Detection Engineer Analyst Subject Matter Expert (SME) job opportunity at Resource Management Concepts, Inc..



Date2026-03-24T21:15:17.050Z bot
Resource Management Concepts, Inc. Detection Engineer Analyst Subject Matter Expert (SME)
Experience: 5-years
Pattern: Full-time
apply Apply Now
Salary:
Status:

Job

Copy Link Report
degreeGeneral
loacation Quantico, United States
loacation Quantico....United States
Auto GPT Summarize Enabled

Resource Management Concepts, Inc. (RMC) provides high-quality, professional services to government and commercial sectors. Our mission is to deliver exceptional management and technology solutions supporting the protection and preservation of the people and environment of the United States of America. RMC is hiring a Detection Engineer Analyst Subject Matter Expert (SME) to support an active government contract in Quantico, Virginia, providing defensive cyberspace operations and Cyber Security Service Provider (CSSP) functions. This position will support the government's mission to deny, disrupt, and degrade adversaries’ abilities and attempts to disrupt, exploit and attack the information technology (IT) services provided to network users.  The selected applicant will perform a variety of activities including but not limited to: Develop detection use cases based on current threats, the MITRE ATT&CK framework, and government direction. Review incident reporting to tune related detection use cases as necessary. Review Security information and event management (SIEM)/ Security orchestration, automation, and response (SOAR) incident queue for unnecessary events and alerts and implement corrective actions. Identify gaps in logging and detection capabilities across attack surface. Assist in implementing new log ingestion and verify proper parsing and normalization of data in SIEM/SOAR. Create high fidelity correlation rules, signatures, filters, and automations and maintain low false-positive rate. Required Active TS/SCI (DoD TOP SECRET clearance with Sensitive Compartmented Information access) eligibility is required.  Applicant selected will be subject to security investigation(s) and must maintain eligibility requirements for access to classified information. Bachelor’s in IT or Computer Science OR 5 years’ supporting DCO and/or network systems and technology DoD 8570 IAT Level III certification . DoD 8570 CSSP Analyst certification . 5 years’ experience with development/refinement of signatures, plays, policies, configurations, scripts and indicators used to identify malicious activity via network and host-based detection on the enterprise network. Experience leading operations and maintenance support for an enterprise-level (50k users) network. Experience writing signatures (e.g., KQL/Snort/ePO/Yara) for network and host IDS/IPS. Desired Microsoft Cloud Security training is highly recommended. Microsoft Azure and Microsoft Defender XDR. Microsoft Sentinel Ninja Training. Microsoft Defender For Endpoint Ninja Training. Microsoft Defender For Identity Ninja Training. Microsoft SC-XXX Training (certifications). Schedule: M-F, 5 X 8, between 7:00am EST and 5:00pm EST, normally not to exceed 40 hours per week. This position may require extended or non-standard hours occasionally to support major cyber incidents.  This position is considered essential and may be required to report during hazardous weather, power outages, fuel shortages, pandemics, and other emergencies.

Other Ai Matches

Zero Trust Program Manager (ZTPM) Applicants are expected to have a solid experience in handling Job related tasks
Kafka & SIEM Integration Engineer Applicants are expected to have a solid experience in handling Job related tasks
Workstation Technician Applicants are expected to have a solid experience in handling Job related tasks
Splunk SIEM Engineer Applicants are expected to have a solid experience in handling Job related tasks