Cyber Threat Detection Engineer (SIEM / Signatures)
$78k - $86kRISA
Job Description
Job Description
Cyber Threat Detection Engineer (SIEM / Signatures) Location: St. Louis, MO - on siteTime Type: Full time, ExemptClearance Required to Start: Active TS/SCI (U.S. citizenship required)Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)Travel: NoneSalary Range: $78,000 – $86,000 Adversaries are already inside somebody's enterprise. Make sure it isn't this one.RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.What You Will DoAnalyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.Turn intelligence and incident reporting into deployed detection logic.Run regular Purple Team exercises and continuously validate countermeasures already deployed.Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.What You'll BringU.S. citizenship and an active TS/SCI.Ability to successfully obtain and maintain a Government polygraph after hire.Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.8+ years of related advanced cyber security analytics experience.A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.Data mining or query building in a SIEM.Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.Static file signatures (magic numbers) and good working knowledge of regular expressions.Nice to HaveHex editor comfort; Python, Bash, or PowerShell scripting.Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.About RISARolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.BenefitsMedical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.RISA is an Equal Opportunity Employer.
- RISA is hiring a Cyber Threat Detection Engineer (SIEM / Signatures) in St. Louis, MO on site. You will develop and tune detection logic, run Purple Team exercises, and collaborate with the Cyber Data Analytics team to improve SIEM efficiency. The role requires active...Cyber
- ...protect our country from threats. Job... ...Events Management (SIEM) capability (i.e. Enterprise... ...platform, and the cyber threat intelligence capability, signature development and... ...threshold of 99.99% Detect and ticket... ...Perform all development, engineering, testing, integration...CyberFor contractors
- ...collaborating with Focused Operations and other teams to proactively prevent compromises and eradicate persistent adversaries. Responsibilities include tuning SIEM signatures, analyzing incident data, and supporting Purple Team exercises. #J-18808-Ljbffr D2 ConsultingCyber
- ...cybersecurity analyst with an active TS/SCI clearance to join the Defensive Cyber Operations team in the United States. You will develop and maintain defensive countermeasures, tune SIEM detections, and coordinate with Purple Teaming exercises to prevent and eradicate...Cyber
- ...OverviewMiTek is looking for a Cyber Threat Analyst to join our... ...investigations from initial detection through closure.ResponsibilitiesInvestigate... ...and analyze alerts from SIEM, EDR, DLP, and other... ...delivers software, services, engineered products, and automated solutions...CyberFull timeTemporary workWork at officeWorldwide
- ...insurance Description We are seeking a SOAR engineer to display a strong background in security operations, threat detection, and security engineering. Responsible for key... ...Stack or Splunk Experience supporting Defensive Cyber Operations Experience with integrating with...Cyber
- ...Pre-Sales Systems Engineer We are looking for a Pre-Sales Systems Engineer... ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident... ...Network operations Breach detection and prevention Security...CyberWorldwide
$72.12 - $84.14 per hour
...Job Title Systems Engineer Overview EverWatch is a government... ...skillset into areas like SIEM platforms, stream processing... ...experience in defensive cyber operations, cybersecurity... ...routing Experience architecting detection engineering pipelines, threat hunting workflows, and...CyberHourly payContract workLocal area- ...Inside Systems Engineer We are looking for an Inside Systems Engineer... ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident... ...Network Operations Breach Detection and Prevention Security Operations...CyberRemote workWorldwideHome office
- ...looking for a Pre-Sales Systems Engineer to work closely with our Mid-Market... ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident response... ...: Network operations Breach detection and prevention Security...Cyber
- MiTek is seeking a Cyber Threat Analyst to join our Cybersecurity team in Chesterfield, MO. You will investigate, coordinate, and respond... ..., endpoint security, and strong stakeholder communication skills to drive investigations from detection #J-18808-Ljbffr MiTekCyber
$75.2k - $158.1k
...Cyber Threat Hunter The Opportunity: CACI is seeking a cyber threat hunter to join our team in supporting the National Geospatial-Intelligence Agency (NGA). This role will proactively search for indicators of compromise on NGA systems and networks. You will conduct...CyberContract workWork experience placementFlexible hours$126.82k - $149.2k
...location three (3) or more days per week.U.S. Bank is seeking a Cyber Threat Intelligence Lead Analyst to help advance the bank’s cyber... ...findings to defensive actions across threat hunting, detection engineering, incident response, vulnerability management, and...CyberFull timeLocal area3 days per week$90k - $100k
