> Markdown version of [/jobs/ext/2706177-security-tools-engineer](https://www.wearedevelopers.com/jobs/ext/2706177-security-tools-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Tools Engineer - **Company:** Ultraviolet Cyber - **Location:** Oxon Hill, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Application Integration Architecture, CompTIA Security+, Cyber Security, Data Integration, Document-Oriented Databases, Intrusion Detection and Prevention, Python (Programming Language), Automation of Marketing, Windows PowerShell, Zero Trust Network Access, Security Information and Event Management, Data Streaming, Software Vulnerability Management, Scripting, Cyberark, Tanium Platform Expertise, Cybercrime, Splunk, Data Pipelines, Api Management, Security Orchestration, Automation & Response - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-security-engineer-crowdstrike-ultraviolet-cyber-8904566 ## About the Role The Senior Security Tools Engineer should feel comfortable not only diagnosing cross-tool problems but assisting with escalations and onsite tasks as they arise. We are looking for an experienced engineer who shows initiative and demonstrates strong customer service and communication skills. The candidate will be self-directed, organized, and results-driven. In this role, the candidate will work as a primary technical resource for closing detection and reporting gaps that no single tool can solve on its own., * Ability to attain DHS EOD * Master's degree or equivalent, plus 12 years of relevant experience * Demonstrated, hands-on experience across more than one security tool category (endpoint/EDR, SIEM, vulnerability management, network detection, or similar) * Hands-on experience with an EDR/endpoint platform (e.g., CrowdStrike Falcon) - administration, detection engineering, or response * Hands-on experience with Splunk (or an equivalent SIEM) - search, correlation searches, and dashboard/reporting development * Demonstrated experience correlating and integrating data across disparate security platforms to close a visibility, detection, or reporting gap * Scripting/automation proficiency (Python, PowerShell, or similar) for cross-tool data pipelines and API integrations * Experience owning a tool deprecation or migration without losing detection or reporting coverage * Effective communicator at all levels, both written and verbal * Professional, customer-oriented, and even-keeled under pressure, * Experience supporting federal agency security operations centers * Additional security certifications (CISSP, GIAC, Security+) * Experience with CrowdStrike's cloud workload protection capabilities * Knowledge of CISA directives and CDM program requirements * Background in threat hunting and advanced persistent threat detection * Experience with security orchestration and automation platforms * Familiarity with Zero Trust Architecture implementation Work Environment: * Hybrid work model with 3 day/week on-site presence near National Harbor, Maryland * Must be able to pass a Federal background investigation - US Citizenship required * Participation in on-call rotation for security incident response ## Description * Lead cross-tool security engineering efforts, advising on best practices for closing detection and reporting gaps that span multiple platforms * Diagnose and resolve reporting and visibility gaps created when a tool in the environment is deprecated, replaced, or reconfigured - for example, reconstructing lost reporting coverage by combining endpoint telemetry with Splunk data * Design, implement, and document data flows and integration points across endpoint protection, SIEM, and other security tools supporting the program * Build and tune detection logic, correlation searches, and dashboards that hold up as individual tools in the stack change, are replaced, or are retired * Lead the technical transition work when a security tool is deprecated, replaced, or reconfigured, ensuring no loss of detection or reporting coverage * Integrate tools such as CrowdStrike, Splunk, Cribl, CyberArk, Suricata, Tenable, Tanium, Thales, CASB, Trellix, Axonius, and others to close cross-platform visibility gaps * Develop automation and correlation workflows using APIs across the security tool stack to reduce manual reporting and analysis work * Support threat hunting and incident response efforts that require correlating evidence across more than one tool or data source * Support endpoint and platform security compliance with NIST, FISMA, and agency-specific requirements * Maintain current, accurate documentation of tool configurations, data flows, and integration architecture across the stack * Serve as the team's point of contact for cross-tool security engineering issues ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)