Cyber Detection Engineer

Leidos UK

Base: $107,900.00 - $195,050.00; bonus/equity: not...
Develop security content (signatures, alerts, rules)
Analyze network and endpoint logs
Utilize mitre att&ck framework
Responsible for in-depth technical analysis of network and endpoint logs & activity, developing signatures, alerts, rules, etc., to improve the security posture of the environment

Job Summary

  • Responsible for in-depth technical analysis of network and endpoint logs & activity, developing signatures, alerts, rules, etc., to improve the security posture of the environment.
  • Proactively and iteratively search through systems and networks to detect advanced threats, and create content to monitor and alert on such activity/threats.
  • Produce high quality technical and non-technical products, briefings, whitepapers, etc., with minimal supervision and emphasis on effective/ accurate reporting on product topics.

Matching Summary

Responsible for in-depth technical analysis of network and endpoint logs & activity, developing signatures, alerts, rules, etc., to improve the security posture of the environment.

Salary

Base: $107,900.00 - $195,050.00; Bonus/Equity: Not specified; Benefits: Not specified

Skills & Requirements

Must-have

  • Develop security content (signatures, alerts, rules)
  • Analyze network and endpoint logs
  • Utilize MITRE ATT&CK framework
  • Proactively search for advanced threats
  • Develop scripts for threat detection

Nice-to-have

  • Experience with DOD, IC or Law Enforcement
  • Understanding of complex Enterprise networks
  • Familiarity with Windows and Linux systems
  • Proficient with Python or PowerShell scripting

Key Requirements

  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field
  • Minimum 8 years of professional experience in incident detection and response, malware analysis, cyber threat hunting, or cyber forensics
  • 2+ years recent experience with host-based and network-based security monitoring
  • Experienced developing scripts for cyber threat detection (VB scripts, Python, C++, HTML, XML)
  • Established experience with incident response and SIEM tools, host-based logs, network-based logs, and regex
  • CompTIA CySA+, GPEN, GWAPT, GSNA, GISF, GXPN, GWEB, GNFA, GMON, GCTI, GOSI, OSCP, OSCE, OSWP, OSEE, CCFP, CISSP, CEH, CHFI, LPT, CSA, ENSA, ECIH, ECSS, ECES (at least ONE required)
  • Top Secret Clearance with ability to obtain Top Secret/SCI

Work Rights

Must have Top Secret Clearance with ability to obtain Top Secret/SCI

Tailored Resume

Cover Letter