Summary
Blu Omega is seeking a Detection Engineer to support a federal program protecting critical health systems and data within the NIH Cybersecurity Operations Center. The role focuses on cybersecurity monitoring, detection engineering, threat hunting, phishing analysis, and collaboration with security operations teams in a fully remote environment.
Responsibilities
- Develop and maintain security alerts and detection rules within Splunk
- Write and modify SPL queries to identify suspicious or potentially malicious activity
- Create and maintain Splunk dashboards, reports, and security analytics
- Review and tune existing detections to improve accuracy and reduce false positives
- Support phishing detection and analysis using Cofense Triage or similar tools
- Assist with the development and maintenance of YARA rules
- Use SnapAttack and other security tools to support detection development and analysis
- Leverage built-in security analytics and detections across cybersecurity tools
- Support threat hunting and investigation of suspicious activity
- Apply MITRE ATT&CK concepts to understand attacker behaviors and detection coverage
- Work with SOC analysts, incident responders, and other cybersecurity team members to improve monitoring and detection capabilities
- Document detection rules, queries, dashboards, and investigative procedures
Skills
- 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
- Experience working with Splunk or a comparable SIEM platform
- Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
- Understanding of common cybersecurity threats and attacker techniques
- Experience reviewing or investigating cybersecurity alerts
- Strong analytical, troubleshooting, and communication skills
- Experience developing or tuning security detections in Splunk
- Familiarity with YARA rules
- Experience with Cofense Triage or phishing analysis
- Familiarity with SnapAttack
- Knowledge of MITRE ATT&CK
- Experience with threat hunting, endpoint security, or incident response
- Federal cybersecurity experience
- Security certification such as Security+, CySA+, CEH, or similar
Qualifications
Must Haves
- 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
- Experience working with Splunk or a comparable SIEM platform
- Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
- Understanding of common cybersecurity threats and attacker techniques
- Experience reviewing or investigating cybersecurity alerts
- Strong analytical, troubleshooting, and communication skills
Nice to Haves
- Experience developing or tuning security detections in Splunk
- Familiarity with YARA rules
- Experience with Cofense Triage or phishing analysis
- Familiarity with SnapAttack
- Knowledge of MITRE ATT&CK
- Experience with threat hunting, endpoint security, or incident response
- Federal cybersecurity experience
- Security certification such as Security+, CySA+, CEH, or similar
Benefits