Talent.com
AWS Detection Engineer

AWS Detection Engineer

Leidos IncScott Air Force Base, IL, United States
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Description

We are seeking an AWS Detection Engineer to join our team in support of the GSM-O II effort. This position allows a hybrid schedule, and candidates can work out of Scott AFB, IL; Whitehall, OH; or Hill AFB, UT on their on-site days.

The Cyber Security Analyst / AWS Detection Engineer develops SIEM / SOAR capabilities to support the team's Cyber Security Service Provider (CSSP) services. This will include developing, implementing, testing, and executing detection capabilities for AWS security monitoring using Elastic and Splunk.

A successful candidate will have experience in cyber analysis / incident response and SIEM / SOAR development. Candidates with experience using Elastic and Splunk within AWS environments will be able to apply that knowledge while analyzing and responding to cyber threats and warnings.

PRIMARY RESPONSIBILITIES :

  • Work with site threat emulation / analytic development team to maximize detection opportunities referenced to the MITRE ATT&CK framework.
  • Develop, implement, and test analytics using Elastic and Splunk to detect malicious actor activity within AWS IaaS environments.
  • Review operation and threat reports to determine detection improvement opportunities.
  • Provide analyst training opportunities using test environments and emulations of malicious activity.
  • Assist / advise other teams within DISA Global on their cloud security missions as needed.

BASIC QUALIFICATIONS :

  • Active DoD Secret security clearance and ability to obtain TS / SCI
  • DoD 8570 IAT level II or higher certification such as CompTIA Security+ CE, CySA+, ISC2 SSCP, SANS GSEC prior to starting.
  • DoD 8570 CSSP-A level Certification such as CEH, CySA+, GCIA or other certification is required within 180 days of hire.
  • Demonstrated commitment to training, self-study and maintaining proficiency in the technical cyber security domain and an ability to think and work independently.
  • Bachelor's degree and 4+ years of prior relevant experience; additional work experience or Cyber courses / certifications may be substituted in lieu of degree.
  • Knowledge of architecture, engineering, and operations of Elastic and / or Splunk.
  • Understanding of AWS cyber security monitoring tools such as CloudWatch, GuardDuty, VPC Flow logs, and Security Hub.
  • Strong written and oral communications skills and strong analytical and troubleshooting skills.
  • An ability to think critically and work independently.
  • PREFERRED QUALIFICATIONS :

  • CND experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization
  • Experience with Azure, Google Cloud Platform (GCP), or Oracle Cloud Infrastructure is desirable.
  • Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
  • Advanced understanding of TCP / IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth and common security elements.
  • Unix / Linux command line experience.
  • Experience with automation templates such as CloudFormation, ARM template, or terraform.
  • Scripting and programming experience such as PowerShell, bash, or python.
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.
  • Familiarity or experience in Intelligence Driven Defense and / or Cyber Kill Chain methodology.
  • Existing 8570 CSSP Analyst Certifications (CEH), CySA+, etc.
  • Familiarity or experience using cybersecurity frameworks such as MITRE ATT&CK, CIS Controls, NIST CSF, or CSA CCM.
  • At Leidos, we don't want someone who "fits the mold"-we want someone who melts it down and builds something better. This is a role for the restless, the over-caffeinated, the ones who ask, "what's next?" before the dust settles on "what's now."

    If you're already scheming step 20 while everyone else is still debating step 2... good. You'll fit right in.

    Original Posting : September 10, 2025

    For U.S. Positions : While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

    Pay Range :

    Pay Range $85,150.00 - $153,925.00

    The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

    serp_jobs.job_alerts.create_a_job

    Detection Engineer • Scott Air Force Base, IL, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    Hunter Engineering CompanyBridgeton, MO, US
    serp_jobs.job_card.full_time
    Looking to build your career with a company that values.This position follows a fully onsite work schedule (5 days in the office). Candidates who are not currently located in the St.Louis area must ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Endpoint Security Engineer

    Endpoint Security Engineer

    General Dynamics Information TechnologySt Louis, MO, United States
    serp_jobs.job_card.full_time
    Clearance Level Must Be Able to Obtain : .Intelligence Operations and Analysis.Cybersecurity,Host Based Security System (HBSS),Linux. GDIT has an exciting opportunity as subcontractor within the Natio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Endpoint Security Engineer

    Endpoint Security Engineer

    Cherokee FederalSt Louis, MO, United States
    serp_jobs.job_card.full_time
    This position requires an active.TS / Sensitive Compartmental Information (SCI).We are seeking an experienced Endpoint Security Engineer to support enterprise cyber defense initiatives.The ideal cand...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer, Senior

    Security Engineer, Senior

    BOOZ, ALLEN & HAMILTON, INC.O'Fallon, IL, United States
    serp_jobs.job_card.full_time +1
    Are you looking for an opportunity to share your experience in network and system security to safeguard our nation? As a systems security and network security engineer, you can identify the tool, s...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Surveillance Agent

    Surveillance Agent

    Boyd GamingSaint Charles, MO, US
    serp_jobs.job_card.full_time
    Boyd Gaming Corporation has been successful in gaming jurisdiction in which we operate in the United States and is one of the premier casino entertainment companies in the United States.Never conte...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    TS / SCI-Cloud Engineer

