Loading jobs…
Loading jobs…
Berkadia Commercial Mortgage, LLC — McLean Virginia
Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
Description Title: Cyber Detection Engineer Location: Remote Terms: Full-time Salary: $125 - $140k DOE Clearance: Public Trust Travel: 10% Position Description As a Cyber Detection Engineer, you will play a critical role in safeguarding the Department of Veterans Affairs (VA) digital assets by developing and implementing security detections for our Cyber Incident Response team to monitor. Your primary focus will be to baseline, develop, implement, and tune security detections using a variety of technologies such as SIEM, EDR, XDR, etc.
What You'Ll Do
Configure monitoring tools to detect threat actor techniques and/or behavioral indicators. Craft custom search queries using Splunk, Microsoft Defender for Endpoint, Microsoft Sentinel, CrowdStrike Falcon, and Elastic. Provide subject matter expertise to support security detections in one of the following areas: Cloud Technologies, SaaS, Identity and Access Management, Networking, Splunk, EDR, or Offensive Security and Purple-teaming.
Map security detections to the MITRE ATT CK Framework. Research new data source identification and configuration recommendations to facilitate detection of adversary activities. Use machine learning and pattern analysis to improve detection of specific types of threats.
Collaborate effectively with cross-functional teams, including forensics, threat intelligence, IT, and network administrators. Clearly communicate technical information and detection-related updates to management and stakeholders. Develop and operationalize advanced security analytics to detect and respond to sophisticated cyber threats in real-time.
, tuning false positives, etc. Ensure data quality meets completeness and consistency. Monitor the performance of security analytics and automation processes regularly, identifying areas for improvement and taking proactive measures to enhance their efficacy.
Leverage Security Orchestration, Automation, and Response (SOAR) platforms to streamline and automate detection and incident response, including enrichment, containment, and remediation actions. Support the operationalization of new security detections, including building reference documentation, investigation guidelines, and tuning considerations. Stay informed about the latest cybersecurity threats, trends, and best practices.
Actively participate in cybersecurity exercises, drills, and simulations to improve incident response capabilities.
Requirements
): Bachelor's degree in computer science, Cybersecurity, Information Technology, or a related field (or equivalent work experience) 5+ years of experience supporting large-scale IT related projects 3+ years of experience supporting incident response in an enterprise-level Security Operations Center (SOC) Candidates should possess a professional level certification in one of the following subject areas: Cloud (ex: GLCD), Incident Response/Forensics (ex: GCIH, GCFE), IDAM (ex: Microsoft Identity and Access Administrator Associate), SIEM (Splunk Power User), Offensive Security (ex: OSCP, GPEN) A deep understanding of cybersecurity principles, incident response methodologies, and a proactive mindset to ensure our SOC operates effectively in a high-pressure environment
Nice To Have (Differentiators)
: Strong experience with security technologies, including SIEM, IDS/IPS, EDR, and network monitoring tools Experience with enterprise ticketing systems like Servi