Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Cyber Threat Detection Engineer (SIEM / Signatures)

$78k - $86k

RISA

Job Description

Job Description

Cyber Threat Detection Engineer (SIEM / Signatures) Location: St. Louis, MO - on siteTime Type: Full time, ExemptClearance Required to Start: Active TS/SCI (U.S. citizenship required)Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)Travel: NoneSalary Range: $78,000 – $86,000 Adversaries are already inside somebody's enterprise. Make sure it isn't this one.RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.What You Will DoAnalyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.Turn intelligence and incident reporting into deployed detection logic.Run regular Purple Team exercises and continuously validate countermeasures already deployed.Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.What You'll BringU.S. citizenship and an active TS/SCI.Ability to successfully obtain and maintain a Government polygraph after hire.Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.8+ years of related advanced cyber security analytics experience.A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.Data mining or query building in a SIEM.Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.Static file signatures (magic numbers) and good working knowledge of regular expressions.Nice to HaveHex editor comfort; Python, Bash, or PowerShell scripting.Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.About RISARolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.BenefitsMedical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.RISA is an Equal Opportunity Employer.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Cyber Threat Detection Engineer (SIEM / Signatures) in Saint Louis, MO vacancy
  • RISA is hiring a Cyber Threat Detection Engineer (SIEM / Signatures) in St. Louis, MO on site. You will develop and tune detection logic, run Purple Team exercises, and collaborate with the Cyber Data Analytics team to improve SIEM efficiency. The role requires active... 
    Cyber

    RISA

    Saint Louis, MO
    2 days ago
  •  ...protect our country from threats. Job...  ...Events Management (SIEM) capability (i.e. Enterprise...  ...platform, and the cyber threat intelligence capability, signature development and...  ...threshold of 99.99% Detect and ticket...  ...Perform all development, engineering, testing, integration... 
    Cyber
    For contractors

    General Dynamics Information Technology

    Saint Louis, MO
    more than 2 months ago
  •  ...collaborating with Focused Operations and other teams to proactively prevent compromises and eradicate persistent adversaries. Responsibilities include tuning SIEM signatures, analyzing incident data, and supporting Purple Team exercises. #J-18808-Ljbffr D2 Consulting
    Cyber

    D2 Consulting

    Saint Louis, MO
    2 days ago
  •  ...cybersecurity analyst with an active TS/SCI clearance to join the Defensive Cyber Operations team in the United States. You will develop and maintain defensive countermeasures, tune SIEM detections, and coordinate with Purple Teaming exercises to prevent and eradicate... 
    Cyber

    D2 Technical Services

    Saint Louis, MO
    2 days ago
  •  ...OverviewMiTek is looking for a Cyber Threat Analyst to join our...  ...investigations from initial detection through closure.ResponsibilitiesInvestigate...  ...and analyze alerts from SIEM, EDR, DLP, and other...  ...delivers software, services, engineered products, and automated solutions... 
    Cyber
    Full time
    Temporary work
    Work at office
    Worldwide

    MiTek Industries

    Chesterfield, MO
    3 days ago
  •  ...insurance Description We are seeking a SOAR engineer to display a strong background in security operations, threat detection, and security engineering. Responsible for key...  ...Stack or Splunk Experience supporting Defensive Cyber Operations Experience with integrating with... 
    Cyber

    IQUASAR LLC

    Saint Louis, MO
    4 days ago
  •  ...Pre-Sales Systems Engineer We are looking for a Pre-Sales Systems Engineer...  ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident...  ...Network operations Breach detection and prevention Security... 
    Cyber
    Worldwide

    Edelman

    Saint Louis, MO
    5 days ago
  • $72.12 - $84.14 per hour

     ...Job Title Systems Engineer Overview EverWatch is a government...  ...skillset into areas like SIEM platforms, stream processing...  ...experience in defensive cyber operations, cybersecurity...  ...routing Experience architecting detection engineering pipelines, threat hunting workflows, and... 
    Cyber
    Hourly pay
    Contract work
    Local area

    EverWatch

    Swansea, IL
    2 days ago
  •  ...Inside Systems Engineer We are looking for an Inside Systems Engineer...  ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident...  ...Network Operations Breach Detection and Prevention Security Operations... 
    Cyber
    Remote work
    Worldwide
    Home office

    Edelman

    Saint Louis, MO
    5 days ago
  •  ...looking for a Pre-Sales Systems Engineer to work closely with our Mid-Market...  ...common cybersecurity issues, threats, attacks, and vulnerabilities Principles of cyber threat management and incident response...  ...: Network operations Breach detection and prevention Security... 
    Cyber

    Fortinet, Inc.

