DoD TS Clearance SIEM Detection Engineer

MartinFed

Washington (District of Columbia)

On-site

USD 110,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

MartinFed is seeking an SIEM Detection Engineer to develop, tune, and maintain Splunk-based detections for government-focused security operations. You will own correlation searches, alerts, and use cases aligned to MITRE ATT&CK, leveraging threat intelligence to minimize noise while maximizing coverage.

The role collaborates with security analysts, threat intel teams, and platform engineers to ensure precise detection, validated content, and actionable dashboards for SOC triage and investigation

Qualifications

  • Detection development in SPL: correlation searches, scheduled searches, alerts, and thresholds.
  • Security use case design mapped to MITRE ATT&CK.
  • Alert tuning and false-positive reduction while maintaining coverage.
  • Threat intelligence application and IOC/behavioral detection logic.
  • Dashboard and visualization development for SOC triage and investigation.
  • Detection testing and validation against known attack techniques and sample data.
  • Working knowledge of Splunk Enterprise Security (ES): notable events, risk-based alerting (RBA), and data models.
  • Understanding of the incident response lifecycle and SOC workflows.
  • Familiarity with adversary tactics, techniques, and common attack patterns across endpoint, network, and cloud.

Responsibilities

  • Detection Development: Develop and optimize search queries, correlation searches, and SPL alerts.
  • Use Case Development: Design security use cases mapped to MITRE ATT&CK and drive by threat intel.
  • Alert Tuning: Reduce false positives while preserving coverage and relevance.
  • Dashboards & Visualization: Build dashboards for SOC triage and investigation.
  • Threat Detection Support: Monitor events and provide detection context for incident response.
  • Detection Testing & Validation: Test detections with known techniques and document outcomes.
  • Collaboration & Documentation: Coordinate with analysts and threat intel; maintain runbooks and docs.

Skills

Detection SPL development
MITRE ATT&CK mapping
Alert tuning
Threat intelligence
SOC dashboards
Detections testing
Splunk ES basics
IR lifecycle knowledge
Threat patterns across tech

Job description

MartinFed is seeking an SIEM Detection Engineer to develop, tune, and maintain Splunk-based detections for government-focused security operations. You will own correlation searches, alerts, and use cases aligned to MITRE ATT&CK, leveraging threat intelligence to minimize noise while maximizing coverage.

The role collaborates with security analysts, threat intel teams, and platform engineers to ensure precise detection, validated content, and actionable dashboards for SOC triage and investigation

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DoD TS Cleared SIEM Detection Engineer (Splunk)
DoD TS Cleared SIEM Detection Engineer (Splunk)

MartinFederal Consulting, LLC • Washington

On-site
USD 110,000 - 180,000
SIEM Detection Engineer (DoD TS Clearance)
SIEM Detection Engineer (DoD TS Clearance)

MartinFederal Consulting, LLC • Washington

On-site
USD 110,000 - 180,000
SIEM Detection Engineer (DoD TS Clearance)
SIEM Detection Engineer (DoD TS Clearance)

MartinFed • Washington

On-site
USD 110,000 - 160,000
Junior Software Engineer - Splunk & SIEM (TS Clearance)
Junior Software Engineer - Splunk & SIEM (TS Clearance)

MartinFederal Consulting, LLC • Starkville (MS)

On-site
USD 60,000 - 80,000
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
SIEM/Detection Engineer
SIEM/Detection Engineer

Mantis Security Corporation • Reston (VA)

On-site
USD 140,000 - 190,000
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
Confidential
SITEC - Cyber Threat Detection Engineer - MacDill AFB
SITEC - Cyber Threat Detection Engineer - MacDill AFB

Peraton • Tampa (FL)

On-site
USD 110,000 - 170,000
Senior Splunk Engineer — SIEM Dashboards & Threat Detection
Senior Splunk Engineer — SIEM Dashboards & Threat Detection

Chenega Agile Real Time Solutions, LLC • Oakton (VA)

On-site
USD 145,000 - 215,000