Threat Detection Engineer — SIEM Signatures (TS/SCI, Onsite)

RISA

St. Louis (MO)

On-site

USD 78,000 - 86,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Rolston Information Systems Assurance (RISA) in St. Louis, MO, is seeking a Cyber Threat Detection Engineer (SIEM/Signatures) on-site. You will craft and tune detection logic, analyze incidents, and run Purple Team exercises to outpace adversaries.

Active TS/SCI clearance and the ability to obtain a polygraph are required. Required is a Bachelor's degree with 6+ years of relevant experience (or equivalent), DoD 8140/8570-M IAT III/CSSP Analyst certification, and strong data-mining, regex, and

Qualifications

  • U.S. citizenship and an active TS/SCI.
  • Ability to successfully obtain and maintain a Government polygraph after hire.
  • Bachelor's degree in a field applicable to the position plus 6 years of relevant experience; equivalents accepted - Master's +4, Associate +8, or High School diploma/GED +10.
  • 8+ years of related advanced cyber security analytics experience.
  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
  • Data mining or query building in a SIEM.
  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
  • Static file signatures (magic numbers) and good working knowledge of regular expressions.

Responsibilities

  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
  • Turn intelligence and incident reporting into deployed detection logic.
  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.
  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.

Skills

SIEM data mining
Signature development
Regex patterns
Network protocol analysis
Scripting (Python/Bash/PowerShell)
DoD 8140/8570-M IAT III CSSP Analyst

Education

Bachelor's degree + 6 years experience; Master’s +4; Associate +8; HS diploma + 10

Tools

Protocol analyzers
SIEM tooling

Job description

Rolston Information Systems Assurance (RISA) in St. Louis, MO, is seeking a Cyber Threat Detection Engineer (SIEM/Signatures) on-site. You will craft and tune detection logic, analyze incidents, and run Purple Team exercises to outpace adversaries.

Active TS/SCI clearance and the ability to obtain a polygraph are required. Required is a Bachelor's degree with 6+ years of relevant experience (or equivalent), DoD 8140/8570-M IAT III/CSSP Analyst certification, and strong data-mining, regex, and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Detection Engineer III - SIEM Signatures
Cyber Threat Detection Engineer III - SIEM Signatures

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
Cyber Threat Detection Engineer (SIEM / Signatures)
Cyber Threat Detection Engineer (SIEM / Signatures)

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Cyber Analytics Engineer III
Cyber Analytics Engineer III

RISA • St. Louis (MO)

On-site
USD 78,000 - 86,000
Medical insurance
Dental insurance
Vision insurance
+4
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Cybersecurity Detection Engineer — SIEM & Threat Analytics
Cybersecurity Detection Engineer — SIEM & Threat Analytics

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK
Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Top-Secret Cleared Cybersecurity Engineer (SIEM)
Top-Secret Cleared Cybersecurity Engineer (SIEM)

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Senior Cyber Threat Analytics Engineer (TS/SCI)
Senior Cyber Threat Analytics Engineer (TS/SCI)

D2 Consulting • St. Louis (MO), Northern (KY)

Hybrid
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Threat Detection Analyst — Splunk ES & MITRE Expert
Threat Detection Analyst — Splunk ES & MITRE Expert

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000