Skip to main content

Dark Wolf Solutions

Threat Detection Engineer (Cloud Security)

Ogden, UTmidAdded today

About this role

Dark Wolf seeks a Threat Detection Engineer to design and deploy detection logic across on-premise and AWS GovCloud environments using a Detection-as-Code methodology. The role combines SIEM expertise, threat hunting against advanced adversaries, and AI/ML-assisted analysis to build high-fidelity alerts and automated response workflows at Hill AFB in Ogden, Utah.

What you'll do

  • Design, build, test, and deploy detection logic using Detection-as-Code across on-prem and AWS GovCloud
  • Author and tune custom detection signatures for cloud-native threats, container security, and host-level behavior
  • Ingest, normalize, and analyze AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, EKS Audit Logs) into SIEM and data lake
  • Conduct proactive threat hunting against MITRE ATT&CK Cloud Matrix TTPs for malicious activity and insider threats
  • Develop automated remediation and incident response playbooks within GitLab CI/CD pipelines with NOSC operators
  • Perform root-cause analysis on false positives/negatives to improve alert fidelity and reduce noise

What they're looking for

  • Splunk Enterprise detection authoring and tuning
  • ELK Stack (Elasticsearch, Logstash, Kibana) query development
  • AWS GovCloud security telemetry analysis
  • GitLab and DevSecOps CI/CD pipelines
  • MITRE ATT&CK framework and threat modeling
  • DoD cybersecurity policies and A&A procedures
  • Container runtime security (Falco, eBPF, Kubernetes)
  • Infrastructure as Code (Terraform, CloudFormation)
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Dark Wolf Solutions

Dark Wolf Solutions builds DevSecOps platforms, integration systems, and data analytics solutions for defense and intelligence customers, with a focus on DoD and Space Force operations. The company is hiring DevOps engineers, full-stack software engineers, systems engineers, and data engineers to support cloud infrastructure, platform development, radar systems, and mission-critical defense applications.

View all jobs at Dark Wolf Solutions

Likely interview questions

  • Walk us through your experience authoring detection rules in Splunk and the ELK Stack—what types of threats have you built detections for?
  • Describe your hands-on experience ingesting and normalizing AWS GovCloud security logs, particularly CloudTrail and VPC Flow Logs, into a SIEM.