> Markdown version of [/jobs/ext/499947-cybersecurity-detection-engineering-lead](https://www.wearedevelopers.com/jobs/ext/499947-cybersecurity-detection-engineering-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Detection Engineering Lead - **Company:** Gunnison Consulting Group Inc - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $145,000.0 - $155,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Big Data, Configuration Management, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Security Information and Event Management, Scripting, Cyber Threat Analysis, Information Technology, Cybercrime, Microsoft Sentinel, Splunk, Blue Team (Cyber Security) - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=aa2cb302b758340d ## About the Role Do you have experience in Threat intelligence?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Technology, or related field * Minimum of 5 years of experience in incident response or SOC operations, including at least 3 years focused on detection engineering, threat hunting, or adversary emulation * At least 3 years of experience developing hypotheses, querying large datasets, and identifying advanced threat behaviors * Minimum of 2 years of experience with scripting languages such as Python and PowerShell * At least 2 years of experience developing detection logic in SIEM platforms such as Splunk Enterprise Security or Microsoft Sentinel * Certification required: OSCP or GXPN Clearance Requirement: Ability to obtain and maintain a Public Trust. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description * Lead detection engineering activities supporting cybersecurity monitoring and defense for the federal customer * Oversee the full lifecycle of detection development, including research, testing, deployment, tuning, and maintenance * Research emerging threats, adversary capabilities, and attack methodologies to improve detection coverage * Develop, validate, and deploy SIEM detections, correlation rules, and analytic workflows * Manage and maintain risk-based alerting frameworks to prioritize critical threats * Conduct regular reviews of alert performance, including analysis of false positives and tuning opportunities * Document detection logic, configurations, and implementation procedures * Collaborate with threat hunting, intelligence, and incident response teams to operationalize threat insights * Develop new detections in response to emerging threats, vulnerabilities, and operational priorities * Ensure timely implementation of critical detections within defined SLAs * Evaluate new telemetry sources and security alerts for detection value and operational impact * Track detection changes and enhancements through Agile workflows and ticketing systems * Produce operational reports summarizing detection performance and improvements * Maintain configuration management and documentation repositories * Recommend improvements for telemetry collection, log visibility, and monitoring effectiveness * Coordinate with Blue Team to incorporate findings from adversary simulations and exercises * Deliver briefings and reports to technical teams and leadership * Support transition and operational readiness activities ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Alibaba Big Data and Machine Learning Technology](https://www.wearedevelopers.com/videos/37-alibaba-big-data-and-machine-learning-technology) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london)