Cyber Threat Detection Engineer (SIEM/Signatures)
$78k - $86kRISA
Job Description
Job Description
Cyber Threat Detection Engineer (SIEM / Signature Development)
Cyber Security Operations Specialist III - Advanced Cyber Analytics
Location: St. Louis, MO - on site
Time Type: Full time, Exempt
Clearance Required to Start: Active TS/SCI (U.S. citizenship required)
Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)
Travel: None
Salary Range: $78,000 – $86,000
Adversaries are already inside somebody's enterprise. Make sure it isn't this one.
RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.
What You Will Do
- Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.
- Turn intelligence and incident reporting into deployed detection logic.
- Run regular Purple Team exercises and continuously validate countermeasures already deployed.
- Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.
- Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.
- Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.
What You'll Bring
- S. citizenship and an active TS/SCI.
- Ability to successfully obtain and maintain a Government polygraph after hire.
- Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.
- 8+ years of related advanced cyber security analytics experience.
- A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.
- Data mining or query building in a SIEM.
- Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.
- Static file signatures (magic numbers) and good working knowledge of regular expressions.
Nice to Have
- Hex editor comfort; Python, Bash, or PowerShell scripting.
- Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.
About RISA
Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.
Benefits
Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.
RISA is an Equal Opportunity Employer.
- Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
- ...protect our country from threats. Job... ...Events Management (SIEM) capability (i.e. Enterprise... ...platform, and the cyber threat intelligence capability, signature development and... ...threshold of 99.99% Detect and ticket... ...Perform all development, engineering, testing, integration...CyberFor contractors
- ...Pre-Sales Systems Engineer We are looking for a Pre-Sales Systems Engineer... ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident... ...Network operations Breach detection and prevention Security...CyberWorldwide
- ...Sr. Cybersecurity Engineer The Sr. Cybersecurity Engineer... ...infrastructure of the SIEM and MEDR services. They... ...analysis of security threats. This position works... ...years' experience in the Cyber security field ~5+... ...work (e.g. develop custom detection rules, custom...Cyber
$80k - $150k
...Security Engineer Come join the company reinventing... ...the next big thing in cyber. Backed by the world's... ...automation, cloud security, detection engineering, and AI-... ...experience working with SIEM data and log pipelines.... ...detections based on logs, threat behavior, and...CyberTemporary workWork experience placementWork at officeRemote work- ...master planning, architecture, engineering, and construction firm that... ...SaaS APIs, Identity Provider, SIEM/SOAR) Data... ...that high-fidelity DLP and CASB detection data is successfully and reliably... ...Understanding of malware, emerging threats, attacks, and vulnerability exploitation...SuggestedFor contractorsWork experience placementFlexible hours
$87.1k - $157.45k
...mission software capabilities in the areas of cyber, logistics, security operations, and... ...customers’ mission to defend against evolving threats around the world. Our team’s focus is to... ...is currently seeking a Mid-Level Systems Engineer for the Chinook Program. As part of a...CyberContract workFor contractorsWork at officeLocal areaImmediate start- ...provide innovative design, engineering, procurement, implementation... ...You’ll Get to Do: Provide cyber threat intelligence services for the... ...tuning requests, and custom signature creation to the CSOC and... ...operates Network Intrusion Detection and Forensics; conducts performance...CyberContract workWorldwide
- ...insurance Description We are seeking a SOAR engineer to display a strong background in security operations, threat detection, and security engineering. Responsible for... ...or Splunk Experience supporting Defensive Cyber Operations Experience with integrating...Cyber
- ...Job Description Job Title: Cyber Security Engineer Location: St. Louis, MO... ...role will provide cyber threat intelligence, advanced cybersecurity... ...analytics, reporting, detection tuning, operational... ...tuning requests, and custom signature creation to the CSOC and other...CyberContract workLocal area
$145.46k - $193.94k
...Lotus Labs is seeking a remote Threat Intelligence Researcher on... ...intelligence, data science, AI engineering, and security automation. The... ...threat discovery and detection development, automate enrichment... ...passive DNS,) to track malicious cyber actors, their infrastructure,...CyberFull timeTemporary workRemote work$132.23k - $176.31k
...opening for a Senior Lead Security Engineer that will leverage Lumen’s... ...of evolving malicious threats, provide mission-relevant intelligence... .... Black Lotus Labs has detected and disrupted key evolving threats... ...detection. Work with cyber operators, when requested, to...CyberFull timeTemporary workWork experience placementWork at officeRemote work- ...(SSI) helps clients conceptualize and design for the deep interdependencies inherent in today’s cyber-physical systems. We balance the art and science of systems engineering to creatively and digitally transform design and development. We provide leading expertise in digital...CyberRemote work
$60 - $65 per hour
