Senior Threat Hunter & Detection Engineer (Hybrid)

Everforth ECS

Arlington (VA)

Hybrid

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Everforth ECS is seeking a Detection Engineer – Threat Hunter to join our Arlington, VA hybrid team. You will proactively hunt threats, design and tune detections, and collaborate with SOC and IR during incidents to strengthen security monitoring across endpoints, networks, and cloud environments.

The ideal candidate has 7+ years in cybersecurity, deep knowledge of TTPs, MITRE ATT&CK, and hands-on experience with SIEM platforms, Sigma rules, YARA, and automation using Python/PowerShell/KQL.

Qualifications

  • Bachelor's degree or equivalent experience in cybersecurity, CS, IT or related field.
  • 7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with SIEM platforms and security analytics tools.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry.
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages.

Responsibilities

  • Conduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications.
  • Design, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms.
  • Create and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations.
  • Develop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks.
  • Continuously improve detection coverage using MITRE ATT&CK and industry threat frameworks.
  • Define and validate true-positive criteria and effectively tunes/retires weak detections.
  • Analyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications.
  • Correlate threat intelligence with internal security data to identify emerging threats.
  • Perform root cause analysis and provide actionable recommendations to improve detection effectiveness.
  • Develop metrics and dashboards that measure detection coverage and security monitoring effectiveness.
  • Partner with Incident Response and SOC teams during active investigations.
  • Provide advanced threat analysis and forensic context during security incidents.
  • Assist with containment, eradication, and recovery efforts when necessary.
  • Create post-incident detection enhancements to prevent adversary re-entry.
  • Consume and operationalize threat intelligence from commercial, government, open-source, and internal sources.
  • Map intelligence findings to security controls and detection opportunities.
  • Identify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs).
  • Collaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.
  • Assess existing detections for effectiveness and false-positive reduction opportunities.
  • Conduct adversary emulation and purple team exercises to validate detection capabilities.
  • Identify visibility gaps and recommend additional logging, telemetry, and monitoring controls.
  • Stay current on emerging cyber threats, attacker methodologies, and detection technologies.

Skills

Threat Hunting
Detection Engineering
Security Analytics
MITRE ATT&CK
Cyber Kill Chain
SIEM platforms
Python
PowerShell
KQL
Threat intelligence

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience

Tools

Sigma rules
YARA signatures
SIEM queries
analytics rules
detection playbooks

Job description

Everforth ECS is seeking a Detection Engineer – Threat Hunter to join our Arlington, VA hybrid team. You will proactively hunt threats, design and tune detections, and collaborate with SOC and IR during incidents to strengthen security monitoring across endpoints, networks, and cloud environments.

The ideal candidate has 7+ years in cybersecurity, deep knowledge of TTPs, MITRE ATT&CK, and hands-on experience with SIEM platforms, Sigma rules, YARA, and automation using Python/PowerShell/KQL.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Hunter & Detection Engineer – Hybrid SIEM & Analytics
Threat Hunter & Detection Engineer – Hybrid SIEM & Analytics

ECS • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

Everforth ECS • Arlington (VA)

Hybrid
USD 120,000 - 170,000
Detection Engineer - Threat Hunter with Security Clearance - ECS
Detection Engineer - Threat Hunter with Security Clearance - ECS

OpenTalent • West Virginia

Hybrid
USD 100,000 - 130,000
Senior Threat Detection Engineer — Hybrid Role
Senior Threat Detection Engineer — Hybrid Role

3M HEALTHCARE • Scottsdale (AZ)

Hybrid
USD 132,000 - 165,000
Discretionary incentive plan
Benefits
Detection Engineer – Threat Hunter
Detection Engineer – Threat Hunter

ECS • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Threat Intelligence Analyst - Hybrid in Arlington
Threat Intelligence Analyst - Hybrid in Arlington

ECS • Arlington (VA)

Hybrid
USD 140,000 - 160,000
Senior Cyber Threat Intelligence Lead | Hybrid Arlington
Senior Cyber Threat Intelligence Lead | Hybrid Arlington

ECS • Arlington (VA)

Hybrid
USD 160,000 - 180,000
Senior Threat Hunter & Detection Engineer - Tier 3 (Onsite)
Senior Threat Hunter & Detection Engineer - Tier 3 (Onsite)

Evans & Chambers • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Threat Detection Engineer - Hybrid (Public Trust)
Threat Detection Engineer - Hybrid (Public Trust)

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 140,000
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 150,000