On-Site Cyber Threat Detection Engineer (SIEM/Signatures)

RISA

St. Louis (MO)

On-site

USD 78,000 - 86,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
11 paid Federal Holidays

Job summary

RISA, located in St. Louis, MO, is seeking an experienced Cyber Threat Detection Engineer to develop and tune SIEM rules, signatures, and scripts.

You will participate in a Fusion model with Defensive Cyber Operations, focusing on hunt and detection engineering rather than queue-clearing. You will analyze trends, convert intelligence into deployed logic, and run Purple Team exercises while supporting the Cyber Incident Response Team during live activity.

Qualifications

  • U.S. citizenship and an active TS/SCI clearance
  • Ability to obtain and maintain a Government polygraph after hire
  • Bachelor's degree in a field relevant to the position plus 6 years of experience (equivalents accepted)
  • 8+ years of advanced cyber security analytics experience
  • DoD 8140.01 / 8570.01-M IAT III and CSSP Analyst certification
  • Data mining or query building in a SIEM
  • Strong signature development, tuning and network protocol analysis
  • Good knowledge of regular expressions

Responsibilities

  • Analyze trends to identify and predict events, then develop or tune rules, signatures, and scripts
  • Convert intelligence and incident reports into deployed detection logic
  • Run regular Purple Team exercises and validate countermeasures
  • Collaborate with Cyber Data Analytics on SIEM alert efficiency
  • Support the Incident Response Team during live activity and assist triage
  • Document work in the ticketing system for traceability

Skills

U.S. citizenship
Active TS/SCI clearance
DoD 8140/8570 IAT III / CSSP Analyst
SIEM data mining / query building
Signature development & tuning
Regex / protocol analysis

Education

Bachelor's degree + 6 years experience
Master's + 4 years

Tools

Python
Bash
PowerShell

Job description

RISA, located in St. Louis, MO, is seeking an experienced Cyber Threat Detection Engineer to develop and tune SIEM rules, signatures, and scripts.

You will participate in a Fusion model with Defensive Cyber Operations, focusing on hunt and detection engineering rather than queue-clearing. You will analyze trends, convert intelligence into deployed logic, and run Purple Team exercises while supporting the Cyber Incident Response Team during live activity.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Threat Detection Engineer III - SIEM Signatures
Cyber Threat Detection Engineer III - SIEM Signatures

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Cyber Threat Detection Engineer (SIEM/Signatures)
Cyber Threat Detection Engineer (SIEM/Signatures)

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical, dental, and vision insurance
401(k) and Roth IRA
Paid Time Off
+1
Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Splunk SIEM Threat Detection & Incident Response Engineer
Splunk SIEM Threat Detection & Incident Response Engineer

TALENT Software Services • Richmond (VA)

On-site
USD 90,000 - 130,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
Cyber Data Analytics Engineer — Flexible, Innovative Tech
Cyber Data Analytics Engineer — Flexible, Innovative Tech

Freedom Technology Solutions Group • St. Louis (MO)

On-site
USD 120,000 - 165,000
401k matching
Fully paid medical benefits
Tuition reimbursement
+1
TS/SCI SIEM Engineer | Threat Detection & Incident Response
TS/SCI SIEM Engineer | Threat Detection & Incident Response

Cymertek Corporation • Chantilly (VA)

On-site
USD 120,000 - 155,000
Excellent Salaries
Flexible schedule
401k Matching
+3
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000