...Judge Group Recruitment Specialist at Judge group/Aerospace Engineering,Non-IT, Security Clearance St Louis, MO Onsite Basic... ...-4 years (based on level) or equivalent experience in software/cyber security integration and verification, with a focus on military...CyberContract work$101k - $111k
...Description Job Description Vulnerability Management Engineer (Tenable / Nessus) Cyber Security Engineer III - Endpoint Security Services... ...respond to incidents promptly; stay current on emerging threats. Train and support users on the Tenable suite, and keep...CyberFull timeLocal area- ...vital interests. Requisition #: 1647 Job Title: System Engineer (MBSE) Location: Hybrid, St Louis, MO Clearance Level:... ...regulatory, certification, product assurance, product security (cyber security) and other specialties quality factors into a preferred...CyberWork at office
$120k - $140k
...driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI....CyberFreelanceLocal area- ...Product Security Engineer Lead the cybersecurity aspects of the full-lifecycle development and manufacturing and production of... ...programs. The candidates will lead and support system analysis for cyber threats, cyber test activities, cybersecurity of large scale events,...Cyber
- ...organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first... ...Qualifications What you bring to the table ~5+ years of engineering and pre-sales experience ~ Possess strong analytical...CyberWorldwide
$143k - $156k
...critical infrastructure. Come join us. Shift5 is seeking a Systems Engineer to join our team. In this role, you will be the bridge between... ...-discipline technical execution across software, platform, cyber, data science, and integration teams. Serve as the technical...CyberContract workFor contractorsRemote workFlexible hours- ...organizations worldwide from increasingly sophisticated cyber and AI-driven threats, securing their AI transformation. Our prevention-first... ...Qualifications What you bring to the table 5+ years of engineering and pre-sales experience Possess strong analytical and problem...CyberWorldwide
$119.77k - $140.9k
...and resiliency planning.Implement and maintain backup, recovery, cyber resiliency, Safeguarded Copy, and data protection solutions to... ..., service reliability, and risk management.Collaborate with engineering, application, infrastructure, operations, and vendor teams to troubleshoot...CyberFull timeWork experience placementLocal area3 days per week- ...mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever... ...(Recommend an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree...CyberTemporary workFor contractorsFlexible hours
$162.35k - $219.65k
...currently seeking a Senior Product Security Engineer to join our Training Systems Product... ...solutions Conduct security assessments (threat analyses, risk assessments, audits),... ...(e.g., JSIG, DoD RMF, NISPOM) Support cyber test and validation activities, including...CyberPermanent employmentRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workDay shift- ...using your expertise to protect our country from threats. Job Description GDIT is seeking a Domain Service Engineer to support the planning, building, and... ...AD/Entra ID, PKI/Certificate Authorities, and SIEM tools for automated threat containment and compliance...Immediate start
- ...and standardsEvaluate and deploy security technologies (e.g., SIEM, EDR, firewalls, IAM, DLP, DSPM, Zero Trust)Ensure compliance... ...incident response and forensic investigations.Design and manage threat detection and prevention systems.Perform proactive threat hunting and...Contract workWork experience placementWork at officeImmediate startRemote workFlexible hours1 day per week
$241.5k - $359k
...business model design, business process re-engineering, products and services delivery, and... ...assessment of external digital opportunities and threats, and internal technology capabilities... ...management, application management, cyber security and disaster recovery, and...CyberMinimum wageFull timeTemporary workWork at officeLocal areaWorldwideFlexible hours$122.7k - $187.8k
...clients, with USA as the primary focus and the engine driving regional expansion. In this high-... ...for Accenture Security offerings across Cyber Defense , Cloud Security, Identity &... ...innovator by sharing insights on emerging threats, regulatory trends, and AI-driven...CyberContract workWork experience placementLive inWork at officeLocal areaWorldwide- ...solutions within client organizations. Job Description Network Security Engineer Indigo Beam is looking for 2 knowledgeable Network Security engineers with 10+ years’ of Network/Cyber Security experience remediating excessive/over permissive firewall rules...CyberWork experience placement
- ...Perform beginning level civil engineering work as part of a construction/contract management team responsible for the administration of... ...performing essential functions of the job without posing a direct threat to the health and safety of others. SPECIAL REQUIREMENT Must...Contract workFor contractorsLocal area
- ...offerings across the defense, space, civilian and intelligence markets includes secure high-end solutions in mission IT, enterprise IT, engineering services and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Detection Engineer (SIEM/Signatures). Be the first to apply!
- senior cloud security engineer Saint Louis, MO
- aws cloud security engineer Saint Louis, MO
- sr information security engineer Saint Louis, MO
- network security engineer Saint Louis, MO
- information technology security engineer Saint Louis, MO
- senior application security engineer Saint Louis, MO
- security engineer Saint Louis, MO
- IT security engineer Saint Louis, MO
- cyber Saint Louis, MO
- application security engineer





