Detection Engineering SME Location: Washington, DC Work Authorization: US Citizen
Role Summary The Detection Engineering SME leads the development of detection content, including up to 3,500 single-event rules and 200 multi-event correlation rules. This role ensures SBA’s threat detection posture is modern, comprehensive, and aligned with current adversary techniques. Roles & Responsibilities · Author detection rules for Google SecOps SIEM. · Deploy curated detections and validate rule performance. · Build multi-event correlation rules aligned to MITRE ATT&CK. · Tune detections to meet false-positive thresholds. · Integrate threat intelligence sources into detection logic. · Support UEBA risk scoring and insider-threat detection. · Provide expert guidance during Detect & Tune and Operationalize phases. Professional Experience Required · 7+ years of experience in detection engineering, threat hunting, or cyber analytics. · Experience authoring SIEM rules and correlation logic. · Experience with MITRE ATT&CK, threat intelligence, and adversary emulation. · Experience with cloud-native SIEM platforms. Educational Qualification · Bachelor’s degree in Cybersecurity, Computer Science, or related field. Certifications · GIAC Detection Engineering (GCTI, GDAT), CISSP, or equivalent preferred.
Numbers & Facts
Location
Santa Monica, CA
Job Type
Full-time
Skills
Cloud Computingunmatched
Computer Scienceunmatched
Content Developmentunmatched
Cyber Threat Huntingunmatched
Event Correlationunmatched
Internet Securityunmatched
Riskunmatched
Security Information and Event Management (SIEM)unmatched
Small Businessunmatched
United States Citizenunmatched
Web Analyticsunmatched
Writing Skillsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.