    Saint Louis, MO
    2 days ago
  • MiTek is seeking a Cyber Threat Analyst to join our Cybersecurity team in Chesterfield, MO. You will investigate, coordinate, and respond...  ..., endpoint security, and strong stakeholder communication skills to drive investigations from detection #J-18808-Ljbffr MiTek
    Cyber

    MiTek

    Chesterfield, MO
    2 days ago
  • $75.2k - $158.1k

     ...Cyber Threat Hunter The Opportunity: CACI is seeking a cyber threat hunter to join our team in supporting the National Geospatial-Intelligence Agency (NGA). This role will proactively search for indicators of compromise on NGA systems and networks. You will conduct... 
    Cyber
    Contract work
    Work experience placement
    Flexible hours

    CACI International

    Saint Louis, MO
    4 days ago
  • $126.82k - $149.2k

     ...location three (3) or more days per week.U.S. Bank is seeking a Cyber Threat Intelligence Lead Analyst to help advance the bank’s cyber...  ...findings to defensive actions across threat hunting, detection engineering, incident response, vulnerability management, and... 
    Cyber
    Full time
    Local area
    3 days per week

    US Bank

    Earth City, MO
    2 days ago
  • $90k - $100k

    D2 Technical Services in St. Louis, MO seeks an Advanced Cyber Security Analytics Engineer with an active TS/SCI clearance to strengthen enterprise defenses. You will analyze data, tune SIEM rules, and collaborate with incident response and purple team activities. Responsibilities... 
    Cyber

    D2 Consulting

    Saint Louis, MO
    1 day ago
  • MiTek Industries is seeking a Cyber Threat Analyst to join our Cybersecurity team. You will investigate incidents across endpoints, identities...  ...guiding containment and remediation efforts. You will analyze SIEM/EDR/DLP alerts, perform log investigations, and communicate... 
    Cyber

    MiTek Industries

    Chesterfield, MO
    4 days ago
  • $90k - $100k

     ...the Branch Chief of Defensive Cyber Operations, you will be...  ...incidents and develop or tune rules/signatures/scripts as needed....  ...Data Analytics team to achieve SIEM alert efficiency though evaluation...  ...use case, as it pertains to detection logic, and identify the corresponding... 
    Cyber
    Work experience placement

    D2 Technical Services

    Saint Louis, MO
    2 days ago
  •  ...SUMMARY The Security Analyst detects, manages and reduces the impact of cybersecurity threats to the organization. They are...  ...equivalent (e.g., Math, Electrical Engineering, Cyber Security) 5+ years of...  ...Information and Event Management (SIEM) CERTIFICATIONS CISSP, CCE, CEH... 
    Cyber

    Indigo Beam LLC

    Saint Louis, MO
    1 day ago
  • $75.2k - $158.1k

     ...Cybersecurity Analytics Engineer IIISt. Louis, MO,...  ...Branch Chief of Defensive Cyber Operations, you will...  ...develop or tune rules/signatures/scripts as needed.* Coordinates...  ...team to achieve SIEM alert efficiency...  ...case, as it pertains to detection logic, and identify the... 
    Cyber
    Contract work
    Work experience placement
    Local area
    Flexible hours

    CACI International Inc.

    Saint Louis, MO
    4 days ago
  •  ...Job Title: Cyber Security Engineer Location: St. Louis, MO Work Model...  ...This role will provide cyber threat intelligence, advanced...  ...cybersecurity analytics, reporting, detection tuning, operational...  ...tuning requests, and custom signature creation to the CSOC and other... 
    Cyber
    Contract work
    Temporary work
    Local area

    System One

    Saint Louis, MO
    a month ago
  • CACI International Inc. seeks a Cyber Threat Hunter to join NGA operations, proactively hunting for indicators of compromise and analyzing Windows, Linux, and network data. You’ll document findings and drive improvements to the agency's security posture through cross‑team... 
    Cyber
    Local area

    CACI International Inc.

