Threat Detection Engineer — Splunk SIEM & MITRE ATT&CK

Peraton

Beltsville (MD)

On-site

USD 80,000 - 128,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Cyber Monitoring Signature Analyst to join the DoS DSCM program. The role is based in Rosslyn, VA with a secondary site at Beltsville, MD, and a standard Mon-Fri schedule. You will develop and tune SPL-based detections, work with senior engineers, and maintain SIEM health across global IT infrastructure.

Preferred candidates have Splunk ES experience, MITRE ATT&CK familiarity, and strong reporting skills. U.S.

Qualifications

  • Hands-on experience authoring and tuning SPL in a production Splunk environment.

Responsibilities

  • Author, tune, and maintain correlation searches, Risk Notables, and Adaptive Response actions within Splunk Cloud Enterprise Security.
  • Evaluate new analytical detections from open-source libraries and incorporate vetted alerting into a SIEM.
  • Author new correlational searches in SPL2 using best practice search methodologies.
  • Maintain a living MITRE ATT&CK coverage matrix and identify gaps with SME.
  • Ensure proper cohesion and health of SIEM alerting.
  • Collaborate with system engineers on configuration and tuning of cyber security tools.
  • Operationalize threat intelligence to ensure IOC are actionable in detections.
  • Provide reporting on detection development metrics (coverage, MTTx, FP rate).

Skills

SPL searches
Splunk ES
MITRE ATT&CK
EDR
Incident Response
Communication
Security Lifecycle

Education

Bachelor's degree
Master's degree

Tools

Splunk Enterprise Security

Job description

Peraton is seeking a Cyber Monitoring Signature Analyst to join the DoS DSCM program. The role is based in Rosslyn, VA with a secondary site at Beltsville, MD, and a standard Mon-Fri schedule. You will develop and tune SPL-based detections, work with senior engineers, and maintain SIEM health across global IT infrastructure.

Preferred candidates have Splunk ES experience, MITRE ATT&CK familiarity, and strong reporting skills. U.S.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat Detection Analyst — Splunk ES & MITRE Expert
Threat Detection Analyst — Splunk ES & MITRE Expert

Peraton • Beltsville (MD)

On-site
USD 80,000 - 128,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Onsite Senior Splunk SIEM Engineer – Threat Detection
Onsite Senior Splunk SIEM Engineer – Threat Detection

Creative Solutions Services, LLC • Richmond (VA)

On-site
USD 120,000 - 170,000
Senior Splunk SIEM Engineer for Threat Detection & IR
Senior Splunk SIEM Engineer for Threat Detection & IR

Doist • Richmond (VA)

On-site
USD 110,000 - 160,000
Cybersecurity Detection Engineer — SIEM & Threat Analytics
Cybersecurity Detection Engineer — SIEM & Threat Analytics

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Senior SIEM Engineer — Splunk & Threat Detection Expert
Senior SIEM Engineer — Splunk & Threat Detection Expert

Leidos • Corridor North (MD)

On-site
USD 131,000 - 237,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Cyber Detection Engineering Lead – SIEM & SOAR Architect
Cyber Detection Engineering Lead – SIEM & SOAR Architect

ManTech • McLean (VA)

On-site
USD 140,000 - 190,000
Senior CND Engineer - Splunk & Threat Detection (TS/SCI)
Senior CND Engineer - Splunk & Threat Detection (TS/SCI)

Mission Technologies, a division of HII • Springfield (VA)

On-site
USD 85,000 - 185,000