1

Cyber Detection Engineer Jobs (NOW HIRING)

Detection Engineering Lead

$104K - $138K/yr

... cyber defense. Learn more at www.dropzone.ai. About the role We're looking for a highly experienced Senior / Principal Detection Engineer to help shape the future of AI-driven security operations.

Sr. Detection Engineer

Scottsdale, AZ · On-site

$105K - $145K/yr

Overall Purpose The Detection Engineer is part of a high‑performance team, responsible for ... Work with incident detection, incident response, cyber threat intelligence, and other teams to ...

Detection Engineer (Cloud)

Charleston, SC · On-site

$52.25 - $69.75/hr

The Detection Engineer collaborates with Defensive Cyber Operations (DCO) Watch Analysts and other teams to ensure timely and effective threat detection, adhering to CJCSM 6510.01B reporting ...

Showing results 41-60

Cyber Detection Engineer information

See salary details

$29.5K

$122.1K

$197.5K

How much do cyber detection engineer jobs pay per year?

As of Sep 14, 2026, the average yearly pay for cyber detection engineer in the United States is $122,108.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,500.00 and $149,500.00 per year, depending on experience, location, and employer.

What are popular job titles related to Cyber Detection Engineer jobs?

For Cyber Detection Engineer jobs, the most frequently searched job titles are:

Cyber Threat Detection Engineer (SIEM / Signatures)

Saint Louis, MO • On-site

RISA
11 - 50 employees

$78K - $86K/yr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 16 days ago


Job description

Cyber Threat Detection Engineer (SIEM / Signatures)


Location: St. Louis, MO - on site


Time Type: Full time, Exempt


Clearance Required to Start: Active TS/SCI (U.S. citizenship required)


Additional Requirement: Must be able to obtain and maintain a Government polygraph (post-hire requirement)


Travel: None


Salary Range: $78,000 – $86,000


Adversaries are already inside somebody's enterprise. Make sure it isn't this one.


RISA is hiring an advanced cybersecurity analytics specialist to develop and maintain the defensive countermeasures protecting an Intelligence Community customer's enterprise. You will work in a Fusion model alongside Focused Operations under Defensive Cyber Operations. This is hunt and detection engineering, not queue-clearing: you write and tune the logic that prevents a compromise and evicts adversaries who are already persistent. You will talk to the owner here, not a recruiting queue.


What You Will Do

  • Analyze trends and patterns to identify and predict previously undiscovered events, then develop or tune the rules, signatures, and scripts that catch them.

  • Turn intelligence and incident reporting into deployed detection logic.

  • Run regular Purple Team exercises and continuously validate countermeasures already deployed.

  • Work with the Cyber Data Analytics team on SIEM alert efficiency, evaluating valid alerts against false positives.

  • Support the Cyber Incident Response Team during live activity, predicting adversary response and locations of compromise to assist triage.

  • Document work in the authorized ticketing system so any stakeholder can reconstruct the analysis.


What You'll Bring

  • U.S. citizenship and an active TS/SCI.

  • Ability to successfully obtain and maintain a Government polygraph after hire.

  • Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10.

  • 8+ years of related advanced cyber security analytics experience.

  • A certification compliant with DoD 8140.01 and 8570.01-M IAT Level III and CSSP Analyst.

  • Data mining or query building in a SIEM.

  • Strong signature development and tuning, and strong network protocol analysis with protocol analyzers.

  • Static file signatures (magic numbers) and good working knowledge of regular expressions.


Nice to Have

  • Hex editor comfort; Python, Bash, or PowerShell scripting.

  • Purple Team tactics; cloud security - visibility gaps, data lakes, and data mining.


About RISA

Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down.


Benefits

Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays.


RISA is an Equal Opportunity Employer.

#J-18808-Ljbffr