cFocus Software Incorporated
Posted 1mo ago

AOUSC - Detection Engineer

cFocus Software Incorporated
Washington, District of Columbia, United States
HybridFull Time
Responsibilities
  • hunting threats
  • developing detections
  • querying datasets
Requirements
  • Active Public Trust clearance
  • BS in CS/IT or related
  • 3+ years threat hunting/adversary emulation
  • Experience querying large datasets
  • Python and PowerShell scripting, and detection development in SIEM (Splunk ES or Microsoft Sentinel)
Technical tools mentioned
PythonPowerShellSplunk ESMicrosoft SentinelSIEM

Job description

cFocus Software seeks a Detection Engineer to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 3+ years’ experience conducting proactive threat hunting or adversary emulation. 
  • 2+ years demonstrated experience forming hypothesis, querying large datasets and identifying APT behavior.
  • 2+ years’ experience in scripting languages including Python and PowerShell to develop new tools. 
  • 2+ years’ experience with demonstrated proficiency developing detections in a SIEM (utilizing Splunk ES or Microsoft Sentinel). 

About cFocus Software Incorporated

Private IT services firm providing cybersecurity, cloud, geospatial, and enterprise software services to U.S. federal agencies.

Similar jobs

Detection Engineer roles near Washington, District of Columbia
2w
Save
Mark Applied
Hide
Vectra Detection Engineer
Chantilly, Virginia, United States
OnsiteFull Time
GuidePoint Security
GuidePoint Security: Private cybersecurity services and solutions firm serving businesses and government agencies with consulting, engineering, and managed security.
Requires active TS/SCI clearance, network traffic analysis and threat detection experience, Suricata experience, offensive security knowledge, MITRE ATT&CK familiarity, and understanding of networking protocols and OSI layers.
Suricata, MITRE ATT&CK, Greenhouse Software, Zoom Scheduler
3w
Save
Mark Applied
Hide
Senior Detection Engineer
Ashburn or Southlake or Cary or Branchburg
$101k-$194k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Leading global provider of telecommunications and technology services.
4+ YOEBachelor's degree or 4+ years' experience; 4+ years relevant experience; EDR/XDR, Linux security, networking, Splunk, scripting, databases, and enterprise security engineering expertise.
Splunk, CrowdStrike Falcon, Splunk ES, Python, Linux, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), Security Information and Event Management (SIEM), BGP, TLS/SSL, DNS, PAM, RTR, Fusion
3w
Save
Mark Applied
Hide
Senior Detection Engineer
Ashburn or Southlake or Cary or Branchburg
$101k-$194k/yr HybridFull Time
Verizon
VerizonNYSE: VZ: Leading global provider of telecommunications and technology services.
4+ YOEBachelor's degree or 4+ years' experience; 4+ years relevant experience; EDR/XDR, Linux security, networking, Splunk, scripting, databases, and enterprise security engineering expertise.
Splunk, CrowdStrike Falcon, Splunk Enterprise Security (Splunk ES), Python, Linux, BGP, TLS, SSL, DNS, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), Remote Terminal Responder (RTR), Fusion
6mo
Save
Mark Applied
Hide
Detection Engineer
Arlington, Virginia, United States
$91k-$221k/yr RemoteFull Time
Accenture Federal Services
Accenture Federal ServicesNew York Stock Exchange: ACN: Technology and management consulting for U.S. federal agencies.
6+ YOE6+ years in information security; Bachelor's in Cybersecurity, CS, or related field; 2+ years event/log analysis; US Citizenship; hands-on with Microsoft Sentinel, KQL, Cisco FirePower/IDS-IPS; SIEM; scripting (PowerShell, Python, regex); Git/GitHub; TCP/IP and Windows/Linux; MITRE ATT&CK mapping.
Microsoft Sentinel, KQL, Cisco FirePower, IDS/IPS, SIEM, Git, GitHub, PowerShell, Python, regex, Wireshark, grep, sed, awk
4w
Save
Mark Applied
Hide
Manager, Threat Detection Engineer
Washington, District of Columbia, United States
$160k-$180k/yr HybridFull Time
The Carlyle Group
The Carlyle GroupNasdaq Global Select Market: CG: Public investment firm serving institutional investors, financial advisors, and portfolio companies through private equity, credit, and AlpInvest.
5+ YOEBachelor's required,5+ years cybersecurity experience,4+ years detection engineering and threat intelligence,hands-on detection development and tuning,automation and API integration experience,experience with SIEM/EDR/SOAR and detection languages.
MITRE ATT&CK, SIEM, EDR, XDR, SOAR, Sigma, KQL, SPL, XQL, YARA-L, EQL, SQL, YARA, APIs
5mo
Save
Mark Applied
Hide
Detection Engineer Analyst Subject Matter Expert (SME)
Quantico, Virginia, United States
$130k-$150k/yr OnsiteFull Time
Resource Management Concepts
Resource Management Concepts: Delivering Mission-Focused IT & Cybersecurity Solutions
5+ YOEActive TS/SCI clearance; BS in IT/CS or 5 years DCO/network experience; DoD 8570 IAT III and CSSP Analyst certs; 5 years in signatures/policies; enterprise network experience; signature development (KQL/Snort/ePO/Yara).
KQL, Snort, ePO, Yara, SIEM, SOAR
3d
Save
Mark Applied
Hide
Data & Detection Engineer
Fort Belvoir, Virginia, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
Requires Elastic machine learning and AIOps experience, cybersecurity expertise, TS/SCI clearance, bachelor's degree, and IASAE II certification such as CASP+, CISSP, or CSSLP.
Elastic, Elastic Stack, Python, PowerShell, NIST 800-207, OSCP, GCIH, GVAP
3d
Save
Mark Applied
Hide
Data & Detection Engineer
Fort Belvoir, Virginia, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Global firm providing management, technology, and engineering consulting services.
Requires TS/SCI clearance, bachelor's degree, IASAE II certification such as CASP+, CISSP, or CSSLP, and experience with Elastic machine learning, AI alerting, log analysis, AIOps, and platform monitoring.
Elastic, Elastic Stack, Python, PowerShell, SIEM, APM, NIST 800-207, OSCP, GCIH, GVAP