Cintel, Inc. ยท 13 hours ago
Cyber Capability Developer- Senior
Cintel, Inc. is a Small Business providing strategies and services to support an array of Government clients in various domains including Cyber Security. They are seeking an experienced Senior Cyber Capability Developer to support advanced cyber threat detection, analysis, and response operations, focusing on designing and optimizing cybersecurity detection capabilities and analytics.
AerospaceBusiness IntelligenceCyber SecurityEmbedded SystemsGovernmentMachine LearningMilitarySoftware
Responsibilities
Engineer, develop, and deploy cybersecurity threat detection capabilities, alerts, and analytics across enterprise environments
Design, implement, and optimize security detections and dashboards using Splunk SPL and Microsoft Sentinel
Perform Splunk backend engineering, including log and data onboarding, ingestion pipelines, visualization, testing, and validation
Leverage cyber threat intelligence to improve detection logic, reduce false positives, and enhance analytic fidelity
Design, implement, and optimize cybersecurity data pipelines to support monitoring, analytics, and response workflows
Implement, operate, maintain, and optimize Security Orchestration, Automation, and Response (SOAR) tools and platforms
Establish data baselines and detect anomalous or malicious activity across network, endpoint, and cloud environments
Perform advanced cyber threat analysis, including malware analysis, network traffic analysis, and host-based forensics
Conduct static and dynamic analysis of known and unknown binary files and reverse engineer compiled software
Support memory, disk, and network forensic investigations in classified cyber threat environments
Develop and maintain capabilities across multiple environments, including on-premises and cloud infrastructures
Collaborate with cross-functional cyber and software development teams in agile or DevSecOps environments
Qualification
Required
Active Top Secret (TS) security clearance
Bachelor's degree (BS or BA) in Cybersecurity, Computer Science, Engineering, or a related field
Significant experience in cyber threat detection engineering, alert and analytics development, display, and deployment
Proficiency in Splunk Search Processing Language (SPL)
Hands-on experience with Splunk and Microsoft Sentinel
Experience with data sourcing, integration, and analysis to establish baselines and identify anomalies
Experience implementing, operating, and optimizing SOAR systems and tools
Experience engineering and maintaining cybersecurity solutions within Linux environments
Minimum of (8) years of experience, including Bash, PowerShell, Python, SQL, and Java
Cloud engineering experience, including AWS and Azure GovCloud environments
Preferred
GIAC Continuous Monitoring Certification (GMON)
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
GIAC Certified Intrusion Analyst (GCIA)
GIAC Network Forensic Analyst (GNFA)
Professional experience supporting cyber intrusion detection and response operations
Experience with malware reverse engineering and functional analysis of source code and scripts
Experience analyzing technical data within advanced cyber threat environments
Experience working in team-based software development or cyber operations environments