Senior Detection Engineer & SIEM SME

Softthink Solutions

Washington (District of Columbia)

On-site

USD 150,000 - 210,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Softthink Solutions in Washington, DC seeks a Detection Engineering SME to lead the creation of detection content for our security operations. You will author up to 3,500 single-event rules and 200 multi-event correlations, ensuring our threat detections remain modern and effective against current adversary techniques.

You will deploy detections, validate performance, and tune thresholds while integrating threat intelligence sources. Prior experience with cloud-native SIEMs is required.

Qualifications

  • 7+ years of experience in detection engineering, threat hunting, or cyber analytics.
  • Experience authoring SIEM rules and correlation logic.
  • Experience with MITRE ATT&CK, threat intelligence, and adversary emulation.
  • Experience with cloud-native SIEM platforms.

Responsibilities

  • Author detection rules for Google SecOps SIEM.
  • Deploy curated detections and validate rule performance.
  • Build multi-event correlation rules aligned to MITRE ATT&CK.
  • Tune detections to meet false-positive thresholds.
  • Integrate threat intelligence sources into detection logic.
  • Support UEBA risk scoring and insider-threat detection.
  • Provide expert guidance during Detect & Tune and Operationalize phases.

Skills

Detection engineering
SIEM rule authoring
MITRE ATTCK framework
Cloud-native SIEM platforms

Education

Bachelor's degree in Cybersecurity/CS

Job description

Softthink Solutions in Washington, DC seeks a Detection Engineering SME to lead the creation of detection content for our security operations. You will author up to 3,500 single-event rules and 200 multi-event correlations, ensuring our threat detections remain modern and effective against current adversary techniques.

You will deploy detections, validate performance, and tune thresholds while integrating threat intelligence sources. Prior experience with cloud-native SIEMs is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineering SME: SIEM Rules & Threat Detection Lead
Detection Engineering SME: SIEM Rules & Threat Detection Lead

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions • Washington

On-site
USD 150,000 - 210,000
Remote SIEM Detection Engineer: Build Detection Excellence
Remote SIEM Detection Engineer: Build Detection Excellence

Mosaec • Northern (KY)

Hybrid
USD 112,000 - 162,000
Unlimited PTO
Work location flexibility
Parental leave (up to 24 weeks)
Senior SIEM & Detection Engineering Lead
Senior SIEM & Detection Engineering Lead

K2United, LLC. • Washington

On-site
USD 150,000 - 190,000
Senior Splunk SIEM & Threat Detection Engineer
Senior Splunk SIEM & Threat Detection Engineer

Mantis Security Corporation • Reston (VA)

On-site
USD 140,000 - 190,000
Cloud SecOps SIEM/SOAR Engineer
Cloud SecOps SIEM/SOAR Engineer

Softthink Solutions • Washington

On-site
USD 180,000 - 240,000
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site
Remote SIEM Engineer: Detection & Content Architect
Remote SIEM Engineer: Detection & Content Architect

Relha LLC • Washington, Northern (KY)

Hybrid
USD 89,000 - 163,000
Senior SIEM & Detection Engineer (Hybrid)
Senior SIEM & Detection Engineer (Hybrid)

Corebridge Financial • Houston (TX)

Hybrid
USD 168,000 - 195,000
Health insurance
401(k) with company match
Paid time off
+1