bachelor’s degree in Cybersecurity or Computer Science

Tools

Google SecOps SIEM
Cloud-native SIEM platforms
Threat intelligence sources

Job description

Softthink Solutions Inc in Washington, DC is seeking a Detection Engineering SME to lead the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules, ensuring a modern threat posture.

You will author rules for Google SecOps SIEM, deploy detections, and build MITRE ATT&CK aligned correlations, while tuning rules to minimize false positives and integrating threat intelligence.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection Engineer & SIEM SME
Senior Detection Engineer & SIEM SME

Softthink Solutions • Washington

On-site
USD 150,000 - 210,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions • Washington

On-site
USD 150,000 - 210,000
Remote SIEM Detection Engineer: Build Detection Excellence
Remote SIEM Detection Engineer: Build Detection Excellence

Mosaec • Northern (KY)

Hybrid
USD 112,000 - 162,000
Unlimited PTO
Work location flexibility
Parental leave (up to 24 weeks)
Senior Threat Intelligence & Detection Architect
Senior Threat Intelligence & Detection Architect

Jobtailor • Seattle (WA)

On-site
USD 110,000 - 160,000
Cloud SecOps SIEM/SOAR Engineer
Cloud SecOps SIEM/SOAR Engineer

Softthink Solutions • Washington

On-site
USD 180,000 - 240,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Detection Engineer: EDR/ITDR & MITRE Mapping
Detection Engineer: EDR/ITDR & MITRE Mapping

Threatlocker Inc • Orlando (FL)

On-site
USD 90,000 - 150,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Security Operations Engineer - Level 3
Security Operations Engineer - Level 3

Veriipro • Blue Ash (OH)

On-site
USD 105,000 - 145,000