368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$135k – $150k per year
Location
Remote/Hybrid (United States)
Seniority
Senior · 12+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Ultraviolet Cyber is an enterprise cybersecurity company that provides unified, automated security operations and threat management solutions. The firm offers managed detection and response (MDR), threat intelligence, and security automation services designed to help organizations streamline their security operations centers (SOCs). By synthesizing telemetry across diverse IT environments, it enables enterprises to detect, investigate, and neutralize complex cyber threats in real time.

UltraViolet Cyber is seeking a Senior Security Tools Engineer to support the security tools environment on the Security Tools program. This is a hybrid role based in Oxon Hill, MD, with three days per week onsite. We are seeking a technical resource with experience diagnosing and closing detection and reporting gaps that span multiple security platforms - someone who can work across endpoint, SIEM, and adjacent tools rather than inside a single product. This role will include supporting tool integration initiatives, closing gaps created by tool deprecations or replacements, and supporting security automation across the stack.

The Senior Security Tools Engineer should feel comfortable not only diagnosing cross-tool problems but assisting with escalations and onsite tasks as they arise. We are looking for an experienced engineer who shows initiative and demonstrates strong customer service and communication skills. The candidate will be self-directed, organized, and results-driven. In this role, the candidate will work as a primary technical resource for closing detection and reporting gaps that no single tool can solve on its own.

What You'll Do:

  • Lead cross-tool security engineering efforts, advising on best practices for closing detection and reporting gaps that span multiple platforms
  • Diagnose and resolve reporting and visibility gaps created when a tool in the environment is deprecated, replaced, or reconfigured - for example, reconstructing lost reporting coverage by combining endpoint telemetry with Splunk data
  • Design, implement, and document data flows and integration points across endpoint protection, SIEM, and other security tools supporting the program
  • Build and tune detection logic, correlation searches, and dashboards that hold up as individual tools in the stack change, are replaced, or are retired
  • Lead the technical transition work when a security tool is deprecated, replaced, or reconfigured, ensuring no loss of detection or reporting coverage
  • Integrate tools such as CrowdStrike, Splunk, Cribl, CyberArk, Suricata, Tenable, Tanium, Thales, CASB, Trellix, Axonius, and others to close cross-platform visibility gaps
  • Develop automation and correlation workflows using APIs across the security tool stack to reduce manual reporting and analysis work
  • Support threat hunting and incident response efforts that require correlating evidence across more than one tool or data source
  • Support endpoint and platform security compliance with NIST, FISMA, and agency-specific requirements
  • Maintain current, accurate documentation of tool configurations, data flows, and integration architecture across the stack
  • Serve as the team's point of contact for cross-tool security engineering issues

What You've Done:

  • Ability to attain DHS EOD
  • Master's degree or equivalent, plus 12 years of relevant experience
  • Demonstrated, hands-on experience across more than one security tool category (endpoint/EDR, SIEM, vulnerability management, network detection, or similar)
  • Hands-on experience with an EDR/endpoint platform (e.g., CrowdStrike Falcon) - administration, detection engineering, or response
  • Hands-on experience with Splunk (or an equivalent SIEM) - search, correlation searches, and dashboard/reporting development
  • Demonstrated experience correlating and integrating data across disparate security platforms to close a visibility, detection, or reporting gap
  • Scripting/automation proficiency (Python, PowerShell, or similar) for cross-tool data pipelines and API integrations
  • Experience owning a tool deprecation or migration without losing detection or reporting coverage
  • Effective communicator at all levels, both written and verbal
  • Professional, customer-oriented, and even-keeled under pressure

Preferred Qualifications:

  • Experience supporting federal agency security operations centers
  • Additional security certifications (CISSP, GIAC, Security+)
  • Experience with CrowdStrike's cloud workload protection capabilities
  • Knowledge of CISA directives and CDM program requirements
  • Background in threat hunting and advanced persistent threat detection
  • Experience with security orchestration and automation platforms
  • Familiarity with Zero Trust Architecture implementation

Work Environment:

  • Hybrid work model with 3 day/week on-site presence near National Harbor, Maryland
  • Must be able to pass a Federal background investigation - US Citizenship required
  • Participation in on-call rotation for security incident response

What We Offer:

  • 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
  • Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
  • Group Term Life, Short-Term Disability, Long-Term Disability
  • Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
  • Participation in the Discretionary Time Off (DTO) Program
  • 11 Paid Holidays Annually
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$110k – $130k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
JavaScript
Python
SQL
AI/ML
AI Agents
Human-in-the-Loop
Cybersecurity
HIPAA
Apply
$176k – $203k per year • Remote • Full-Time • 5+ years exp
Assembly
Python
SQL
Apply
$160k – $200k per year • Remote • Full-Time • Bachelor's Degree
Python
SQL
AI/ML
Time Series Forecasting
Analytics
A/B Testing
Marketing
Amplitude
Mixpanel
Apply
$133k – $161k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Westminster
C++
Python
DevOps
CI/CD
SpaceTech
NASA cFS
Apply
$134k – $241k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
JavaScript
Python
TypeScript
Node JS
Node JS
Axios
Databases
ElasticSearch
Frontend
Vue.js
DevOps
Terraform
Apply
$94k – $184k per year (Estimated) • Remote/Hybrid • 8+ years exp • Bachelor's Degree • Washington
Python
SQL
AI/ML
Airflow
Prefect
DevOps
AWS
Azure
CI/CD
CloudFormation
GCP
GitHub Actions
Jenkins
Self-Healing
Terraform
GitHub
GitLab
Analytics
ETL/ELT
Apply
$160k – $205k per year • Remote/Hybrid • 12+ years exp • Bachelor's Degree
DevOps
Splunk
Cybersecurity
Qualys Cloud Platform
Zero Trust
Apply
$90k – $130k per year • In office • 4+ years exp • Herndon
PowerShell
Python
DevOps
Ansible
AWS
Azure
Splunk
Apply
$140k – $175k per year • Remote/Hybrid • Full-Time • 7+ years exp • Master's Degree
DevOps
Splunk
Cybersecurity
Crowdstrike
CyberArk
Zero Trust
Apply
$90k – $110k per year • In office • Full-Time • 3+ years exp • High School Diploma • Herndon
DevOps
Ansible
Red Hat
Splunk
VMWare
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.