{"schemaVersion":"jobsearcher.job.v1","id":"2f87c96d95388c9e3530386d","url":"https://jobsearcher.com/jobs/2f87c96d95388c9e3530386d","canonicalUrl":"https://jobsearcher.com/jobs/2f87c96d95388c9e3530386d","title":"AOUSC - Detection Engineering Lead","description":"cFocus Software seeks a Detection Engineering Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.\nQualifications:\nActive Public Trust clearance\nB.S. Computer Science, Information Technology, or a related field\n5+ years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on proactive detection engineering, threat hunt, or adversary emulation.\n3+ years of experience with demonstrated proficiency in forming hypothesis, querying large datasets and identifying APT behavior.\n2+ years’ experience with demonstrated proficiency in scripting languages including Python and PowerShell to develop new tools.\n2+ years’ experience with demonstrated proficiency developing detections in a SIEM (utilizing Splunk ES or Microsoft Sentinel).\nThis role most closely aligns with the NICE work role PD-WRL-006 (Threat Analysis).\nActive OSCP or GXPN certification\n\nDuties:\nLead Detection Engineering operations supporting AOUSC Security Operations Division (SOD) mission objectives and defensive cybersecurity operations.\nProvide full lifecycle support for cybersecurity detection engineering activities, including research, testing, implementation, tuning, deployment, and maintenance of detection capabilities.\nResearch emerging cyber threats, adversary capabilities, attack methodologies, and Tactics, Techniques, and Procedures (TTPs) to improve detection coverage and SOC visibility.\nDevelop, test, validate, and deploy new SIEM detection signatures, analytics, rules, and workflows to enhance threat detection capabilities and minimize analyst burden.\nMaintain and manage the Risk Based Alerting (RBA) framework within the Judiciary SIEM environment to ensure effective detection of risky or malicious activity.\nCoordinate weekly meetings with SOC analysts and stakeholders to review alert performance, analyst feedback, false positives, and detection tuning requirements.\nAnalyze all false positive alerts to determine necessary tuning, whitelisting, suppression logic, and gaps in security monitoring or analytics.\nDevelop and maintain detailed documentation for all detection engineering changes, configuration updates, rule logic, workflows, and implementation procedures.\nCoordinate with Threat Hunting, Cyber Threat Intelligence (CTI), Cybersecurity Triage, Incident Response, and Blue Team personnel to operationalize intelligence-driven detections.\nDevelop new alerts and detections in response to emerging cybersecurity threats, active vulnerabilities, malicious campaigns, and government-directed priorities.\nEnsure critical vulnerability-related detections are deployed within required service level timelines, including 24-hour implementation for critical severity alerts.\nConduct analysis and validation of new alerts from security devices and external telemetry sources to determine operational impact, detection value, and analyst workflow considerations.\nTrack all detection engineering changes, modifications, additions, and removals through Jira stories and established Agile workflows.\nDevelop weekly operational reports summarizing security events, alert dispositions, workforce metrics, tuning activities, detection improvements, and outstanding issues.\nDocument and maintain all detection framework changes within configuration files, knowledge management portals, and operational repositories.\nSupport development and implementation of detection engineering execution plans aligned to AOUSC operational priorities, organizational risks, and emerging threat vectors.\nProvide recommendations for improving telemetry collection, log visibility, event correlation, and security monitoring effectiveness across Judiciary systems and cloud environments.\nCollaborate with Blue Team personnel to improve detection coverage associated with Red Team findings, adversary emulation, and cyber exercises.\nPrepare and deliver technical briefings, operational status reports, executive summaries, and stakeholder presentations.\nSupport transition-in, transition-out, operational readiness, and knowledge transfer activities in accordance with AOUSC requirements.