Lead Detection Engineer — Splunk ES & Threat Hunting (Remote)

K&A Technologies LLC

Washington

Hybrid

USD 165,000 - 190,000

Full time

18 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

K&A Technologies LLC is seeking an experienced Detection Engineering Lead to drive enterprise cybersecurity detections using Splunk ES and advanced analytics. You will lead hypothesis-driven threat hunts, develop SPL queries, and map findings to MITRE ATT&CK, while guiding SOPs and operational deliverables.

The role emphasizes leadership across detection engineering, threat hunting, and documentation, with a focus on reducing alert noise and improving detection fidelity in a large enterprise

Qualifications

  • Minimum 5 years of Incident Response experience within a large SOC environment supporting more than 5,000 endpoints.
  • At least 3 years of experience focused on proactive detection engineering, threat hunting, or adversary emulation.
  • At least 3 years developing investigative hypotheses, querying large datasets, and identifying sophisticated or APT-related behavior.
  • At least 2 years hands-on experience developing detections within a SIEM, with strong preference for Splunk Enterprise Security.
  • Strong proficiency developing and optimizing Splunk SPL searches and security detections.
  • At least 2 years of demonstrated experience using Python and PowerShell to develop security tools, scripts, or automation.
  • Demonstrated ability to develop SOPs, work instructions, playbooks, and technical documentation.
  • Strong understanding of threat hunting methodologies, attacker TTPs, incident response, security telemetry, and MITRE ATT&CK.
  • Excellent verbal and written communication skills.

Responsibilities

  • Lead the development, testing, tuning, deployment, and lifecycle management of security detections within Splunk Enterprise Security (ES).
  • Develop advanced SPL queries, correlation searches, and security analytics using enterprise-scale telemetry.
  • Conduct hypothesis-driven threat hunts across endpoints, network, authentication, identity, cloud, and other data sources.
  • Identify suspicious activity related to APTs and emerging attacker behaviors.
  • Translate threat intel, incident findings, and attacker techniques into detection logic.
  • Map detections to MITRE ATT&CK and identify gaps in coverage.
  • Tune detections to improve fidelity and reduce false positives, providing actionable context.
  • Develop scripts and automation using Python and PowerShell.
  • Create and maintain SOPs, playbooks, and technical procedures for detection engineering.
  • Ensure documentation reflects operational processes and evolving program requirements.
  • Support completion of contractual or program deliverables for detection engineering.
  • Collaborate with SOC analysts, incident responders, threat intel, and security engineers to strengthen detection capabilities.
  • Provide technical leadership and mentorship in detection engineering and threat hunting.

Skills

Splunk ES
SPL queries
Threat hunting
MITRE ATT&CK
Python
PowerShell
Documentation
Incident response
Communication

Tools

KQL

Job description

K&A Technologies LLC is seeking an experienced Detection Engineering Lead to drive enterprise cybersecurity detections using Splunk ES and advanced analytics. You will lead hypothesis-driven threat hunts, develop SPL queries, and map findings to MITRE ATT&CK, while guiding SOPs and operational deliverables.

The role emphasizes leadership across detection engineering, threat hunting, and documentation, with a focus on reducing alert noise and improving detection fidelity in a large enterprise

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineer Lead
Detection Engineer Lead

K&A Technologies LLC • Washington

Hybrid
USD 165,000 - 190,000
Lead Cybersecurity Engineer – Splunk & Threat Hunting
Lead Cybersecurity Engineer – Splunk & Threat Hunting

SSV Technologies Inc. • Richmond (VA)

On-site
USD 120,000 - 180,000
Telemetry Engineer
Telemetry Engineer

Openkyber • Alaska

On-site
USD 130,000 - 180,000
Remote Detection Engineer: Splunk & Threat Hunting
Remote Detection Engineer: Splunk & Threat Hunting

Blu Omega LLC • Rockville (MD)

Remote
USD 70,000 - 90,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Staff Detection Engineering Lead - Remote/Hybrid
Staff Detection Engineering Lead - Remote/Hybrid

LinkedIn • United States

Hybrid
USD 156,000 - 255,000
Threat Intelligence & Detection Engineer — Splunk
Threat Intelligence & Detection Engineer — Splunk

SECU • United States

On-site
USD 120,000 - 180,000
Lead Detection & Incident Response Engineer
Lead Detection & Incident Response Engineer

Mundi • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Equity
Remote Splunk Threat Detection Engineer
Remote Splunk Threat Detection Engineer

Openkyber • Alaska

On-site
USD 130,000 - 180,000