Benefits:
401(k)
401(k) matching
Dental insurance
Health insurance
Paid time off
Profit sharing
Training & development
Tuition assistance
Vision insurance
SarelaTech is seeking a Cybersecurity Engineer to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide technical expertise in the development, implementation, and enhancement of enterprise cybersecurity detection capabilities by designing advanced threat detection use cases, developing SIEM content, and improving cybersecurity monitoring and analytics across government enterprise environments.
Working closely with cybersecurity operations personnel, Threat Detection Analysts, system administrators, cybersecurity tool Subject Matter Experts (SMEs), and government stakeholders, the Cybersecurity Engineer will develop detection logic, automate security processes, enhance SIEM functionality, and improve enterprise visibility into emerging cyber threats while supporting the confidentiality, integrity, availability, and resilience of DLA information systems.
Primary Responsibilities
Research, develop, and implement new cybersecurity threat detection use cases based on emerging threats, threat intelligence, and Threat Detection Analyst recommendations.
Design, develop, and maintain SIEM correlation rules, analytics, dashboards, and detection content to improve enterprise threat detection and monitoring capabilities.
Develop and maintain automation scripts using PowerShell, Python or similar scripting languages to enhance SIEM functionality and streamline cybersecurity operations.
Analyze log sources and data quality to identify gaps in visibility, improve event collection, and optimize enterprise cybersecurity monitoring.
Collaborate with government stakeholders, cybersecurity tool SMEs, and operational teams to identify critical systems, prioritize monitoring requirements, and develop tailored detection signatures.
Evaluate cybersecurity architectures, network traffic, and security telemetry to identify deficiencies in detection capabilities and recommend improvements.
Support continuous improvement of cybersecurity monitoring capabilities by implementing detection methodologies aligned with the MITRE ATT&CK framework and Defense-in-Depth principles.
Prepare technical documentation, implementation guides, operational procedures, and engineering recommendations supporting cybersecurity tool enhancements.
Required Qualifications
Active DoD Top Secret security clearance with SCI eligibility and IT-I access.
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Computer Engineering, or related discipline, or equivalent experience.
Minimum five (5) years of relevant Information Technology experience.
Minimum three (3) years of experience working with a SIEM in a content development, threat detection, or Incident Response role.
Minimum three (3) years of experience as a System Administrator and/or Network Administrator.
Experience developing SIEM correlation rules, threat detection content, or cybersecurity analytics using SPL and KQL query languages.
Strong understanding of enterprise network architecture, cybersecurity monitoring, and log analysis.
Experience developing automation scripts using PowerShell, Python or similar scripting languages.
Strong written and verbal communication skills
Desired Qualifications
Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD cybersecurity organizations.
Experience supporting Security Operations Center (SOC), Cyber Security Service Provider (CSSP), or Incident Response operations.
Experience working with Splunk Enterprise Security or other enterprise SIEM platforms.
Knowledge of the MITRE ATT&CK framework, Cyber Kill Chain, NIST SP 800-53, NIST SP 800-61, and DISA STIGs.
Experience integrating threat intelligence into SIEM detection content.
Experience developing custom detection signatures, dashboards, automation workflows, or security analytics.
Experience evaluating enterprise log sources, telemetry quality, and security monitoring effectiveness.
Certifications
Required
DoD 8570 IAT Level II certification (Security+, CySA+, SSCP, GSEC, CCNA, GICSP, or equivalent).
DoD 8570 CSSP certification meeting CSSP-IR or CSSP-A requirements.
Preferred
Splunk Core Certified Power User
Splunk Enterprise Security Certified Administrator
GIAC Certified Incident Handler (GCIH)
GIAC Certified Intrusion Analyst (GCIA)
GIAC Certified Enterprise Defender (GCED)
Certified Ethical Hacker (CEH)
Preferred Skills
SIEM engineering and content development
Threat detection engineering
Security analytics
Threat intelligence integration
MITRE ATT&CK framework
Incident Response
Splunk Enterprise Security
Log management and normalization
PowerShell, Python, SPL scripting
Enterprise network architecture
Cybersecurity automation
Technical documentation and engineering design
NIST and DoD cybersecurity standards