Detection Engineer Analyst SME

Relocation
Apply
AI Summary

Resource Management Concepts, Inc. is hiring a Detection Engineer Analyst SME to support an active government contract in Quantico, Virginia. The selected applicant will perform a variety of activities including developing detection use cases, reviewing incident reporting, and identifying gaps in logging and detection capabilities.

Key Highlights
Detection use cases development
Incident reporting review
Logging and detection capabilities identification
Key Responsibilities
Develop detection use cases based on current threats, the MITRE ATT&CK framework, and government direction
Review incident reporting to tune related detection use cases as necessary
Review Security information and event management (SIEM)/ Security orchestration, automation, and response (SOAR) incident queue for unnecessary events and alerts and implement corrective actions
Identify gaps in logging and detection capabilities across attack surface
Assist in implementing new log ingestion and verify proper parsing and normalization of data in SIEM/SOAR
Create high fidelity correlation rules, signatures, filters, and automations and maintain low false-positive rate
Technical Skills Required
MITRE ATT&CK framework Security information and event management (SIEM) Security orchestration, automation, and response (SOAR) KQL Snort ePO Yara Microsoft Cloud Security Microsoft Azure Microsoft Defender XDR Microsoft Sentinel Ninja Training Microsoft Defender For Endpoint Ninja Training Microsoft Defender For Identity Ninja Training DoD 8570 IAT Level III certification DoD 8570 CSSP Analyst certification
Benefits & Perks
Competitive paid vacation package
11 paid federal holidays
High-quality, low-deductible healthcare plans
Pet insurance
Competitive 401K package
Paid relocation
Nice to Have
Microsoft SC-XXX Training (certifications)

Job Description


Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America.

RMC is hiring a Detection Engineer Analyst Subject Matter Expert (SME) to support an active government contract in Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government's mission to deny, disrupt, and degrade adversaries' abilities and attempts to disrupt, exploit and attack the information technology (IT) services provided to network users. 

The selected applicant will perform a variety of activities including but not limited to{{:}}

  • Develop detection use cases based on current threats, the MITRE ATT&CK framework, and government direction
  • Review incident reporting to tune related detection use cases as necessary
  • Review Security information and event management (SIEM)/ Security orchestration, automation, and response (SOAR) incident queue for unnecessary events and alerts and implement corrective actions
  • Identify gaps in logging and detection capabilities across attack surface
  • Assist in implementing new log ingestion and verify proper parsing and normalization of data in SIEM/SOAR
  • Create high fidelity correlation rules, signatures, filters, and automations and maintain low false-positive rate

Requirements

Required

  • Active TS/SCI (DoD TOP SECRET clearance with Sensitive Compartmented Information access) eligibility is required.  Applicant selected will be subject to security investigation(s) and must maintain eligibility requirements for access to classified information
  • Bachelor's in IT or Computer Science OR 5 years' supporting DCO and/or network systems and technology
  • DoD 8570 IAT Level III certification
  • DoD 8570 CSSP Analyst certification
  • 5 years' experience with development/refinement of signatures, plays, policies, configurations, scripts and indicators used to identify malicious activity via network and host-based detection on the enterprise network
  • Experience leading operations and maintenance support for an enterprise-level (50k users) network
  • Experience writing signatures (e.g., KQL/Snort/ePO/Yara) for network and host IDS/IPS

Desired

  • Microsoft Cloud Security training is highly recommended
  • Microsoft Azure and Microsoft Defender XDR
  • Microsoft Sentinel Ninja Training
  • Microsoft Defender For Endpoint Ninja Training.
  • Microsoft Defender For Identity Ninja Training
  • Microsoft SC-XXX Training (certifications)

Schedule{{:}} M-F, 5 X 8, between 7{{:}}00am EST and 5{{:}}00pm EST, normally not to exceed 40 hours per week.

This position may require extended or non-standard hours occasionally to support major cyber incidents.  This position is considered essential and may be required to report during hazardous weather, power outages, fuel shortages, pandemics, and other emergencies.

Benefits

At RMC, we're committed to your career growth! RMC differentiates itself from other firms through its investment in our employees. We invest our resources to train, certify, educate, and build our employees.

RMC can offer you a great place to work with a small company feel and give you the experience, tuition assistance, and certifications that will take your career to the next level. We offer Monday to Friday full-time day shift work, and can assist in paid relocation. This also includes a competitive paid vacation package with 11 paid federal holidays. Additionally, we also offer high-quality, low-deductible healthcare plans, pet insurance, and a competitive 401K package.

Salary at RMC is determined by various factors, including but not limited to location, a candidate's specific combination of education, knowledge, skills, competencies, and experience, as well as contract-specific requirements. The current salary range for this position will be $130,000 to $150,000 (annually).


Similar Jobs

Explore other opportunities that match your interests

Restaurant Leader

Networking
•
1h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Raising Cane's Chicken Fingers

United State

Regional IT Services Manager

Networking
•
5h ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

business network consulting -...

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Mid-Senior level

Defense Information Systems Ag...

United State

Subscribe our newsletter

New Things Will Always Update Regularly