Security Tools Engineer

Ultraviolet Cyber
Oxon Hill, MD, United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Application Integration Architecture CompTIA Security+ Cyber Security Data Integration Document-Oriented Databases Intrusion Detection and Prevention Python (Programming Language) Automation of Marketing Windows PowerShell Zero Trust Network Access Security Information and Event Management
+10 more
Data Streaming Software Vulnerability Management Scripting Cyberark Tanium Platform Expertise Cybercrime Splunk Data Pipelines Api Management Security Orchestration, Automation & Response

Job description

  • Lead cross-tool security engineering efforts, advising on best practices for closing detection and reporting gaps that span multiple platforms
  • Diagnose and resolve reporting and visibility gaps created when a tool in the environment is deprecated, replaced, or reconfigured - for example, reconstructing lost reporting coverage by combining endpoint telemetry with Splunk data
  • Design, implement, and document data flows and integration points across endpoint protection, SIEM, and other security tools supporting the program
  • Build and tune detection logic, correlation searches, and dashboards that hold up as individual tools in the stack change, are replaced, or are retired
  • Lead the technical transition work when a security tool is deprecated, replaced, or reconfigured, ensuring no loss of detection or reporting coverage
  • Integrate tools such as CrowdStrike, Splunk, Cribl, CyberArk, Suricata, Tenable, Tanium, Thales, CASB, Trellix, Axonius, and others to close cross-platform visibility gaps
  • Develop automation and correlation workflows using APIs across the security tool stack to reduce manual reporting and analysis work
  • Support threat hunting and incident response efforts that require correlating evidence across more than one tool or data source
  • Support endpoint and platform security compliance with NIST, FISMA, and agency-specific requirements
  • Maintain current, accurate documentation of tool configurations, data flows, and integration architecture across the stack
  • Serve as the team’s point of contact for cross-tool security engineering issues

Requirements

The Senior Security Tools Engineer should feel comfortable not only diagnosing cross-tool problems but assisting with escalations and onsite tasks as they arise. We are looking for an experienced engineer who shows initiative and demonstrates strong customer service and communication skills. The candidate will be self-directed, organized, and results-driven. In this role, the candidate will work as a primary technical resource for closing detection and reporting gaps that no single tool can solve on its own., * Ability to attain DHS EOD

  • Master’s degree or equivalent, plus 12 years of relevant experience
  • Demonstrated, hands-on experience across more than one security tool category (endpoint/EDR, SIEM, vulnerability management, network detection, or similar)
  • Hands-on experience with an EDR/endpoint platform (e.g., CrowdStrike Falcon) - administration, detection engineering, or response
  • Hands-on experience with Splunk (or an equivalent SIEM) - search, correlation searches, and dashboard/reporting development
  • Demonstrated experience correlating and integrating data across disparate security platforms to close a visibility, detection, or reporting gap
  • Scripting/automation proficiency (Python, PowerShell, or similar) for cross-tool data pipelines and API integrations
  • Experience owning a tool deprecation or migration without losing detection or reporting coverage
  • Effective communicator at all levels, both written and verbal
  • Professional, customer-oriented, and even-keeled under pressure, * Experience supporting federal agency security operations centers
  • Additional security certifications (CISSP, GIAC, Security+)
  • Experience with CrowdStrike’s cloud workload protection capabilities
  • Knowledge of CISA directives and CDM program requirements
  • Background in threat hunting and advanced persistent threat detection
  • Experience with security orchestration and automation platforms
  • Familiarity with Zero Trust Architecture implementation Work Environment:

  • Hybrid work model with 3 day/week on-site presence near National Harbor, Maryland
  • Must be able to pass a Federal background investigation - US Citizenship required
  • Participation in on-call rotation for security incident response

Benefits & conditions

  • 401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
  • Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
  • Group Term Life, Short-Term Disability, Long-Term Disability
  • Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
  • Participation in the Discretionary Time Off (DTO) Program
  • 11 Paid Holidays Annually UltraViolet Cyber maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect our company’s differing products, services, industries and lines of business. Candidates are typically placed into the range based on the preceding factors. We sincerely thank all applicants in advance for submitting their interest in this position. We know your time is valuable. UltraViolet Cyber welcomes and encourages diversity in the workplace regardless of race, gender, religion, age, sexual orientation, gender identity, disability, or veteran status. If you want to make an impact, UltraViolet Cyber is the place for you!

About the company

UltraViolet Cyber is a leading platform-enabled unified security operations company providing a comprehensive suite of security operations solutions. Founded and operated by security practitioners with decades of experience, the UltraViolet Cyber security-as-code platform combines technology innovation and human expertise to make advanced real-time cybersecurity accessible for all organizations by eliminating risks of separate red and blue teams. By creating continuously optimized identification, detection, and resilience from today’s dynamic threat landscape, UltraViolet Cyber provides both managed and custom-tailored unified security operations solutions to the Fortune 500, Federal Government, and Commercial clients. UltraViolet Cyber is headquartered in McLean, Virginia, with global offices across the U.S. and in India.

UltraViolet Cyber is seeking a Senior Security Tools Engineer to support the security tools environment on the Security Tools program. This is a hybrid role based in Oxon Hill, MD, with three days per week onsite. We are seeking a technical resource with experience diagnosing and closing detection and reporting gaps that span multiple security platforms - someone who can work across endpoint, SIEM, and adjacent tools rather than inside a single product. This role will include supporting tool integration initiatives, closing gaps created by tool deprecations or replacements, and supporting security automation across the stack.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all