\nyLdjnmggcM","company":"Cfocus Software","rawCompany":"cfocus software","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-05-24T15:14:37.623Z","occupations":[{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"922190","title":"Other Justice, Public Order, and Safety Activities","slug":"other-justice-public-order-and-safety-activities"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"AOUSC - Detection Engineering Lead","description":"cFocus Software seeks a Detection Engineering Lead to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.\nQualifications:\nActive Public Trust clearance\nB.S. Computer Science, Information Technology, or a related field\n5+ years within IR in a large SOC (over 5,000 endpoints) with at least 3 years focused on proactive detection engineering, threat hunt, or adversary emulation.\n3+ years of experience with demonstrated proficiency in forming hypothesis, querying large datasets and identifying APT behavior.\n2+ years’ experience with demonstrated proficiency in scripting languages including Python and PowerShell to develop new tools.\n2+ years’ experience with demonstrated proficiency developing detections in a SIEM (utilizing Splunk ES or Microsoft Sentinel).\nThis role most closely aligns with the NICE work role PD-WRL-006 (Threat Analysis).\nActive OSCP or GXPN certification\n\nDuties:\nLead Detection Engineering operations supporting AOUSC Security Operations Division (SOD) mission objectives and defensive cybersecurity operations.\nProvide full lifecycle support for cybersecurity detection engineering activities, including research, testing, implementation, tuning, deployment, and maintenance of detection capabilities.\nResearch emerging cyber threats, adversary capabilities, attack methodologies, and Tactics, Techniques, and Procedures (TTPs) to improve detection coverage and SOC visibility.\nDevelop, test, validate, and deploy new SIEM detection signatures, analytics, rules, and workflows to enhance threat detection capabilities and minimize analyst burden.\nMaintain and manage the Risk Based Alerting (RBA) framework within the Judiciary SIEM environment to ensure effective detection of risky or malicious activity.\nCoordinate weekly meetings with SOC analysts and stakeholders to review alert performance, analyst feedback, false positives, and detection tuning requirements.\nAnalyze all false positive alerts to determine necessary tuning, whitelisting, suppression logic, and gaps in security monitoring or analytics.\nDevelop and maintain detailed documentation for all detection engineering changes, configuration updates, rule logic, workflows, and implementation procedures.\nCoordinate with Threat Hunting, Cyber Threat Intelligence (CTI), Cybersecurity Triage, Incident Response, and Blue Team personnel to operationalize intelligence-driven detections.\nDevelop new alerts and detections in response to emerging cybersecurity threats, active vulnerabilities, malicious campaigns, and government-directed priorities.\nEnsure critical vulnerability-related detections are deployed within required service level timelines, including 24-hour implementation for critical severity alerts.\nConduct analysis and validation of new alerts from security devices and external telemetry sources to determine operational impact, detection value, and analyst workflow considerations.\nTrack all detection engineering changes, modifications, additions, and removals through Jira stories and established Agile workflows.\nDevelop weekly operational reports summarizing security events, alert dispositions, workforce metrics, tuning activities, detection improvements, and outstanding issues.\nDocument and maintain all detection framework changes within configuration files, knowledge management portals, and operational repositories.\nSupport development and implementation of detection engineering execution plans aligned to AOUSC operational priorities, organizational risks, and emerging threat vectors.\nProvide recommendations for improving telemetry collection, log visibility, event correlation, and security monitoring effectiveness across Judiciary systems and cloud environments.\nCollaborate with Blue Team personnel to improve detection coverage associated with Red Team findings, adversary emulation, and cyber exercises.\nPrepare and deliver technical briefings, operational status reports, executive summaries, and stakeholder presentations.\nSupport transition-in, transition-out, operational readiness, and knowledge transfer activities in accordance with AOUSC requirements.\nyLdjnmggcM","datePosted":"2026-05-24T15:14:37.623Z","dateModified":"2026-05-24T15:14:37.623Z","hiringOrganization":{"@type":"Organization","name":"Cfocus Software","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"2f87c96d95388c9e3530386d"},"url":"https://jobsearcher.com/jobs/2f87c96d95388c9e3530386d"}}