Threat Detection Engineer (Cloud Security)

Dark Wolf Solutions, LLC

Town of Ogden (NY)

On-site

USD 110,000 - 150,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Dark Wolf Solutions, LLC is seeking a Threat Detection Engineer to design, build, test, and deploy detection logic using Detection-as-Code across on-prem and AWS GovCloud. This role emphasizes high-fidelity alerts, threat hunting against sophisticated adversaries, and automating response workflows to reduce alert fatigue.

The engineer will leverage AI/ML to accelerate detection development, optimize queries, and streamline incident response while working fully on-site at Hill AFB in Ogden, Utah.

Qualifications

  • 4+ years of relevant experience in threat detection engineering.
  • 2+ years tuning detection logic in Splunk Enterprise and the ELK Stack.
  • 2+ years with DoD cybersecurity requirements, policies, and A&A activities.
  • Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
  • Experience ingesting and engineering detections for AWS GovCloud telemetry.
  • Experience using GitLab for Detection-as-Code and DevSecOps workflows.
  • DoDD 8140 IAT CSSP Certification must be obtained prior to hire.
  • US Citizenship and an active Top Secret/SCI clearance.
  • Bachelor’s degree in Computer Science, Information Technology, or a related field.

Responsibilities

  • Design, build, test, and deploy detection logic using Detection-as-Code across on-prem and AWS GovCloud environments.
  • Write and maintain custom detection signatures for cloud-native vectors, containers, and host behavior.
  • Ingest, normalize, and analyze AWS security logs and on-prem telemetry into SIEM and data lake environments.
  • Proactively hunt for undetected malicious activity and map to MITRE ATT&CK Cloud Matrix.
  • Partner with NOSC operators and AWS Engineers to automate remediation and incident response playbooks in GitLab pipelines.
  • Conduct root-cause analysis on false positives/negatives to improve alert fidelity.
  • Utilize AI-assisted analysis and ML features to enhance query generation and threat intelligence correlation.
  • Contribute to DCO concepts, processes, and procedures.
  • Support vulnerability management mitigations and adhere to BSTG policies.
  • Develop DCO TTPs, threat models, and supporting technical documentation.

Skills

Threat detection
Splunk ELK
GitLab CI/CD
Detection-as-Code
Threat hunting
AI/ML for detection
Incident response
MITRE ATT&CK Cloud
Security clearance

Education

Bachelor's degree in CS/IT or related

Tools

Terraform
CloudFormation
Falco
eBPF
Docker security
Kubernetes
RHEL

Job description

Dark Wolf is looking for a Threat Detection Engineer to design, build, test, and deploy detection logic using a “Detection-as-Code” methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.

Key Responsibilities:
  • Designing, building, testing, and deploying robust detection logic using a “Detection-as-Code” methodology across on-prem and cloud-hosted AWS GovCloud environments
  • Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior
  • Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environments
  • Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs mapped against the MITRE ATT&CK Cloud Matrix
  • Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident response playbooks within GitLab pipelines
  • Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity, reduce noise, and optimize detection rules
  • Utilizing AI-assisted analysis and ML features to enhance query generation, automate threat intelligence correlation, and streamline detection development
  • Participating in the development of DCO concept of operations, processes, and procedures
  • Supporting vulnerability management mitigations, adhere to defined policies and schedules, and complete all required training and disclosures as outlined by BSTG.
  • Participating in the development of DCO tactics, techniques, and procedures (TTPs), threat models, and supporting technical documentation.
Required Qualifications:
  • 4+ years of relevant experience
  • 2+ years of hands-on experience authoring and tuning detection logic in Splunk Enterprise and the ELK Stack (Elasticsearch, Logstash, Kibana).
  • 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures to include assessment and authorization activities.
  • Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
  • Direct experience ingesting, normalizing, and engineering detections for AWS GovCloud security telemetry (CloudTrail, VPC Flow Logs, GuardDuty, EKS Audit Logs).
  • Demonstrated experience using GitLab for Detection-as-Code, CI/CD pipelines, version control, and DevSecOps workflows.
  • Department of Defense Directive (DoDD) 8140 (formerly DoDD 8570) IAT CSSP Certification must be obtained prior to hire (CEH, CCNA Security, GCIH, CySA+ or Equivalent).
  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • US Citizenship and an active Top Secret/SCI security clearance required.
Desired Qualifications:
  • Experience managing detections as code using Infrastructure as Code (IaC) tools like Terraform or CloudFormation.
  • Familiarity with container runtime security (e.g., Falco, eBPF, Docker security) and Kubernetes threat modeling.
  • Experience with RHEL
  • Experience in performing post-incident computer forensics without destruction of critical data
  • Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Darkwolfsolutions • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)Ogden, UT
Threat Detection Engineer (Cloud Security)Ogden, UT

BuddoBot Inc. • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Architect: Cloud & GovCloud Security
Threat Detection Architect: Cloud & GovCloud Security

Darkwolfsolutions • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer, Cloud & GovCloud Security
Threat Detection Engineer, Cloud & GovCloud Security

Dark Wolf Solutions, LLC • Town of Ogden (NY)

On-site
USD 110,000 - 150,000
AI-Driven Cloud Threat Detection Engineer (DoD)
AI-Driven Cloud Threat Detection Engineer (DoD)

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer - Detection-as-Code (On-site Utah)
Threat Detection Engineer - Detection-as-Code (On-site Utah)

BuddoBot Inc. • Ogden (UT)

On-site
USD 100,000 - 160,000
Senior Systems Test Engineer (Cloud)
Senior Systems Test Engineer (Cloud)

darkwolfsolutions • Ogden (UT)

On-site
USD 90,000 - 145,000
EEO/AA employer
Defensive Cyber Operations (DCO) Analyst
Defensive Cyber Operations (DCO) Analyst

Dark Wolf Solutions, LLC • Town of Ogden (NY)

On-site
USD 90,000 - 145,000
Defensive Cyber Operations (DCO) Analyst
Defensive Cyber Operations (DCO) Analyst

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 90,000 - 145,000