Threat Detection Engineer - Detection-as-Code (On-site Utah)

BuddoBot Inc.

Ogden (UT)

On-site

USD 100,000 - 160,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Dark Wolf is seeking a Threat Detection Engineer to design, build, test, and deploy detection logic across on-premise and AWS GovCloud environments, applying a Detection-as-Code approach to create high-fidelity alerts, automate responses, and reduce alert fatigue. The role centers on proactive threat hunting, ML-assisted detection development, and integration with GitLab pipelines.

This is an on-site position at Hill AFB in Ogden, Utah.

Qualifications

  • 4+ years of relevant experience in threat detection or security engineering.
  • Hands-on Splunk Enterprise and ELK Stack tuning and use.
  • Experience applying DoD cybersecurity requirements and A&A activities.
  • Experience in a vSOC, SOC, or CSSP responding to incidents.
  • Experience ingesting AWS GovCloud security telemetry and on-prem logs.
  • GitLab for Detection-as-Code and CI/CD workflows.
  • DoDD 8140 CSSP certification or equivalent before hire.
  • Bachelor's degree in CS/IT or related field.
  • US Citizenship with active Top Secret/SCI clearance.

Responsibilities

  • Design, build, test, and deploy detection logic across on-prem and AWS GovCloud.
  • Write and maintain detection signatures for cloud vectors, containers, and hosts.
  • Ingest and analyze CloudTrail, VPC logs, GuardDuty, Config, EKS logs and on‑prem telemetry.
  • Proactively hunt for threats mapped to MITRE ATT&CK Cloud Matrix.
  • Collaborate with NOSC and AWS engineers to develop automated remediation in GitLab CI/CD.
  • Root-cause analysis on false positives/negatives to improve alert fidelity.
  • Leverage AI-assisted analysis to improve query generation and threat intelligence correlation.
  • Contribute to DCO concepts of operations, processes, and procedures.
  • Support vulnerability management, adhere to BSTG policies and training.
  • Participate in developing DCO TTPs, threat models, and documentation.

Skills

Threat detection engineering
Splunk Enterprise
ELK Stack
SOC/CSSP experience
GitLab & CI/CD
DoD compliance knowledge
Security clearance eligibility

Education

Bachelor's degree in Computer Science / IT

Tools

GitLab
AWS GovCloud
Terraform / CloudFormation
CloudTrail / GuardDuty / EKS Logs

Job description

Dark Wolf is seeking a Threat Detection Engineer to design, build, test, and deploy detection logic across on-premise and AWS GovCloud environments, applying a Detection-as-Code approach to create high-fidelity alerts, automate responses, and reduce alert fatigue. The role centers on proactive threat hunting, ML-assisted detection development, and integration with GitLab pipelines.

This is an on-site position at Hill AFB in Ogden, Utah.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Architect: Cloud & GovCloud Security
Threat Detection Architect: Cloud & GovCloud Security

Darkwolfsolutions • Ogden (UT)

On-site
USD 100,000 - 160,000
AI-Driven Cloud Threat Detection Engineer (DoD)
AI-Driven Cloud Threat Detection Engineer (DoD)

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)Ogden, UT
Threat Detection Engineer (Cloud Security)Ogden, UT

BuddoBot Inc. • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Darkwolfsolutions • Ogden (UT)

On-site
USD 100,000 - 160,000
Threat Detection Engineer (Cloud Security)
Threat Detection Engineer (Cloud Security)

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 100,000 - 160,000
Defensive Cyber Ops Analyst: AI-Driven Threat Detection
Defensive Cyber Ops Analyst: AI-Driven Threat Detection

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 90,000 - 145,000
Defensive Cyber Operations (DCO) Analyst
Defensive Cyber Operations (DCO) Analyst

Dark Wolf Solutions, LLC • Ogden (UT)

On-site
USD 90,000 - 145,000
Senior Security Engineer — AI-Driven Detection & Response
Senior Security Engineer — AI-Driven Detection & Response

Socket.dev • American Fork (UT)

On-site
USD 120,000 - 180,000
Health coverage
401k match
Flexible PTO
Remote Detection Engineer: Build & Automate Detections
Remote Detection Engineer: Build & Automate Detections

Binary-Defense • Houston (TX)

Remote
USD 110,000 - 170,000
Medical, dental, and vision coverage
401k match
Remote-friendly work environment
+1
Threat Detection Engineer - Cloud & On-Prem Monitoring
Threat Detection Engineer - Cloud & On-Prem Monitoring

Sharp Decisions • Charlotte (NC)

Hybrid
USD 105,000 - 145,000