5 threat detection engineer jobs at 4 companies in Elkton, MD

1w
Save
Mark Applied
Hide
Manager, Threat Detection Engineering
Plano or Malvern or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
7+ YOEBachelor's degree preferred; 7+ years in security operations, detection engineering, threat hunting, or incident response; people leadership, SIEM and SOAR experience, MITRE ATT&CK knowledge, and program-building expertise.
SIEM, SOAR, CI/CD, MITRE ATT&CK, Cyber Kill Chain, EDR, CNAPP, ITP, NIDS/NIPS
1w
Save
Mark Applied
Hide
Manager, Threat Detection Engineering
Malvern or Fort Worth or Dallas or United States
HybridFull Time
Vanguard
Vanguard: Provides mutual funds, ETFs, and investment management services.
7+ YOERequires 7+ years in security operations or related disciplines, security people-management experience, SIEM and SOAR expertise, detection engineering knowledge, and familiarity with MITRE ATT&CK and CI/CD.
SIEM, EDR, CNAPP, ITP, NIDS/NIPS, SaaS, SOAR, CI/CD, MITRE ATT&CK, Cyber Kill Chain, AI
21h
Save
Mark Applied
Hide
Threat Hunting Engineer Lead
Carrollton or Conshohocken
OnsiteFull Time
Cencora
CencoraNYSE: COR: Distributes pharmaceuticals and provides global healthcare supply chain solutions.
7+ YOEBachelor's degree or equivalent experience; 7+ years in cybersecurity, including 4+ years in incident response, forensics, threat hunting, or detection; scripting, threat platforms, network, OS, cloud, and communication expertise.
SIEM, EDR, SOAR, Windows, Linux, MacOS, MITRE ATT&CK, Python, Go, Powershell
1w
Save
Mark Applied
Hide
Senior Adversary Emulation Engineer
Philadelphia or Reston
$134k-$211k/yr OnsiteFull Time
Comcast
ComcastNASDAQ: CMCSA: Provides global telecommunications, media content, and entertainment services.
7+ YOEBachelor's degree or equivalent experience and 7+ years of cybersecurity experience. Requires adversary emulation, detection, threat hunting, scripting, AI-assisted security, telemetry, and detection logic expertise.
MITRE ATT&CK, Python, PowerShell, Bash, SIEM, XDR, EDR, SPL, KQL, SQL, Sigma, YARA, Atomic Red Team, MITRE Caldera, Mandiant Security Validation, Cymulate, AttackIQ, Prelude Operator
3w
Save
Mark Applied
Hide
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Baltimore, Maryland, United States
OnsiteFull Time
OneMain Financial
OneMain FinancialNYSE: OMF: Provides personal loans and credit cards to nonprime consumers.
8+ YOE8+ years cybersecurity experience with 6+ years SOC experience; bachelor\u0002s degree or equivalent; 2+ DFIR/forensics years; requires multiple certifications (e.g., GCFA, GCIH, CISSP); deep expertise in enterprise incident response, detection engineering, and threat hunting.
Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, Bash, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, Defender for Cloud Apps, Elastic, EDR/XDR, NDR, SIEM, SOAR, IDS/IPS, WAF, firewalls, VPN, DNS, DHCP, proxy, CASB, DLP, IAM, PAM, Kubernetes, Azure, AWS, Microsoft 365, Microsoft Entra ID, VMware, Hyper-V