Detection Engineer – Threat Hunter

Posted 3 Days Ago
Be an Early Applicant
Arlington, VA, USA
In-Office
170K-190K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Security • Software
The Role
Conduct proactive threat hunting across networks, endpoints, cloud environments, and applications; develop and tune detections using SIEM, EDR/XDR, NDR, Sigma, YARA, and security analytics. Analyze telemetry, threat intelligence, and adversary TTPs; support incident response, forensic investigations, purple-team exercises, and detection validation. Build dashboards, identify visibility gaps, improve detection coverage, and reduce false positives using MITRE ATT&CK and related frameworks.
Summary Generated by Built In
Job Summary & Responsibilities

Everforth ECS is seeking a Detection Engineer – Threat Hunter to join our team in Arlington, VA (Hybrid).  This position is contingent upon award.


We are seeking a highly motivated Detection Engineer / Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise environment. This role combines threat hunting, detection engineering, and security analytics to improve the organization's ability to identify malicious activity before it results in business impact.

The ideal candidate will have experience working within Security Operations Centers (SOC), Incident Response, Detection Engineering, or Threat Hunting teams and possess strong analytical skills, knowledge of adversary tactics and techniques, and expertise in developing high-fidelity security detections.

Key Responsibilities

Threat Hunting

  • Conduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications.
  • Leverage threat intelligence, behavioral analytics, and emerging threat research to develop hunting hypotheses.
  • Investigate anomalous events and indicators that may represent compromise or active threats and translate findings into formal hunt/detection guidance.
  • Document threat hunting methodologies, findings, and recommendations.

Detection Engineering

  • Design, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms.
  • Create and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations.
  • Develop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks.
  • Continuously improve detection coverage using MITRE ATT&CK and industry threat frameworks.
  • Define and validate true-positive criteria and effectively tunes/retires weak detections.

Security Analytics

  • Analyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications.
  • Correlate threat intelligence with internal security data to identify emerging threats.
  • Perform root cause analysis and provide actionable recommendations to improve detection effectiveness.
  • Develop metrics and dashboards that measure detection coverage and security monitoring effectiveness.

Incident Response Support

  • Partner with Incident Response and SOC teams during active investigations.
  • Provide advanced threat analysis and forensic context during security incidents.
  • Assist with containment, eradication, and recovery efforts when necessary.
  • Create post-incident detection enhancements to prevent adversary re-entry.

Threat Intelligence Integration

  • Consume and operationalize threat intelligence from commercial, government, open-source, and internal sources.
  • Map intelligence findings to security controls and detection opportunities.
  • Identify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs).
  • Collaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.

Continuous Improvement

  • Assess existing detections for effectiveness and false-positive reduction opportunities.
  • Conduct adversary emulation and purple team exercises to validate detection capabilities.
  • Identify visibility gaps and recommend additional logging, telemetry, and monitoring controls.
  • Stay current on emerging cyber threats, attacker methodologies, and detection technologies.

Salary Range: $170,000 - $190,000

General Description of Benefits 


Preferred Qualifications
  • Top Secret Clearance
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.
  • 7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with SIEM platforms and security analytics tools.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry.
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages.
  • Strong critical-thinking, investigative, and problem-solving skills.

Skills Required

  • Top Secret clearance
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience
  • 7+ years of cybersecurity experience
  • Direct experience in threat hunting, detection engineering, security operations, or incident response
  • Strong understanding of attacker tactics, techniques, and procedures
  • Experience with SIEM platforms and security analytics tools
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages
  • Strong critical-thinking, investigative, and problem-solving skills

ECS Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about ECS and has not been reviewed or approved by ECS.

  • Healthcare Strength ECS advertises multiple national-network medical plan options with HSA eligibility alongside dental and vision coverage. Coverage generally begins quickly and is paired with company-paid short- and long-term disability, adding stability to the health package.
  • Retirement Support A 401(k) with Safe Harbor and immediate vesting on employer contributions is emphasized, with an employer match available. Access to an employee stock purchase plan via the parent company provides an additional savings avenue.
  • Parental & Family Support Paid parental leave up to 30 days, adoption assistance, and other family-oriented leaves are highlighted. Feedback suggests these offerings add meaningful value beyond base pay for many roles.

ECS Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Elkhorn, NE
2,129 Employees
Year Founded: 1993

What We Do

ECS, a segment of ASGN (NYSE: ASGN), delivers advanced solutions and services in cloud, cybersecurity, artificial intelligence (AI), machine learning (ML), application and IT modernization, and science and engineering. The company solves critical, complex challenges for customers across the U.S. public sector, defense, intelligence and commercial industries. ECS maintains partnerships with leading cloud, cybersecurity, and AI/ML providers and holds specialized certifications in their technologies. Headquartered in Fairfax, Virginia, ECS has more than 3,400 employees throughout the U.S. and has been recognized as a Top Workplace by The Washington Post for the last five years.

Similar Jobs

Coursera + Udemy  Logo Coursera + Udemy

Fp&a Manager

Artificial Intelligence • Consumer Web • Edtech • Enterprise Web • HR Tech • Social Impact • Generative AI
Remote or Hybrid
United States
1500 Employees
111K-162K Annually

TransUnion Logo TransUnion

Senior Risk Management Analyst

Big Data • Fintech • Information Technology • Business Intelligence • Financial Services • Cybersecurity • Big Data Analytics
Hybrid
4 Locations
13000 Employees
68K-113K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Support Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Leesburg, VA, USA
16000 Employees
15-22 Hourly

Micron Technology Logo Micron Technology

New College Grad - Legacy DRAM Product Yield Enhancement Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
In-Office
Manassas, VA, USA
45000 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account