ECS

Detection Engineer - Threat Hunter

ECS$170K — $190K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Top Secret Clearance required
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience
  • 7+ years in cybersecurity, focusing on Threat Hunting, Detection Engineering, or Incident Response
  • Deep understanding of attacker tactics, techniques, and procedures (TTPs)
  • Proficiency with SIEM platforms and security analytics tools
  • Familiarity with MITRE ATT&CK and threat hunting methodologies
  • Experience with scripting and automation, preferably in Python or PowerShell

Responsibilities

  • Conduct proactive threat hunting across networks and applications
  • Leverage threat intelligence to derive hunting hypotheses
  • Investigate anomalous events and document findings
  • Design and develop security detection content for various platforms
  • Create and tune detection logic based on adversary TTPs
  • Analyze security telemetry and correlate internal data with threat intelligence
  • Assist Incident Response teams during active investigations

Benefits

  • Top Secret Clearance opportunity
  • Professional development programs
  • Access to the latest security tools and technologies
  • Collaborative team environment
  • Work-life balance with a hybrid model
Full Job Description
Everforth ECS is seeking a Detection Engineer - Threat Hunter to join our team in Arlington, VA (Hybrid). This position is contingent upon award.

We are seeking a highly motivated Detection Engineer / Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise environment. This role combines threat hunting, detection engineering, and security analytics to improve the organization's ability to identify malicious activity before it results in business impact.

The ideal candidate will have experience working within Security Operations Centers (SOC), Incident Response, Detection Engineering, or Threat Hunting teams and possess strong analytical skills, knowledge of adversary tactics and techniques, and expertise in developing high-fidelity security detections.

Key Responsibilities

Threat Hunting
  • Conduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications.
  • Leverage threat intelligence, behavioral analytics, and emerging threat research to develop hunting hypotheses.
  • Investigate anomalous events and indicators that may represent compromise or active threats and translate findings into formal hunt/detection guidance.
  • Document threat hunting methodologies, findings, and recommendations.

Detection Engineering
  • Design, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms.
  • Create and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations.
  • Develop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks.
  • Continuously improve detection coverage using MITRE ATT&CK and industry threat frameworks.
  • Define and validate true-positive criteria and effectively tunes/retires weak detections.

Security Analytics
  • Analyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications.
  • Correlate threat intelligence with internal security data to identify emerging threats.
  • Perform root cause analysis and provide actionable recommendations to improve detection effectiveness.
  • Develop metrics and dashboards that measure detection coverage and security monitoring effectiveness.

Incident Response Support
  • Partner with Incident Response and SOC teams during active investigations.
  • Provide advanced threat analysis and forensic context during security incidents.
  • Assist with containment, eradication, and recovery efforts when necessary.
  • Create post-incident detection enhancements to prevent adversary re-entry.

Threat Intelligence Integration
  • Consume and operationalize threat intelligence from commercial, government, open-source, and internal sources.
  • Map intelligence findings to security controls and detection opportunities.
  • Identify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs).
  • Collaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.

Continuous Improvement
  • Assess existing detections for effectiveness and false-positive reduction opportunities.
  • Conduct adversary emulation and purple team exercises to validate detection capabilities.
  • Identify visibility gaps and recommend additional logging, telemetry, and monitoring controls.
  • Stay current on emerging cyber threats, attacker methodologies, and detection technologies.

Salary Range: $170,000 - $190,000

General Description of Benefits

  • Top Secret Clearance
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.
  • 7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs).
  • Experience with SIEM platforms and security analytics tools.
  • Knowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.
  • Experience analyzing endpoint, network, cloud, and identity-based security telemetry.
  • Familiarity with scripting and automation using Python, PowerShell, KQL, or similar languages.
  • Strong critical-thinking, investigative, and problem-solving skills.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Information Technology Jobs

Find similar Detection Engineer - Threat Hunter jobs: