Threat Detection Analyst — Splunk ES & MITRE Expert

Peraton

Beltsville (MD)

On-site

USD 80,000 - 128,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Peraton is seeking a Cyber Monitoring Signature Analyst to join the DSCM program, based in Rosslyn, VA with a secondary site in Beltsville, MD. The role focuses on building and enhancing threat detection in a Splunk-based SIEM environment, collaborating with senior engineers and threat analysts to protect a global IT infrastructure.

The position requires hands-on SPL development, familiarity with Splunk ES, MITRE ATT&CK framework, and EDR tooling.

Qualifications

  • Minimum 5 years of relevant experience with a Bachelor's degree, or 3 years with a Masters.

Responsibilities

  • Author, tune, and maintain correlation searches, Risk Notables, and Adaptive Response actions in Splunk Cloud Enterprise Security.
  • Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM.
  • Author new correlational searches in SPL/SPL2 using best practice search methodologies.
  • Maintain a living MITRE ATT&CK coverage matrix and identify gaps with SME.
  • Ensure cohesion and health of SIEM alerting.
  • Collaborate with system engineers on tool development, configuration, and tuning.
  • Operationalize threat intelligence for actionable IOC detections.
  • Provide reporting on detection development metrics.

Skills

SPL searches
Splunk Enterprise Security
MITRE ATT&CK
Python
EDR familiarity

Education

Bachelor's degree
Master's degree

Tools

Splunk
Splunk ES
MITRE ATT&CK
Zeek
Suricata
EDR

Job description

Peraton is seeking a Cyber Monitoring Signature Analyst to join the DSCM program, based in Rosslyn, VA with a secondary site in Beltsville, MD. The role focuses on building and enhancing threat detection in a Splunk-based SIEM environment, collaborating with senior engineers and threat analysts to protect a global IT infrastructure.

The position requires hands-on SPL development, familiarity with Splunk ES, MITRE ATT&CK framework, and EDR tooling.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Threat-Monitoring SIEM Analyst (Splunk ES)
Threat-Monitoring SIEM Analyst (Splunk ES)

Peraton • United States

On-site
USD 80,000 - 128,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Cyber Threat Detection Engineer: Splunk, SIEM & SOAR Expert
Cyber Threat Detection Engineer: Splunk, SIEM & SOAR Expert

Peraton • Tampa (FL)

On-site
USD 110,000 - 170,000
Onsite Senior Splunk SIEM Engineer – Threat Detection
Onsite Senior Splunk SIEM Engineer – Threat Detection

Creative Solutions Services, LLC • Richmond (VA)

On-site
USD 120,000 - 170,000
Senior SIEM Engineer — Splunk & Threat Detection Expert
Senior SIEM Engineer — Splunk & Threat Detection Expert

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000
Senior Cyber Threat Detection Engineer (Splunk/SOAR)
Senior Cyber Threat Detection Engineer (Splunk/SOAR)

Peraton • Town of Florida (NY), Northern (KY)

Hybrid
USD 80,000 - 128,000
Cyber Defense Analyst | Splunk & Threat Detection
Cyber Defense Analyst | Splunk & Threat Detection

Makoa • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 160,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000