×
Register Here to Apply for Jobs or Post Jobs. X

Detection Engineer Lead

Job in Kennewick, Benton County, Washington, 99536, USA
Listing for: K&A Technologies LLC
Full Time position
Listed on 2026-09-25
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 165000 - 190000 USD Yearly USD 165000.00 190000.00 YEAR
Job Description & How to Apply Below

Washington, DC Metro Area | Primarily Remote

Occasional onsite support may be required

K&A Technologies LLC is seeking an experienced Detection Engineering Lead to support a large-scale enterprise cybersecurity program. This role will provide technical leadership across detection engineering, proactive threat hunting, advanced security analytics, and the development of operational documentation and contract deliverables supporting the detection function.

The ideal candidate will have strong hands‑on experience with Splunk Enterprise Security
, advanced SPL development, detection lifecycle management, threat hunting, and identifying sophisticated adversary behavior across large datasets.

Success in this role means building high‑fidelity detections, continuously improving detection coverage, reducing unnecessary alert noise, identifying emerging attacker behavior, and ensuring the detection engineering function is supported by clear, repeatable processes, documentation, and required deliverables.

Responsibilities
  • Lead the development, testing, tuning, deployment, and lifecycle management of security detections within Splunk Enterprise Security (ES).
  • Develop advanced SPL queries, correlation searches, and security analytics using enterprise-scale security telemetry.
  • Conduct hypothesis‑driven threat hunts across endpoint, network, authentication, identity, cloud, and other security data sources.
  • Identify suspicious activity associated with advanced persistent threats, attacker behaviors, and emerging TTPs.
  • Translate threat intelligence, incident findings, and adversary techniques into new or improved detection logic.
  • Map detections and threat‑hunting activities to the MITRE ATT&CK framework and identify gaps in detection coverage.
  • Tune existing detections to improve fidelity, reduce false positives, and provide analysts with actionable investigative context.
  • Develop scripts, automation, enrichment tools, and supporting utilities using Python and Power Shell
    .
  • Develop, maintain, and update Standard Operating Procedures (SOPs), work instructions, playbooks, technical procedures, process documentation, and other required detection engineering deliverables
    .
  • Ensure detection engineering documentation accurately reflects operational processes, technical procedures, roles, responsibilities, and evolving program requirements.
  • Support the preparation, review, and timely completion of recurring and ad hoc contractual or program deliverables assigned to the detection engineering team.
  • Collaborate with SOC analysts, incident responders, threat intelligence personnel, and security engineers to strengthen enterprise detection capabilities.
  • Provide technical leadership, mentorship, and guidance related to detection engineering and threat hunting.
Qualifications
  • Minimum 5 years of Incident Response experience within a large SOC environment supporting more than 5,000 endpoints
    .
  • At least 3 years of experience focused on proactive detection engineering, threat hunting, or adversary emulation
    .
  • At least 3 years of demonstrated experience developing investigative hypotheses, querying large datasets, and identifying sophisticated or APT‑related behavior
    .
  • At least 2 years of hands‑on experience developing detections within a SIEM
    , with strong preference for Splunk Enterprise Security
    .
  • Strong proficiency developing and optimizing Splunk SPL searches and security detections
    .
  • At least 2 years of demonstrated experience using Python and Power Shell to develop security tools, scripts, or automation.
  • Demonstrated ability to develop clear SOPs, work instructions, playbooks, technical documentation, and operational deliverables
    .
  • Strong understanding of threat hunting methodologies, attacker TTPs, incident response, security telemetry, and MITRE…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary