Hiring.Camp

Threat Detection Engineer (Cloud Security)

Darkwolfsolutions

·

Today

Salary
$100k – $160k
Location
Ogden, UT · Ogden, Utah, United States
Workplace
Onsite
Department
Cybersecurity
Experience
2+ years
Clearance
Required
Source
Greenhouse

Description

Dark Wolf is looking for a Threat Detection Engineer to design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.

Key Responsibilities:

  • Designing, building, testing, and deploying robust detection logic using a "Detection-as-Code" methodology across on-prem and cloud-hosted AWS GovCloud environments
  • Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior
  • Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environments
  • Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs mapped against the MITRE ATT&CK Cloud Matrix
  • Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident response playbooks within GitLab pipelines
  • Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity, reduce noise, and optimize detection rules
  • Utilizing AI-assisted analysis and ML features to enhance query generation, automate threat intelligence correlation, and streamline detection development
  • Participating in the development of DCO concept of operations, processes, and procedures
  • Supporting vulnerability management mitigations, adhere to defined policies and schedules, and complete all required training and disclosures as outlined by BSTG.
  • Participating in the development of DCO tactics, techniques, and procedures (TTPs), threat models, and supporting technical documentation.

Required Qualifications:

  • 4+ years of relevant experience
  • 2+ years of hands-on experience authoring and tuning detection logic in Splunk Enterprise and the ELK Stack (Elasticsearch, Logstash, Kibana).
  • 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures to include assessment and authorization activities.
  • Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
  • Direct experience ingesting, normalizing, and engineering detections for AWS GovCloud security telemetry (CloudTrail, VPC Flow Logs, GuardDuty, EKS Audit Logs).
  • Demonstrated experience using GitLab for Detection-as-Code, CI/CD pipelines, version control, and DevSecOps workflows.
  • Department of Defense Directive (DoDD) 8140 (formerly DoDD 8570) IAT CSSP Certification must be obtained prior to hire (CEH, CCNA Security, GCIH, CySA+ or Equivalent).
  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • US Citizenship and an active Top Secret/SCI security clearance required.

Desired Qualifications:

  • Experience managing detections as code using Infrastructure as Code (IaC) tools like Terraform or CloudFormation.
  • Familiarity with container runtime security (e.g., Falco, eBPF, Docker security) and Kubernetes threat modeling.
  • Experience with RHEL
  • Experience in performing post-incident computer forensics without destruction of critical data
  • Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff

The salary range for this position is estimated to be between $100,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

We are strictly looking for direct, full-time W2 employees.

Skills

AWSDockerKubernetesTerraformCI/CDElasticsearchMachine LearningGitLabCybersecuritySIEMSOCSplunkComplianceCCNA

Similar Jobs

30

Threat Detection Engineer

Regions · Hoover, AL - Riverchase Operations Center (Birmingham, AL), United States of America +3

3 weeks ago

Threat Detection Engineer

Legato Security · Salt Lake City, Utah, United States

7 months ago

Senior Threat Detection Engineer

Dragos · United States

Today

Threat Detection & Response Engineer -- Senior Expert

Allstate · USA - IL (Remote), United States of America · Remote

4 days ago

Threat Detection & Response Engineer, AI-Era Detection & Response

Trendmicro · US Off-Site, United States of America

5 days ago

Principal Engineer – Web Threat Detection & Distributed Systems

Maxit Consulting Jobs · Massachusetts

1 week ago

Staff Security Engineer, Threat Detection & Response

Gemini · New York, New York; Miami, Florida; Remote (USA) · Remote

1 week ago

Threat Detection and Response Engineer

Whatnot · San Francisco, CA +3 · Remote

2 weeks ago

Network Threat Detection R&D Engineer

Broadcom · USA-CA - Promontory E, United States of America

2 weeks ago

Sr. Security Engineer - Cloud Threat Detection

Thehartford · Hartford CT- Home Office, United States of America +2 · Hybrid

2 weeks ago

Security Engineer Lead - Safe Browsing - Threat Detection

GOC ( Google Operational Centers ) · PH-MNL-UBT1, Philippines

3 weeks ago

Senior Security Engineer- Threat Engineering Detection Team

Truist · Atlanta GA - 303 Peachtree Center Avenue - Garden Offices, United States of America +2

3 weeks ago

Engineer, Threat Detection - 5

Tide · United Kingdom

3 weeks ago

Senior Security Engineer - Threat Detection

Grab · Petaling Jaya, Malaysia · Onsite

1 month ago

Staff Information Security Engineer - Threat Detection & Response

Visier Solutions Inc · Vancouver, BC, Canada

1 month ago

Threat Detection & Response Engineer, Senior (High Level Clearance Required)

Icf · Virginia Client Office (VA88), United States of America +1

1 month ago

Threat Detection & Automation Engineer (with focus on Data Engineering)

Northwestern Mutual · Milwaukee, WI Corporate, United States of America +1

1 month ago

Engineer II, Threat Detection - Windows (Hybrid)

Crowdstrike · Sunnyvale, United States of America +3 · Remote, Hybrid, Onsite

1 month ago

Member of Technical Staff, SecOps & Threat Detection Engineer

Envoy · San Francisco, CA · Onsite

1 month ago

Security Engineer (Threat Detection & Response)

Mastercard · Mexico City, Mexico

1 month ago

Security Engineer - Detection Engineering and Threat Modeling

HiNext · (HE)Office_KRK Pawia, Poland · Hybrid

1 month ago

Senior Threat Detection Engineer

Salesforce · Washington - Bellevue, United States of America · Onsite

2 months ago

Threat Detection Engineer – Security Operations

Idme · Mountain View, California, United States

2 months ago

Threat-Led Detection Engineer

LON3 London - 51 Lime Street · London, London, United Kingdom, GB

2 months ago

Cybersecurity Threat Detection & Response Engineer

Hp · BCN03 - Barcelona S.Cugat B3 (BCN03), Spain

3 months ago

Cybersecurity Threat Detection & Response Engineer

Hp · BCN03 - Barcelona S.Cugat B3 (BCN03), Spain

3 months ago

Cybersecurity Threat Detection & Response Engineer

HP · Sant Cugat del Vallès, CT,ES, ES

3 months ago

Threat Detection Engineer - Cybersecurity

Neysa Networks Private Limited - Linkedin · Chennai +1 · Onsite

3 months ago

Security Engineer - Threat Detection

Snowflake · US, Remote · Remote

3 months ago

Threat Detection Security Engineer

Costar · US-VA Arlington, United States of America · Remote, Onsite

4 months ago