559,526open jobs
21,701companies
76,702added this week
Browse all
Salary
$100k – $160k per year
Location
In office (Ogden)
Seniority
Middle · 4+ years exp
Overview
Company
Impact
Profile match

Dark Wolf  is looking for a Threat Detection Engineer to design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.

Key Responsibilities:

  • Designing, building, testing, and deploying robust detection logic using a "Detection-as-Code" methodology across on-prem and cloud-hosted AWS GovCloud environments
  • Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior
  • Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environments
  • Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs mapped against the MITRE ATT&CK Cloud Matrix
  • Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident response playbooks within GitLab pipelines
  • Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity, reduce noise, and optimize detection rules
  • Utilizing AI-assisted analysis and ML features to enhance query generation, automate threat intelligence correlation, and streamline detection development
  • Participating in the development of DCO concept of operations, processes, and procedures
  • Supporting vulnerability management mitigations, adhere to defined policies and schedules, and complete all required training and disclosures as outlined by BSTG.
  • Participating in the development of DCO tactics, techniques, and procedures (TTPs), threat models, and supporting technical documentation.

Required Qualifications:

  • 4+ years of relevant experience
  • 2+ years of hands-on experience authoring and tuning detection logic in Splunk Enterprise and the ELK Stack (Elasticsearch, Logstash, Kibana).
  • 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures to include assessment and authorization activities.
  • Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
  • Direct experience ingesting, normalizing, and engineering detections for AWS GovCloud security telemetry (CloudTrail, VPC Flow Logs, GuardDuty, EKS Audit Logs).
  • Demonstrated experience using GitLab for Detection-as-Code, CI/CD pipelines, version control, and DevSecOps workflows.
  • Department of Defense Directive (DoDD) 8140 (formerly DoDD 8570) IAT CSSP Certification must be obtained prior to hire (CEH, CCNA Security, GCIH, CySA+ or Equivalent).
  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • US Citizenship and an active Top Secret/SCI security clearance required.

Desired Qualifications:

  • Experience managing detections as code using Infrastructure as Code (IaC) tools like Terraform or CloudFormation.
  • Familiarity with container runtime security (e.g., Falco, eBPF, Docker security) and Kubernetes threat modeling.
  • Experience with RHEL
  • Experience in performing post-incident computer forensics without destruction of critical data
  • Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff

The salary range for this position is estimated to be between $100,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

We are strictly looking for direct, full-time W2 employees.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
559,526 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Ogden
$9k – $24k per year (Estimated) • Remote • Full-Time • 2+ years exp • Moscow
SQL
DevOps
Splunk
Logstash
Management
Confluence
Jira
Apply
$25k – $57k per year (Estimated) • In office • Full-Time • 5+ years exp • Taguig
Databases
MySQL
PostgreSQL
Redis
Oracle
MS SQL
MariaDB
DevOps
Terraform
Ansible
GCP
Azure DevOps
CloudFormation
Azure
CI/CD
AWS
FinOps
Apply
$23k – $49k per year (Estimated) • In office • 8+ years exp • Bengaluru
JavaScript
TypeScript
Databases
Apache Kafka
Frontend
Angular
DevOps
Terraform
CI/CD
Docker
Kubernetes
Management
Agile
QA
Selenium
Playwright
Postman
Rest-Assured
SoapUI
Apply
$17k – $37k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Quezon City
Python
PowerShell
DevOps
Splunk
GCP
Prometheus
Azure
AWS
Cortex
Cybersecurity
Microsoft Sentinel
MITRE ATT&CK
IBM QRadar
Google SecOps
Cortex XSOAR
Apply
Cloud Engineer 2 hours ago
$55k – $98k per year (Estimated) • Remote/Hybrid • Bachelor's Degree • Wrocław
Python
PHP
Bash
PHP
WooCommerce
DevOps
Terraform
AWS
Immutable Infrastructure
Configuration Management
Management
Agile
Apply
$160k – $210k per year • In office • TS/SCI • Contractor • 10+ years exp • Bachelor's Degree • Chantilly
Python
C++
Databases
OpenSearch
DevOps
GCP
Istio
OpenTelemetry
Podman
Linkerd
Prometheus
GitLab CI
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Grafana
Cybersecurity
Snyk
OWASP ZAP
SonarQube
Trivy
HashiCorp Vault
Falco
Open Policy Agent
Fortify
Kyverno
Management
Agile
Scrum
Apply
$120k – $170k per year • In office • Top Secret • Contractor • 5+ years exp • Bachelor's Degree • Ogden
Python
JavaScript
TypeScript
SQL
DevOps
Terraform
Ansible
GCP
GitHub Actions
Rancher
GitLab CI
Azure
CI/CD
Jenkins
AWS
Docker
Kubernetes
Configuration Management
Amazon EKS
Management
Agile
QA
Selenium
JMeter
Cypress
Playwright
k6
Apply
$100k – $150k per year • Remote/Hybrid • Secret • Contractor • 5+ years exp • Bachelor's Degree • Herndon
DevOps
GCP
Azure
AWS
Cybersecurity
Nessus
NIST 800-53
Threat Modeling
Apply
DevSecOps Engineer 7 days ago
$160k – $180k per year • In office • TS/SCI • Contractor • 3+ years exp • Bachelor's Degree • Tampa
Databases
Neo4j
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Management
Agile
Apply
$150k – $175k per year • In office • Secret • 5+ years exp • Mountain View
Apply
$56k – $94k per year • In office • Contractor • Ogden
Apply
$76k – $152k per year (Estimated) • In office • Full-Time • 4+ years exp • High School Diploma • Ogden
Apply
$191k – $300k per year • Remote • Full-Time • 4+ years exp • High School Diploma • Portland • Las Vegas • Ogden • Washington • Salt Lake City
Apply
$52k per year • Equity • In office • Full-Time • High School Diploma • Ogden
Management
Telegram
WhatsApp
Apply
$64k – $74k per year • In office • Contractor • Ogden
Apply
See all jobs
This is one of many
559,526 more open roles from verified company boards, updated every day.