Detection Engineering SME

Softthink Solutions Inc

Detection Engineering SME

Washington, DC
Full Time
Paid
  • Responsibilities

    Detection Engineering SME Location: Washington, DC Work Authorization: US Citizen

    Role Summary

    The Detection Engineering SME leads the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules. This role ensures SBA’s threat detection posture is modern, comprehensive, and aligned with current adversary techniques.

    Roles & Responsibilities

    · Author detection rules for Google SecOps SIEM.

    · Deploy curated detections and validate rule performance.

    · Build multi-event correlation rules aligned to MITRE ATT&CK.

    · Tune detections to meet false-positive thresholds.

    · Integrate threat intelligence sources into detection logic.

    · Support UEBA risk scoring and insider-threat detection.

    · Provide expert guidance during Detect & Tune and Operationalize phases.

    Professional Experience Required

    · 7+ years of experience in detection engineering, threat hunting, or cyber analytics.

    · Experience authoring SIEM rules and correlation logic.

    · Experience with MITRE ATT&CK, threat intelligence, and adversary emulation.

    · Experience with cloud-native SIEM platforms.

    Educational Qualification

    · Bachelor’s degree in Cybersecurity, Computer Science, or related field.

    Certifications

    · GIAC Detection Engineering (GCTI, GDAT), CISSP, or equivalent preferred.