{"schemaVersion":"jobsearcher.job.v1","id":"867eac6663c73c56c02c65ce","url":"https://jobsearcher.com/jobs/867eac6663c73c56c02c65ce","canonicalUrl":"https://jobsearcher.com/jobs/867eac6663c73c56c02c65ce","title":"IT Security Engineer IV","description":"Overview\nIn this role you will design and tune multi-platform detections to reduce false positives and close coverage gaps, collaborating with detection engineers and incident responders. You will implement automation and enrichment pipelines to route alerts into ServiceNow SIR, while contributing to playbooks and detection-as-code practices. You will translate adversary behavior into detection logic and participate in post-incident reviews to drive continuous improvement. This position offers impact through shaping detection capabilities and accelerating secure incident response in a fast-moving SOC environment.\n\nResponsibilitiesDesign, build, and tune detection rules and correlation logic across Splunk, CrowdStrike NG-SIEM/LogScale, Zscaler, and Onyx Security to reduce false positives and close gapsCreate and maintain API- and Lambda-based orchestration pipelines to route alerts into ServiceNow Security Incident Response with context enrichmentCollaborate with Detection Platform Engineering to align detections with data models, ingestion pipelines, and the detection roadmapWork with Incident Responders to identify investigative gaps and translate them into new or refined detection logicSupport playbook development with responders to codify triage steps, escalation criteria, and containment actions into SIR workflowsValidate detections against live data and known TTPs; document tuning decisions and false-positive rationalesParticipate in post-incident lessons-learned reviews and translate findings into detection or playbook updatesMaintain detection-as-code practices: version control, peer review, and change documentation for production logic\nKey requirements4-7 years of total security engineering/detection experienceAt least 2 years of multi-platform detection workHands-on detection engineering in Splunk (SPL) and CrowdStrike NG-SIEM/LogScale (CQL)Experience with API-based integrations and AWS Lambda for security automation/orchestrationExperience with ServiceNow Security Incident Response (SIR) API, field mapping, and workflowsWorking knowledge of Zscaler logging for detectionsFamiliarity with MITRE ATT&CK and translating adversary behavior into detectionsStrong cross-functional communication and collaboration with IR analysts and platform engineersScripting proficiency (Python) for automation and API workcross-functional collaborationanalytical mindsetproactive communicationSplunk SPLCrowdStrike NG-SIEM/LogScale (CQL)Zscaler telemetry","company":"Kforce","rawCompany":"kforce","city":"Springfield","state":"MO","isRemote":false,"isActive":true,"createdAt":"2026-09-15T04:26:52.367Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT Security Engineer IV","description":"Overview\nIn this role you will design and tune multi-platform detections to reduce false positives and close coverage gaps, collaborating with detection engineers and incident responders. You will implement automation and enrichment pipelines to route alerts into ServiceNow SIR, while contributing to playbooks and detection-as-code practices. You will translate adversary behavior into detection logic and participate in post-incident reviews to drive continuous improvement. This position offers impact through shaping detection capabilities and accelerating secure incident response in a fast-moving SOC environment.\n\nResponsibilitiesDesign, build, and tune detection rules and correlation logic across Splunk, CrowdStrike NG-SIEM/LogScale, Zscaler, and Onyx Security to reduce false positives and close gapsCreate and maintain API- and Lambda-based orchestration pipelines to route alerts into ServiceNow Security Incident Response with context enrichmentCollaborate with Detection Platform Engineering to align detections with data models, ingestion pipelines, and the detection roadmapWork with Incident Responders to identify investigative gaps and translate them into new or refined detection logicSupport playbook development with responders to codify triage steps, escalation criteria, and containment actions into SIR workflowsValidate detections against live data and known TTPs; document tuning decisions and false-positive rationalesParticipate in post-incident lessons-learned reviews and translate findings into detection or playbook updatesMaintain detection-as-code practices: version control, peer review, and change documentation for production logic\nKey requirements4-7 years of total security engineering/detection experienceAt least 2 years of multi-platform detection workHands-on detection engineering in Splunk (SPL) and CrowdStrike NG-SIEM/LogScale (CQL)Experience with API-based integrations and AWS Lambda for security automation/orchestrationExperience with ServiceNow Security Incident Response (SIR) API, field mapping, and workflowsWorking knowledge of Zscaler logging for detectionsFamiliarity with MITRE ATT&CK and translating adversary behavior into detectionsStrong cross-functional communication and collaboration with IR analysts and platform engineersScripting proficiency (Python) for automation and API workcross-functional collaborationanalytical mindsetproactive communicationSplunk SPLCrowdStrike NG-SIEM/LogScale (CQL)Zscaler telemetry","datePosted":"2026-09-15T04:26:52.367Z","dateModified":"2026-09-15T04:26:52.367Z","hiringOrganization":{"@type":"Organization","name":"Kforce","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Springfield","addressRegion":"MO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"867eac6663c73c56c02c65ce"},"url":"https://jobsearcher.com/jobs/867eac6663c73c56c02c65ce"}}