Detection Engineering SME
Location: Washington, DC
Work Authorization: US Citizen
Location: Washington, DC
Work Authorization: US Citizen
Role Summary
The Detection Engineering SME leads the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules. This role ensures SBA鈥檚 threat detection posture is modern, comprehensive, and aligned with current adversary techniques.
Roles & Responsibilities
路聽 聽 聽 聽 Author detection rules for Google SecOps SIEM.
路聽 聽 聽 聽 Deploy curated detections and validate rule performance.
路聽 聽 聽 聽 Build multi-event correlation rules aligned to MITRE ATT&CK.
路聽 聽 聽 聽 Tune detections to meet false-positive thresholds.
路聽 聽 聽 聽 Integrate threat intelligence sources into detection logic.
路聽 聽 聽 聽 Support UEBA risk scoring and insider-threat detection.
路聽 聽 聽 聽 Provide expert guidance during Detect & Tune and Operationalize phases.
Professional Experience Required
路聽 聽 聽 聽 7+ years of experience in detection engineering, threat hunting, or cyber analytics.
路聽 聽 聽 聽 Experience authoring SIEM rules and correlation logic.
路聽 聽 聽 聽 Experience with MITRE ATT&CK, threat intelligence, and adversary emulation.
路聽 聽 聽 聽 Experience with cloud-native SIEM platforms.
Educational Qualification
路聽 聽 聽 聽 Bachelor鈥檚 degree in Cybersecurity, Computer Science, or related field.
Certifications
路聽 聽 聽 聽 GIAC Detection Engineering (GCTI, GDAT), CISSP, or equivalent preferred.
Learn more about this Employer on their Career Site
