Base Career helps you apply smarter for this job.
Key skills for this role
Lead cross-tool security engineering efforts, advising on best practices for closing detection and reporting gaps that span multiple platforms
Diagnose and resolve reporting and visibility gaps created when a tool in the environment is deprecated, replaced, or reconfigured — for example, reconstructing lost reporting coverage by combining endpoint telemetry with Splunk data
Design, implement, and document data flows and integration points across endpoint protection, SIEM, and other security tools supporting the program
Build and tune detection logic, correlation searches, and dashboards that hold up as individual tools in the stack change, are replaced, or are retired
Lead the technical transition work when a security tool is deprecated, replaced, or reconfigured, ensuring no loss of detection or reporting coverage
Integrate tools such as CrowdStrike, Splunk, Cribl, CyberArk, Suricata, Tenable, Tanium, Thales, CASB, Trellix, Axonius, and others to close cross-platform visibility gaps
Develop automation and correlation workflows using APIs across the security tool stack to reduce manual reporting and analysis work
Support threat hunting and incident response efforts that require correlating evidence across more than one tool or data source
Support endpoint and platform security compliance with NIST, FISMA, and agency-specific requirements
Maintain current, accurate documentation of tool configurations, data flows, and integration architecture across the stack
Serve as the team's point of contact for cross-tool security engineering issues
Ability to attain DHS EOD
Master's degree or equivalent, plus 12 years of relevant experience
Demonstrated, hands-on experience across more than one security tool category (endpoint/EDR, SIEM, vulnerability management, network detection, or similar)
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Hyderabad, IND
The employer is seeking a Security Analyst to validate vulnerabilities, assess real-world impact, and drive High and Medium findings through remediation or documented compensating controls. The role requires application
, IND
UltraViolet Cyber is seeking a Senior Cybersecurity Incident Response Specialist to own complex enterprise security incidents from detection through closure. The role covers incident response, root cause analysis, malwar
Herndon, USA
Bengaluru, IND
Herndon, USA
Bengaluru, IND
Bengaluru, IND
Washington, USA
Hyderabad, IND
, IND
Herndon, USA
Bengaluru, IND
Herndon, USA
Hands-on experience with an EDR/endpoint platform (e.g., CrowdStrike Falcon) — administration, detection engineering, or response
Hands-on experience with Splunk (or an equivalent SIEM) — search, correlation searches, and dashboard/reporting development
Demonstrated experience correlating and integrating data across disparate security platforms to close a visibility, detection, or reporting gap
Scripting/automation proficiency (Python, PowerShell, or similar) for cross-tool data pipelines and API integrations
Experience owning a tool deprecation or migration without losing detection or reporting coverage
Effective communicator at all levels, both written and verbal
Professional, customer-oriented, and even-keeled under pressure
Experience supporting federal agency security operations centers
Additional security certifications (CISSP, GIAC, Security+)
Experience with CrowdStrike's cloud workload protection capabilities
Knowledge of CISA directives and CDM program requirements
Background in threat hunting and advanced persistent threat detection
Experience with security orchestration and automation platforms
Familiarity with Zero Trust Architecture implementation
Hybrid work model with 3 day/week on-site presence near National Harbor, Maryland
Must be able to pass a Federal background investigation - US Citizenship required
Participation in on-call rotation for security incident response
401(k), including an employer match of 100% of the first 3% contributed and 50% of the next 2% contributed
Medical, Dental, and Vision Insurance (available on the 1st day of the month following your first day of employment)
Group Term Life, Short-Term Disability, Long-Term Disability
Voluntary Life, Hospital Indemnity, Accident, and/or Critical Illness
Participation in the Discretionary Time Off (DTO) Program
11 Paid Holidays Annually
Managed security operations provider combining detection and response services with offensive red team testing to proactively reduce enterprise cyber risk.
Visit company websiteJobs and hiring trendsFull-time
Senior · 12+ years experience
Hybrid
Apply faster on company sites with our extension.