CF CloudFrame Job Scanner Open Dashboard →
Verified Active Opening

Detection Engineer

Accenturefederalservices • Arlington, VA

Job Description

<div class="content-intro"><div> <div> </div> <div>At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology and ingenuity for clients across defense, national security, public safety, civilian, and military health organizations. </div> <div> </div> <div>Join Accenture Federal Services, a technology company within global Accenture. Recognized as a Glassdoor Top 100 Best Place to Work, we offer a collaborative and caring community where you feel like you belong and are empowered to grow, learn and thrive through hands-on experience, certifications, industry training and more. </div> <div> </div> <div>Join us to drive positive, lasting change that moves missions and the government forward!</div> <div> </div> </div></div><p> </p> <p>The Detection Engineer will work on the Cyber Incident Response Team (CIRT) within the Information Security organization.</p> <p>Responsibilities include:</p> <ul> <li>Design, engineer, and implement security detection initiatives under the cybersecurity team lead.</li> <li>Develop new detection logic for SIEM (Microsoft Sentinel) and network security platforms (Cisco FirePower, IDS/IPS), incorporating AI-driven tooling where applicable.</li> <li>Write and optimize KQL queries for Sentinel to improve detection fidelity and reduce false positives.</li> <li>Tune detection sets to raise security-relevant events for triage and response teams.</li> <li>Maintain version control of detection logic using Git and GitHub workflows for collaborative development and auditability.</li> <li>Bridge the gap between network engineering and cybersecurity teams to advocate for secure network designs and maximize security device capabilities.</li> <li>Conduct technical briefings to enhance team awareness of network architecture and detection strategies.</li> <li>Collaborate with operations and management to recommend improvements to security posture and ensure compliance with industry and federal standards (e.g., NIST, CISA).</li> </ul> <p><strong>What You Need:</strong></p> <ul> <li>U.S. Citizenship required</li> <li>Bachelor’s degree in Cybersecurity, Computer Science, or related field (or equivalent experience)</li> <li>6 + years experience in information security or equivalent combination of education and work experience</li> <li>2+ years experience performing event and log analysis across enterprise security tools (AV, IDS/IPS, Firewalls, Active Directory, Web Proxies, DLP, SIEM)</li> <li>Hands-on experience with: <ul> <li>Microsoft Sentinel & KQL (minimum 1 year)</li> <li>Cisco FirePower and IDS/IPS configuration (minimum 1 year)</li> <li>SIEM platforms (Sentinel preferred)</li> <li>Detection engineering: designing and tuning signatures for IoCs and IoAs</li> <li>Packet and malware analysis using tools like Wireshark</li> <li>Git and GitHub for detection code version control and collaborative workflows</li> <li>Scripting and parsing (regex, PowerShell, Python, grep, sed, awk)</li> <li>TCP/IP, application layer protocols, and Windows/Linux internals</li> <li>MITRE ATT&CK framework for detection mapping</li> </ul> </li> </ul> <p><strong>Bonus If You Have:</strong></p> <ul> <li>Threat hunting and automation experience</li> <li>Familiarity with cloud security monitoring (Azure, AW

Job Reference ID: CF-143850 • Posted on CloudFrame Job Scanner