Post Job Free
Sign in

Cyber Security Engineer

Company:
Career Listings
Location:
Clinton Township, OH, 43224
Posted:
July 28, 2026
Apply

Description:

Benefits:

401(k)

401(k) matching

Dental insurance

Health insurance

Paid time off

Profit sharing

Training & development

Tuition assistance

Vision insurance

SarelaTech is seeking a Cybersecurity Engineer to support the Defense Logistics Agency (DLA) Enterprise Cyber Security Service Provider (CSSP). The selected candidate will provide technical expertise in the development, implementation, and enhancement of enterprise cybersecurity detection capabilities by designing advanced threat detection use cases, developing SIEM content, and improving cybersecurity monitoring and analytics across government enterprise environments.

Working closely with cybersecurity operations personnel, Threat Detection Analysts, system administrators, cybersecurity tool Subject Matter Experts (SMEs), and government stakeholders, the Cybersecurity Engineer will develop detection logic, automate security processes, enhance SIEM functionality, and improve enterprise visibility into emerging cyber threats while supporting the confidentiality, integrity, availability, and resilience of DLA information systems.

Primary Responsibilities

Research, develop, and implement new cybersecurity threat detection use cases based on emerging threats, threat intelligence, and Threat Detection Analyst recommendations.

Design, develop, and maintain SIEM correlation rules, analytics, dashboards, and detection content to improve enterprise threat detection and monitoring capabilities.

Develop and maintain automation scripts using PowerShell, Python or similar scripting languages to enhance SIEM functionality and streamline cybersecurity operations.

Analyze log sources and data quality to identify gaps in visibility, improve event collection, and optimize enterprise cybersecurity monitoring.

Collaborate with government stakeholders, cybersecurity tool SMEs, and operational teams to identify critical systems, prioritize monitoring requirements, and develop tailored detection signatures.

Evaluate cybersecurity architectures, network traffic, and security telemetry to identify deficiencies in detection capabilities and recommend improvements.

Support continuous improvement of cybersecurity monitoring capabilities by implementing detection methodologies aligned with the MITRE ATT&CK framework and Defense-in-Depth principles.

Prepare technical documentation, implementation guides, operational procedures, and engineering recommendations supporting cybersecurity tool enhancements.

Required Qualifications

Active DoD Top Secret security clearance with SCI eligibility and IT-I access.

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Computer Engineering, or related discipline, or equivalent experience.

Minimum five (5) years of relevant Information Technology experience.

Minimum three (3) years of experience working with a SIEM in a content development, threat detection, or Incident Response role.

Minimum three (3) years of experience as a System Administrator and/or Network Administrator.

Experience developing SIEM correlation rules, threat detection content, or cybersecurity analytics using SPL and KQL query languages.

Strong understanding of enterprise network architecture, cybersecurity monitoring, and log analysis.

Experience developing automation scripts using PowerShell, Python or similar scripting languages.

Strong written and verbal communication skills

Desired Qualifications

Experience supporting the Defense Logistics Agency (DLA), DISA, or other DoD cybersecurity organizations.

Experience supporting Security Operations Center (SOC), Cyber Security Service Provider (CSSP), or Incident Response operations.

Experience working with Splunk Enterprise Security or other enterprise SIEM platforms.

Knowledge of the MITRE ATT&CK framework, Cyber Kill Chain, NIST SP 800-53, NIST SP 800-61, and DISA STIGs.

Experience integrating threat intelligence into SIEM detection content.

Experience developing custom detection signatures, dashboards, automation workflows, or security analytics.

Experience evaluating enterprise log sources, telemetry quality, and security monitoring effectiveness.

Certifications

Required

DoD 8570 IAT Level II certification (Security+, CySA+, SSCP, GSEC, CCNA, GICSP, or equivalent).

DoD 8570 CSSP certification meeting CSSP-IR or CSSP-A requirements.

Preferred

Splunk Core Certified Power User

Splunk Enterprise Security Certified Administrator

GIAC Certified Incident Handler (GCIH)

GIAC Certified Intrusion Analyst (GCIA)

GIAC Certified Enterprise Defender (GCED)

Certified Ethical Hacker (CEH)

Preferred Skills

SIEM engineering and content development

Threat detection engineering

Security analytics

Threat intelligence integration

MITRE ATT&CK framework

Incident Response

Splunk Enterprise Security

Log management and normalization

PowerShell, Python, SPL scripting

Enterprise network architecture

Cybersecurity automation

Technical documentation and engineering design

NIST and DoD cybersecurity standards

Apply