Blu Omega logo
Blu Omega
Posted 31 days agoVerified live 2d ago

Detection Engineer

Brief overview

Remote
$70k–$90k/yrStated range
SplunkSecurity Information and Event Management (SIEM)Splunk Processing Language (SPL)Cybersecurity MonitoringSecurity Operations Center (SOC) OperationsThreat HuntingIncident ResponseCybersecurity Alert InvestigationYARACofense TriageSnapAttackMITRE ATT&CK

About the company

Blu Omega logo
Blu Omegabluomega.com

Blu Omega offers IT services and Clinical Research management consulting, focusing on technology solutions for federal sectors.

Job description

Summary

Blu Omega is seeking a Detection Engineer to support a federal program protecting critical health systems and data within the NIH Cybersecurity Operations Center. The role focuses on cybersecurity monitoring, detection engineering, threat hunting, phishing analysis, and collaboration with security operations teams in a fully remote environment.

Responsibilities

  • Develop and maintain security alerts and detection rules within Splunk
  • Write and modify SPL queries to identify suspicious or potentially malicious activity
  • Create and maintain Splunk dashboards, reports, and security analytics
  • Review and tune existing detections to improve accuracy and reduce false positives
  • Support phishing detection and analysis using Cofense Triage or similar tools
  • Assist with the development and maintenance of YARA rules
  • Use SnapAttack and other security tools to support detection development and analysis
  • Leverage built-in security analytics and detections across cybersecurity tools
  • Support threat hunting and investigation of suspicious activity
  • Apply MITRE ATT&CK concepts to understand attacker behaviors and detection coverage
  • Work with SOC analysts, incident responders, and other cybersecurity team members to improve monitoring and detection capabilities
  • Document detection rules, queries, dashboards, and investigative procedures

Skills

  • 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
  • Experience working with Splunk or a comparable SIEM platform
  • Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
  • Understanding of common cybersecurity threats and attacker techniques
  • Experience reviewing or investigating cybersecurity alerts
  • Strong analytical, troubleshooting, and communication skills
  • Experience developing or tuning security detections in Splunk
  • Familiarity with YARA rules
  • Experience with Cofense Triage or phishing analysis
  • Familiarity with SnapAttack
  • Knowledge of MITRE ATT&CK
  • Experience with threat hunting, endpoint security, or incident response
  • Federal cybersecurity experience
  • Security certification such as Security+, CySA+, CEH, or similar

Qualifications

Must Haves

  • 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
  • Experience working with Splunk or a comparable SIEM platform
  • Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
  • Understanding of common cybersecurity threats and attacker techniques
  • Experience reviewing or investigating cybersecurity alerts
  • Strong analytical, troubleshooting, and communication skills

Nice to Haves

  • Experience developing or tuning security detections in Splunk
  • Familiarity with YARA rules
  • Experience with Cofense Triage or phishing analysis
  • Familiarity with SnapAttack
  • Knowledge of MITRE ATT&CK
  • Experience with threat hunting, endpoint security, or incident response
  • Federal cybersecurity experience
  • Security certification such as Security+, CySA+, CEH, or similar

Benefits

  • Fully remote environment

More jobs like this