D2 Technical Services in St. Louis, MO seeks an Advanced Cyber Security Analytics Engineer with an active TS/SCI clearance to strengthen enterprise defenses. You will analyze data, tune SIEM rules, and collaborate with incident response and purple team activities. Responsibilities...Cyber- MiTek Industries is seeking a Cyber Threat Analyst to join our Cybersecurity team. You will investigate incidents across endpoints, identities... ...guiding containment and remediation efforts. You will analyze SIEM/EDR/DLP alerts, perform log investigations, and communicate...Cyber
$90k - $100k
...the Branch Chief of Defensive Cyber Operations, you will be... ...incidents and develop or tune rules/signatures/scripts as needed.... ...Data Analytics team to achieve SIEM alert efficiency though evaluation... ...use case, as it pertains to detection logic, and identify the corresponding...CyberWork experience placement- ...SUMMARY The Security Analyst detects, manages and reduces the impact of cybersecurity threats to the organization. They are... ...equivalent (e.g., Math, Electrical Engineering, Cyber Security) 5+ years of... ...Information and Event Management (SIEM) CERTIFICATIONS CISSP, CCE, CEH...Cyber
$75.2k - $158.1k
...Cybersecurity Analytics Engineer IIISt. Louis, MO,... ...Branch Chief of Defensive Cyber Operations, you will... ...develop or tune rules/signatures/scripts as needed.* Coordinates... ...team to achieve SIEM alert efficiency... ...case, as it pertains to detection logic, and identify the...CyberContract workWork experience placementLocal areaFlexible hours- ...Job Title: Cyber Security Engineer Location: St. Louis, MO Work Model... ...This role will provide cyber threat intelligence, advanced... ...cybersecurity analytics, reporting, detection tuning, operational... ...tuning requests, and custom signature creation to the CSOC and other...CyberContract workTemporary workLocal area
- CACI International Inc. seeks a Cyber Threat Hunter to join NGA operations, proactively hunting for indicators of compromise and analyzing Windows, Linux, and network data. You’ll document findings and drive improvements to the agency's security posture through cross‑team...CyberLocal area
- MiTek Industries, Inc. is seeking a Cyber Threat Analyst to join our Cybersecurity team in an on-site role. You will investigate incidents across endpoints, identities, email, and cloud, and coordinate containment and remediation with IT and business units. The ideal candidate...Cyber
$105.79k - $141.05k
...opening for a Lead Information Security Engineer who will support threat hunting, investigation, and discovery... ...the internet. Black Lotus Labs has detected and disrupted key evolving threats at... ...automated detection. Work with cyber operators and senior researchers, when...CyberFull timeTemporary workWork experience placementRemote workWork from home$132.23k - $176.31k
...opening for a Senior Lead Security Engineer that will leverage Lumen’s... ...of evolving malicious threats, provide mission-relevant intelligence... .... Black Lotus Labs has detected and disrupted key evolving threats... ...detection. Work with cyber operators, when requested, to...CyberFull timeTemporary workWork experience placementWork at officeRemote work- Fortinet, Inc. is seeking a Pre-Sales Systems Engineer to work with the Mid-Market sales teams. The role focuses on enabling sales engagements by analyzing IT goals, crafting Fortinet-based solutions, and delivering accurate presentations to customers and partners. The...Cyber
- Forward Slash Technology is a St. Louis-based Cyber Security, Information Technology, and Managed Services provider. We are seeking a Senior Systems & Network Engineer to join our St. Louis‑based engineering team. This is a senior‑level, client‑facing individual contributor...CyberFull timeWork at office
- ...organization(s). Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with... ...enterprise constituency. Manage threat or target analysis of cyber defense information and production of...Cyber
$74.8k - $130.9k
...possible. Job Description: Parsons is now hiring for a Roadway Engineer II to join our St. Louis team supporting major regional road... ...years of experience, Parsons is uniquely qualified to deliver cyber/converged security, technology-based intellectual property, and...CyberLocal areaImmediate startWorldwideFlexible hours$120k - $140k
...driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI....CyberFreelanceLocal area$90.3k - $189.6k
...external customer activities with Defensive Cyber Operations-Internal Defensive Measures (... ...data is available to the NGA CSOC, Insider Threat, and other security‑focused entities... ...of Security Incident & Event Management (SIEM) and log aggregation concepts. Knowledge of...CyberFor contractorsWork at officeFlexible hours$120.64k - $197.6k
...systems that support critical Defense and Intelligence missions. This position is focused on applying risk management frameworks, engineering security controls, and maintaining system authorizations for cloud and on-prem environments. You'll work closely with other...CyberRelocationRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Threat Detection Engineer (SIEM / Signatures). Be the first to apply!
- sr information security engineer Saint Louis, MO
- senior cloud security engineer Saint Louis, MO
- security engineer Saint Louis, MO
- senior security operations engineer Saint Louis, MO
- information technology security engineer Saint Louis, MO
- application security engineer Saint Louis, MO
- network security engineer Saint Louis, MO
- aws cloud security engineer Saint Louis, MO
- IT security engineer Saint Louis, MO
- senior application security engineer Saint Louis, MO