    TS / SCI-Cloud Engineer

    Bailey Information Technology, LLCSt Louis, MO, United States
    serp_jobs.job_card.full_time
    Bailey Information Technology, LLC is recruiting for an experienced AWS Cloud Engineer to work on a cloud development and deployment team. The team is involved in the deployment and maintenance of m...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Surveillance Agent

    Surveillance Agent

    Fairmount Park Casino & RacingCollinsville, IL, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Responsible for maintaining close, continuous surveillance of all gaming areas, racing areas and the surrounding property to secure safety and property assets. Always monitor all areas of the proper...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer

    Security Engineer

    CaleresClayton, MO, United States
    serp_jobs.job_card.full_time
    Founded in 1878, Caleres, originally known as Brown Shoe Company, is a global footwear company comprised of some of the world's most loved brands including Famous Footwear, Sam Edelman, Naturalizer...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Endpoint Security Engineer

    Senior Endpoint Security Engineer

    D2 ConsultingSt Louis, MO, United States
    serp_jobs.job_card.full_time
    ACTIVE TS / SCI SECURITY CLEARANCE REQUIRED • •.Are you passionate about cybersecurity and ready to make a mission impact? D2 is growing, and we're looking for a. Senior Endpoint Security Engineer.Natio...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Data Engineer - Direct-Hire

    Data Engineer - Direct-Hire

    The Timberline Group CompanyShiloh, IL, United States
    serp_jobs.job_card.permanent
    Direct Hire - Candidates will need to be able to get a Secret clearance - so US Citizens only.Hybrid so you will need to live within a reasonable commute to SAFB (Scott Airforce Base - in Shiloh Va...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    API Security Engineer

    API Security Engineer

    eTeamSt Louis, MO, United States
    serp_jobs.job_card.full_time
    The API Security Engineer is responsible for securing APIs across the organization's systems and services.This role involves identifying and mitigating vulnerabilities, monitoring API activity, and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Engineer I

    Engineer I

    Boyd GamingSaint Charles, MO, US
    serp_jobs.job_card.full_time
    Boyd Gaming Corporation has been successful in gaming jurisdiction in which we operate in the United States and is one of the premier casino entertainment companies in the United States.Never conte...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    6M04I2 (6M4) - Product Security Engineering 2-6M4 - Product Security Engineer

    6M04I2 (6M4) - Product Security Engineering 2-6M4 - Product Security Engineer

    Innova SolutionsSt Charles,Missouri,United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    A client of Innova Solutions is immediately hiring for a.Position Type : Full Time (Contract).Assess organization-wide security and privacy risk and update assessment results on an ongoing basis.Per...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Security Engineer - Endpoint Protection

    Senior Security Engineer - Endpoint Protection

    TRGMaryland Heights, MO, United States
    serp_jobs.job_card.full_time
    Seeking a highly skilled and experienced Senior Security Engineer focused on Endpoint security / EDR to join our cyber security team. The ideal candidate will have a primary expertise in SentinelOne a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security Engineer - IAM Analyst

    Senior Security Engineer - IAM Analyst

    Edward JonesSaint Louis, MO, United States
    serp_jobs.job_card.full_time
    And see your ideas come to life.It's an exciting time to work in tech at Edward Jones.We are making massive investments in emerging technologies to improve how we work with our clients and with eac...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Cloud DevOps Engineer (Hybrid) - TS / SCI Required

    Cloud DevOps Engineer (Hybrid) - TS / SCI Required

    Phoenix Operations GroupSaint Louis, MO, US
    serp_jobs.job_card.full_time
    Leverage AWS and CI / CD technologies to streamline and maintain a DevSecOps pipeline for mission critical-software applications. Since most of the work is conducted remotely (from home), this highly ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer, Senior

    Security Engineer, Senior

    Booz Allen HamiltonO'Fallon, IL, United States
    serp_jobs.job_card.full_time +1
    Are you looking for an opportunity to share your experience in network and system security to safeguard our nation? As a systems security and network security engineer, you can identify the tool, s...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    AWS GenAI Pre-Sales Architect

    AWS GenAI Pre-Sales Architect

    InterVision SystemsSaint Louis, MO, US
    serp_jobs.job_card.full_time
    Are you looking for a challenging role as an AWS GenAI Pre-Sales Architect?.As a leading managed service provider (MSP), InterVision assists IT leaders in solving the most crucial challenges they f...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Security Engineer III

    Security Engineer III

    Safety NationalSt. Louis, Missouri, United States
    serp_jobs.job_card.full_time
    At Safety National, we don't just offer jobs - we build careers with purpose! Since 1942, we've been an industry leader, valuing integrity, teamwork, and stability while providing competitive rewar...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Data Engineer - Clearance Required

    Data Engineer - Clearance Required

    Logistics Management InstituteScott Air Force Base, IL, United States
    serp_jobs.job_card.full_time
    LMI is seeking a skilled Data Engineer to work at the site of a government customer.The position requires reviewing, ingesting, and transferring Joint Petroleum Enterprise (JPE) fuels data, develop...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days