{"schemaVersion":"jobsearcher.job.v1","id":"7e4a67a1cf2bae3580ac183d","url":"https://jobsearcher.com/jobs/7e4a67a1cf2bae3580ac183d","canonicalUrl":"https://jobsearcher.com/jobs/7e4a67a1cf2bae3580ac183d","title":"Detection Engineer – Threat Hunter","description":"Everforth ECS is seeking a Detection Engineer – Threat Hunter to join our team in Arlington, VA (Hybrid). This position is contingent upon award.\n\nWe are seeking a highly motivated Detection Engineer / Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise environment. This role combines threat hunting, detection engineering, and security analytics to improve the organization's ability to identify malicious activity before it results in business impact.\n\nThe ideal candidate will have experience working within Security Operations Centers (SOC), Incident Response, Detection Engineering, or Threat Hunting teams and possess strong analytical skills, knowledge of adversary tactics and techniques, and expertise in developing high-fidelity security detections.\n\nKey Responsibilities\n\nThreat Hunting\n\nConduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications.\nLeverage threat intelligence, behavioral analytics, and emerging threat research to develop hunting hypotheses.\nInvestigate anomalous events and indicators that may represent compromise or active threats and translate findings into formal hunt/detection guidance.\nDocument threat hunting methodologies, findings, and recommendations.\n\nDetection Engineering\n\nDesign, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms.\nCreate and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations.\nDevelop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks.\nContinuously improve detection coverage using MITRE ATT&CK and industry threat frameworks.\nDefine and validate true-positive criteria and effectively tunes/retires weak detections.\n\nSecurity Analytics\n\nAnalyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications.\nCorrelate threat intelligence with internal security data to identify emerging threats.\nPerform root cause analysis and provide actionable recommendations to improve detection effectiveness.\nDevelop metrics and dashboards that measure detection coverage and security monitoring effectiveness.\n\nIncident Response Support\n\nPartner with Incident Response and SOC teams during active investigations.\nProvide advanced threat analysis and forensic context during security incidents.\nAssist with containment, eradication, and recovery efforts when necessary.\nCreate post-incident detection enhancements to prevent adversary re-entry.\n\nThreat Intelligence Integration\n\nConsume and operationalize threat intelligence from commercial, government, open-source, and internal sources.\nMap intelligence findings to security controls and detection opportunities.\nIdentify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs).\nCollaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.\n\nContinuous Improvement\n\nAssess existing detections for effectiveness and false-positive reduction opportunities.\nConduct adversary emulation and purple team exercises to validate detection capabilities.\nIdentify visibility gaps and recommend additional logging, telemetry, and monitoring controls.\nStay current on emerging cyber threats, attacker methodologies, and detection technologies.\n\nSalary Range: $170,000 - $190,000\n\nGeneral Description of Benefits\n\nRequirements:\nTop Secret Clearance\nBachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.\n7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.\nStrong understanding of attacker tactics, techniques, and procedures (TTPs).\nExperience with SIEM platforms and security analytics tools.\nKnowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.\nExperience analyzing endpoint, network, cloud, and identity-based security telemetry.\nFamiliarity with scripting and automation using Python, PowerShell, KQL, or similar languages.\nStrong critical-thinking, investigative, and problem-solving skills.\n\nReq Benefits:\nBenefits - Everforth ECS","company":"Everforth Ecs","rawCompany":"everforth ecs","city":"Arlington","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-09-09T09:57:03.643Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"928110","title":"National Security","slug":"national-security"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Detection Engineer – Threat Hunter","description":"Everforth ECS is seeking a Detection Engineer – Threat Hunter to join our team in Arlington, VA (Hybrid). This position is contingent upon award.