Detection Engineer
Blu Omega LLC is looking for Detection Engineer in Rockville, MD.
This local job opportunity with ID 3846848566 is live since 2026-09-22 11:25:07.
Back Detection Engineer
Cloud/Infrastructure Rockville , Maryland Sep 3, 2026
Detection Engineer
Remote
Blu Omega is seeking a Detection Engineer to support a federal program focused on the protection of critical health systems and data. This role operates within a fully remote environment and is responsible for cybersecurity monitoring and detection activities. The position requires experience supporting security operations and detection engineering within a mission-driven environment.
Program OverviewNIH Cybersecurity Operations Center; protection of critical federal health systems/data; 24/7 enterprise cybersecurity operations
Key DetailsLocation: Remote
Clearance: NIH Public Trust; must be able to obtain and maintain
- Develop and maintain security alerts and detection rules within Splunk
- Write and modify SPL queries to identify suspicious or potentially malicious activity
- Create and maintain Splunk dashboards, reports, and security analytics
- Review and tune existing detections to improve accuracy and reduce false positives
- Support phishing detection and analysis using Cofense Triage or similar tools
- Assist with the development and maintenance of YARA rules
- Use SnapAttack and other security tools to support detection development and analysis
- Leverage built-in security analytics and detections across cybersecurity tools
- Support threat hunting and investigation of suspicious activity
- Apply MITRE ATT&CK concepts to understand attacker behaviors and detection coverage
- Work with SOC analysts, incident responders, and other cybersecurity team members to improve monitoring and detection capabilities
- Document detection rules, queries, dashboards, and investigative procedures
- 2+ years of cybersecurity experience, including security monitoring, SOC operations, SIEM, threat hunting, incident response, or detection engineering
- Experience working with Splunk or a comparable SIEM platform
- Familiarity with Splunk Processing Language (SPL) and security-focused searches or queries
- Understanding of common cybersecurity threats and attacker techniques
- Experience reviewing or investigating cybersecurity alerts
- Strong analytical, troubleshooting, and communication skills
- Experience developing or tuning security detections in Splunk
- Familiarity with YARA rules
- Experience with Cofense Triage or phishing analysis
- Familiarity with SnapAttack
- Knowledge of MITRE ATT&CK
- Experience with threat hunting, endpoint security, or incident response
- Federal cybersecurity experience
- Security certification such as Security+, CySA+, CEH, or similar
$70,000.00 - $90,000.00
#CJ#LI-Remote
#J-18808-Ljbffr