Demo

Threat Detection Engineer (Cloud Security)

darkwolfsolutions
Ogden, UT Full Time
POSTED ON 9/1/2026
AVAILABLE BEFORE 11/1/2026

Dark Wolf is looking for a Threat Detection Engineer to design, build, test, and deploy detection logic using a "Detection-as-Code" methodology across on-premise and AWS GovCloud environments. Moving beyond traditional monitoring, this role focuses on proactively engineering high-fidelity alerts, threat hunting against advanced adversary techniques, and automating response workflows to reduce alert fatigue. This position leverages Artificial Intelligence (AI) and Machine Learning (ML) capabilities to accelerate detection engineering, optimize query generation, and streamline incident response. This role will be fully on-site at Hill AFB in Ogden, Utah.

Key Responsibilities:

  • Designing, building, testing, and deploying robust detection logic using a "Detection-as-Code" methodology across on-prem and cloud-hosted AWS GovCloud environments
  • Writing and maintaining custom detection signatures targeting cloud-native vectors, container security, and host-level behavior
  • Ingesting, normalizing, and analyzing AWS security logs (CloudTrail, VPC Flow Logs, GuardDuty, AWS Config, EKS Audit Logs) and on-prem telemetry into SIEM and data lake environments
  • Proactively hunt for undetected malicious activity, insider threats, and novel adversary TTPs mapped against the MITRE ATT&CK Cloud Matrix
  • Partnering with NOSC operators and AWS Engineers to develop automated remediation and incident response playbooks within GitLab pipelines
  • Conducting root-cause analysis on false positives/negatives to continuously improve alert fidelity, reduce noise, and optimize detection rules
  • Utilizing AI-assisted analysis and ML features to enhance query generation, automate threat intelligence correlation, and streamline detection development
  • Participating in the development of DCO concept of operations, processes, and procedures
  • Supporting vulnerability management mitigations, adhere to defined policies and schedules, and complete all required training and disclosures as outlined by BSTG.
  • Participating in the development of DCO tactics, techniques, and procedures (TTPs), threat models, and supporting technical documentation.

Required Qualifications:

  • 4 years of relevant experience
  • 2 years of hands-on experience authoring and tuning detection logic in Splunk Enterprise and the ELK Stack (Elasticsearch, Logstash, Kibana).
  • 2 years of experience with employment of DoD cybersecurity requirements, policies, and procedures to include assessment and authorization activities.
  • Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
  • Direct experience ingesting, normalizing, and engineering detections for AWS GovCloud security telemetry (CloudTrail, VPC Flow Logs, GuardDuty, EKS Audit Logs).
  • Demonstrated experience using GitLab for Detection-as-Code, CI/CD pipelines, version control, and DevSecOps workflows.
  • Department of Defense Directive (DoDD) 8140 (formerly DoDD 8570) IAT CSSP Certification must be obtained prior to hire (CEH, CCNA Security, GCIH, CySA or Equivalent).
  • Bachelor’s degree in Computer Science, Information Technology, or a related field.
  • US Citizenship and an active Top Secret/SCI security clearance required.

Desired Qualifications:

  • Experience managing detections as code using Infrastructure as Code (IaC) tools like Terraform or CloudFormation.
  • Familiarity with container runtime security (e.g., Falco, eBPF, Docker security) and Kubernetes threat modeling.
  • Experience with RHEL
  • Experience in performing post-incident computer forensics without destruction of critical data
  • Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff

The salary range for this position is estimated to be between $100,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

We are strictly looking for direct, full-time W2 employees.

Salary : $100,000 - $160,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Threat Detection Engineer (Cloud Security)?

Sign up to receive alerts about other jobs on the Threat Detection Engineer (Cloud Security) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,466 - $114,731
Income Estimation: 
$114,790 - $146,930
Income Estimation: 
$115,647 - $153,495
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at darkwolfsolutions

  • darkwolfsolutions Colorado, CO
  • Dark Wolf is seeking a Field Support Officer (FSO) to join our Test & Evaluation (T&E) team. Serving as the critical on-site representative on DoD ranges a... more
  • 1 Day Ago

  • darkwolfsolutions Colorado, CO
  • Dark Wolf is seeking a Test Planner and Manager (TPM) to join our Test & Evaluation (T&E) team. Serving as the critical bridge between commercial innovatio... more
  • 1 Day Ago

  • darkwolfsolutions Ogden, UT
  • Dark Wolf Solutions is looking for a Information Systems Security Officer who will perform continuous system monitoring to identify malicious cyber-attacks... more
  • 2 Days Ago

  • darkwolfsolutions Huntsville, AL
  • Dark Wolf Solutions is seeking a Cybersecurity Engineer to will lead and execute the security authorization process for our systems and applications in com... more
  • 3 Days Ago


Not the job you're looking for? Here are some other Threat Detection Engineer (Cloud Security) jobs in the Ogden, UT area that may be a better fit.

  • GMRE Ogden, UT
  • Description JOB SUMMARY GMRE is currently seeking a Project Engineer to support the Engineering Team at the GMRE HQ located in South Ogden, UT. The positio... more
  • 1 Day Ago

  • forsgrenassociates Logan, UT
  • Forsgren, an Apex Company is seeking a Structural Engineer to be based in Logan, UT. When you join Forsgren Associates, a newly acquired Apex Company, you ... more
  • 1 Day Ago

AI Assistant is available now!

Feel free to start your new journey!