\n\nWe are seeking a highly motivated Detection Engineer / Threat Hunter to proactively identify, detect, and mitigate advanced cyber threats across the enterprise environment. This role combines threat hunting, detection engineering, and security analytics to improve the organization's ability to identify malicious activity before it results in business impact.\n\nThe ideal candidate will have experience working within Security Operations Centers (SOC), Incident Response, Detection Engineering, or Threat Hunting teams and possess strong analytical skills, knowledge of adversary tactics and techniques, and expertise in developing high-fidelity security detections.\n\nKey Responsibilities\n\nThreat Hunting\n\nConduct proactive threat hunting activities to identify malicious, suspicious, or unauthorized activity across enterprise networks, endpoints, cloud environments, and applications.\nLeverage threat intelligence, behavioral analytics, and emerging threat research to develop hunting hypotheses.\nInvestigate anomalous events and indicators that may represent compromise or active threats and translate findings into formal hunt/detection guidance.\nDocument threat hunting methodologies, findings, and recommendations.\n\nDetection Engineering\n\nDesign, develop, test, and maintain security detection content across SIEM, EDR/XDR, NDR, and cloud security platforms.\nCreate and tune detection logic based on adversary TTPs, threat intelligence, and attack simulations.\nDevelop and maintain Sigma rules, YARA signatures, SIEM queries, analytics rules, and detection playbooks.\nContinuously improve detection coverage using MITRE ATT&CK and industry threat frameworks.\nDefine and validate true-positive criteria and effectively tunes/retires weak detections.\n\nSecurity Analytics\n\nAnalyze large volumes of security telemetry from endpoints, networks, cloud platforms, identity systems, and applications.\nCorrelate threat intelligence with internal security data to identify emerging threats.\nPerform root cause analysis and provide actionable recommendations to improve detection effectiveness.\nDevelop metrics and dashboards that measure detection coverage and security monitoring effectiveness.\n\nIncident Response Support\n\nPartner with Incident Response and SOC teams during active investigations.\nProvide advanced threat analysis and forensic context during security incidents.\nAssist with containment, eradication, and recovery efforts when necessary.\nCreate post-incident detection enhancements to prevent adversary re-entry.\n\nThreat Intelligence Integration\n\nConsume and operationalize threat intelligence from commercial, government, open-source, and internal sources.\nMap intelligence findings to security controls and detection opportunities.\nIdentify threat actor tactics, techniques, procedures (TTPs), and Indicators of Compromise (IOCs).\nCollaborate with Cyber Threat Intelligence teams to enhance security monitoring capabilities.\n\nContinuous Improvement\n\nAssess existing detections for effectiveness and false-positive reduction opportunities.\nConduct adversary emulation and purple team exercises to validate detection capabilities.\nIdentify visibility gaps and recommend additional logging, telemetry, and monitoring controls.\nStay current on emerging cyber threats, attacker methodologies, and detection technologies.\n\nSalary Range: $170,000 - $190,000\n\nGeneral Description of Benefits\n\nRequirements:\nTop Secret Clearance\nBachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent experience.\n7+ years of experience in cybersecurity, with direct experience in Threat Hunting, Detection Engineering, Security Operations, or Incident Response.\nStrong understanding of attacker tactics, techniques, and procedures (TTPs).\nExperience with SIEM platforms and security analytics tools.\nKnowledge of MITRE ATT&CK, Cyber Kill Chain, and threat hunting methodologies.\nExperience analyzing endpoint, network, cloud, and identity-based security telemetry.\nFamiliarity with scripting and automation using Python, PowerShell, KQL, or similar languages.\nStrong critical-thinking, investigative, and problem-solving skills.\n\nReq Benefits:\nBenefits - Everforth ECS","datePosted":"2026-09-09T09:57:03.643Z","dateModified":"2026-09-09T09:57:03.643Z","hiringOrganization":{"@type":"Organization","name":"Everforth Ecs","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Arlington","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7e4a67a1cf2bae3580ac183d"},"url":"https://jobsearcher.com/jobs/7e4a67a1cf2bae3580ac183d"}}