    Saint Louis, MO
    2 days ago
  • MiTek Industries, Inc. is seeking a Cyber Threat Analyst to join our Cybersecurity team in an on-site role. You will investigate incidents across endpoints, identities, email, and cloud, and coordinate containment and remediation with IT and business units. The ideal candidate... 
    Cyber

    MiTek Industries, Inc.

    Chesterfield, MO
    4 days ago
  • $105.79k - $141.05k

     ...opening for a Lead Information Security Engineer who will support threat hunting, investigation, and discovery...  ...the internet. Black Lotus Labs has detected and disrupted key evolving threats at...  ...automated detection. Work with cyber operators and senior researchers, when... 
    Cyber
    Full time
    Temporary work
    Work experience placement
    Remote work
    Work from home

    Lumen

    Saint Louis, MO
    4 days ago
  • $132.23k - $176.31k

     ...opening for a Senior Lead Security Engineer that will leverage Lumen’s...  ...of evolving malicious threats, provide mission-relevant intelligence...  .... Black Lotus Labs has detected and disrupted key evolving threats...  ...detection. Work with cyber operators, when requested, to... 
    Cyber
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work

    Lumen

    Saint Louis, MO
    14 hours ago
  • Fortinet, Inc. is seeking a Pre-Sales Systems Engineer to work with the Mid-Market sales teams. The role focuses on enabling sales engagements by analyzing IT goals, crafting Fortinet-based solutions, and delivering accurate presentations to customers and partners. The... 
    Cyber

    Fortinet, Inc.

    Saint Louis, MO
    2 days ago
  • Forward Slash Technology is a St. Louis-based Cyber Security, Information Technology, and Managed Services provider. We are seeking a Senior Systems & Network Engineer to join our St. Louis‑based engineering team. This is a senior‑level, client‑facing individual contributor... 
    Cyber
    Full time
    Work at office

    Forward Slash Technology

    Saint Louis, MO
    3 days ago
  •  ...organization(s). Ensure that protection and detection capabilities are acquired or developed using the IS security engineering approach and are consistent with...  ...enterprise constituency. Manage threat or target analysis of cyber defense information and production of... 
    Cyber

    Calibre Inc

    Saint Louis, MO
    1 day ago
  • $74.8k - $130.9k

     ...possible. Job Description: Parsons is now hiring for a Roadway Engineer II to join our St. Louis team supporting major regional road...  ...years of experience, Parsons is uniquely qualified to deliver cyber/converged security, technology-based intellectual property, and... 
    Cyber
    Local area
    Immediate start
    Worldwide
    Flexible hours

    Parsons Company

    Saint Louis, MO
    4 days ago
  • $120k - $140k

     ...driven cybersecurity, helping organizations stay ahead of evolving threats every day. Darktrace was built on a genuinely differentiated idea: that Adaptive AI could detect and respond to novel, real-time cyber threats. That approach matters more than ever in the era of AI.... 
    Cyber
    Freelance
    Local area

    Darktrace Limited

    Saint Louis, MO
    2 days ago
  • $90.3k - $189.6k

     ...external customer activities with Defensive Cyber Operations-Internal Defensive Measures (...  ...data is available to the NGA CSOC, Insider Threat, and other security‑focused entities...  ...of Security Incident & Event Management (SIEM) and log aggregation concepts. Knowledge of... 
    Cyber
    For contractors
    Work at office
    Flexible hours

    3M HEALTHCARE

    Saint Louis, MO
    4 days ago
  • $120.64k - $197.6k

     ...systems that support critical Defense and Intelligence missions. This position is focused on applying risk management frameworks, engineering security controls, and maintaining system authorizations for cloud and on-prem environments. You'll work closely with other... 
    Cyber
    Relocation
    Relocation package

    Esri

    Saint Louis, MO
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Cyber Threat Detection Engineer (SIEM / Signatures). Be the first to apply!