Threat Detection Engineer (Cloud Security)
Dark Wolf SolutionsAbout the role
<p><strong data-path-to-node="0" data-index-in-node="0">Dark Wolf</strong> is looking for a <strong data-path-to-node="0" data-index-in-node="37">Threat Detection Engineer</strong> to design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.</p> <p><strong>Key Responsibilities:</strong></p> <ul> <li>Designing, building, testing, and deploying robust detection logic using a "Detection-as-Code" methodology across on-prem and cloud-hosted AWS GovCloud environments</li> <li>Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior</li> <li>Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environments</li> <li>Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs mapped against the MITRE ATT&CK Cloud Matrix</li> <li>Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident response playbooks within GitLab pipelines</li> <li>Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity, reduce noise, and optimize detection rules</li> <li>Utilizing AI-assisted analysis and ML features to enhance query generation, automate threat intelligence correlation, and streamline detection development</li> <li>Participating in the development of DCO concept of operations, processes, and procedures</li> <li>Supporting vulnerability management mitigations, adhere to defined policies and schedules, and complete all required training and disclosures as outlined by BSTG.</li> <li>Participating in the development of DCO tactics, techniques, and procedures (TTPs), threat models, and supporting technical documentation.</li> </ul> <p><strong>Required Qualifications: </strong></p> <ul> <li>4+ years of relevant experience</li> <li>2+ years of hands-on experience authoring and tuning detection logic in Splunk Enterprise and the ELK Stack (Elasticsearch, Logstash, Kibana).</li> <li>2+ years of experience with employment
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s