Threat Detection Engineer (Cloud Security)
MiddleOn-site (Ogden)Salary undisclosed
Required Skills
Node.jsAWSKubernetesDockerTerraformCI/CD
Job Description
Dark Wolf is looking for a Threat Detection Engineer to design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.
Key Responsibilities:
- Designing, building, testing, and deploying robust detection logic using a "Detection-as-Code" methodology across on-prem and cloud-hosted AWS GovCloud environments
- Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior
- Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environ
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.