Elastic Threat Detection Engineer - CSSP & DoD Security

BreakPoint Labs LLC

Charleston, Northern (SC, KY)

Hybrid

USD 110,000 - 140,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BreakPoint Labs LLC is seeking a Detection Engineer specializing in Elastic to design and implement detection mechanisms for cyber threats within a CSSP environment. You will develop IDS/IPS signatures, log correlation rules, and detection tools guided by the MITRE ATT&CK framework and indicator lifecycle.

The role requires 5+ years in CSSP/SOC and hands-on Elastic Stack expertise. DoD 8570 IAT II and CSSP certifications are expected, with DoD Secret Clearance as a potential requirement.

Qualifications

  • 5+ years in a CSSP, SOC or similar environment.
  • 2+ years developing and optimizing detection signatures across platforms.
  • Hands-on experience with Elastic Stack, KQL/EQL and Elastic Defend.
  • Experience with threat intelligence platforms and indicator management.
  • Expertise in IDS/IPS signature development and optimization.
  • Strong understanding of the indicator lifecycle.
  • Certifications: Elastic Certified Analyst/SIEM/Engineer; DoD 8570 IAT II; DoD 8140 CSSP-specific.

Responsibilities

  • Develop, implement, and maintain high-fidelity detection rules in Elastic for MITRE ATT&CK mapped adversary TTPs.
  • Prioritize risk-based alerting aligned with risk assessments.
  • Analyze threat intelligence to tailor detections to customer environments.
  • Test rules to minimize false positives and improve detection accuracy.
  • Collaborate with DCO Watch Analysts to integrate detections into monitoring workflows.
  • Maintain detection tooling and SOP documentation; ensure compliance with directives.
  • Coordinate with reporting agencies and sites on detection strategies.
  • Support program reviews and certification evaluations; possible surge work; up to 10% travel.

Skills

Threat detection
Threat hunting
Problem solving
Communication
Independent work

Education

Bachelor's degree in a relevant discipline
CSSP/SOC experience (8+ years)

Tools

Elastic Stack
Kibana/KQL
EQL
ES|QL
Elastic Defend
IDS/IPS concepts

Job description

BreakPoint Labs LLC is seeking a Detection Engineer specializing in Elastic to design and implement detection mechanisms for cyber threats within a CSSP environment. You will develop IDS/IPS signatures, log correlation rules, and detection tools guided by the MITRE ATT&CK framework and indicator lifecycle.

The role requires 5+ years in CSSP/SOC and hands-on Elastic Stack expertise. DoD 8570 IAT II and CSSP certifications are expected, with DoD Secret Clearance as a potential requirement.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Analyst (Elastic)
Detection Analyst (Elastic)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Detection Engineer (Cloud)
Detection Engineer (Cloud)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Cloud Detection Engineer — IDS/IPS & Cloud Logs
Cloud Detection Engineer — IDS/IPS & Cloud Logs

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Senior SIEM/SOAR Engineer (Elastic & Splunk)
Senior SIEM/SOAR Engineer (Elastic & Splunk)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 90,000 - 130,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

Valiant Solutions • South Carolina

On-site
USD 80,000 - 110,000
Elastic Detection Analyst - Secret Clearance (Onsite)
Elastic Detection Analyst - Secret Clearance (Onsite)

Valiant Solutions • South Carolina

On-site
USD 80,000 - 110,000
SIEM/SOAR Engineer
SIEM/SOAR Engineer

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 90,000 - 130,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Cybersecurity Detection Engineer — SIEM & Threat Analytics
Cybersecurity Detection Engineer — SIEM & Threat Analytics

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000