More jobs:
Cyber Security Detections Engineer Springfield, VA
Job in
Springfield, Fairfax County, Virginia, 22161, USA
Listed on 2026-06-03
Listing for:
McIntire Solutions
Full Time
position Listed on 2026-06-03
Job specializations:
-
IT/Tech
Cybersecurity, Network Security
Job Description & How to Apply Below
Overview
Cyber Security Detections Engineer job at McIntire Solutions in Springfield, VA.
Seeking a motivated, career- and customer-oriented Cyber Security Engineer, Senior, to join our team in Springfield, VA area.
Responsibilities- Support Cyber Operations Squadron (COS) activities to publish up-to-date cybersecurity tool signatures (e.g. anti-virus and host-based security systems)
- Provide focused analysis, including reverse malware engineering, against intrusion, anomalies, malware, and viruses to identify critical information about source, intended target, affected systems or hosts, recommended mitigation measures, and risk to mission
- Formulate custom Security Information and Event Management (SIEM) tool content and IDS/IPS signatures to address threats
- Perform security event and incident correlation using information gathered from a variety of sources within the enterprise
- Analyze and assess damage to the data/infrastructure as a result of cyber incidents
- Perform cyber incident trend analysis and reporting
- Characterize and perform analysis of network traffic and system data to identify anomalous activity and potential threats to resources
- Provide detection, identification, and reporting of possible cyber-attacks/intrusions, anomalous activities, and misuse activities
- Create and deploy threat-based signatures for operational intrusion detection capabilities
- Create and implement detection rules from intelligence reporting
- Bachelor’s Degree or 4+ years of additional cyber experience in lieu of degree
- 5+ years of experience in a cyber role
- Experience with modern Windows, UNIX, network operating systems, databases, and virtual computing
- DoD 8570 certification meeting IAT Level II (GSEC, Security+, SSCP, or CCNASecurity) required
- CNDSP-A (GCIA, GCIH, or CEH) or CNDSP-IR (GCIH, CSIH, or CEH) certification required
- Experience performing analysis of network traffic and correlating diverse security logs to make recommendations for signature development
- Knowledge of implementation of counter-measures or mitigating controls
- Ability to support incident response and forensic operations, including static/dynamic malware analysis and reverse engineering
- Experience with enterprise security tools, including Security Information and Event Management (SIEM), Threat Intelligence Platforms (TIPs), or network monitoring tools
- Experience in creating, modifying, tuning IDS signatures/SIEM correlation searches and other detection signatures
- Proficient in Linux operating systems
- Advanced skills in Linux/Unix (command line user - proficient and used in last 6 months)
- Working knowledge of current COTS Cybersecurity technologies
- Familiar with MITRE ATT&CK Framework
- TS/SCI w/Poly
- Must be able to remain in a stationary position 50%
- Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine, and computer printer
- The person in this position frequently communicates with co-workers, management, and customers, which may involve delivering presentations
- Must be able to exchange accurate information in these situations
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×