Detection and Response Engineer
Listed on 2026-01-12
-
IT/Tech
Cybersecurity -
Engineering
Cybersecurity
Detection and Response Engineer (Johns Hopkins Applied Physics Laboratory) Compensation
Base pay range: $/yr – $/yr
Responsibilities- Create novel detections in Python, SQL, and similar scripting languages based on a deep understanding of adversarial tradecraft.
- Bring together data‑driven analytics and traditional detection engineering to stay ahead of sophisticated threats by developing and deploying novel tooling that may improve machine learning, statistical methods, or large language models to enhance detection, investigation, and response capabilities.
- Hunt for advanced threats by analyzing data through hypothesis crafting and iterative searching through data to identify malicious behaviors.
- Develop and enhance processes, workflows, and detections to quickly identify and respond to potential incidents.
- Collect evidence to include digital media, logs, and malware to perform analysis associated with cyber intrusions.
- Participate in projects and multi‑functional security teams requiring interaction with IT operations.
- Bachelor’s Degree in Information Security, a security related field, or equivalent experience that provides the necessary knowledge, skill and abilities.
- 3+ years of real‑world cyber experience or an equivalent blend of cybersecurity and data science experience.
- Proficient understanding of operating systems (OS), OS normal activities, OS internals, MITRE ATT&CK TTPs mapped to OS, and identifying anomalous behaviors.
- Proficiency with extracting and manipulating data, using scripting languages such as Python, Power Shell, SQL, or others.
- Experience applying data science or statistical methodologies to cybersecurity data using Python and SQL.
- Experience with cloud attack detection and response in cloud infrastructure.
- Demonstrate ambition to further current knowledge and understanding by exploring new concepts and applying to cyber security.
- Ability to obtain a Secret security clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship.
- Master’s Degree in Information Security Assurance or security related field.
- Demonstrated ability in operational cybersecurity and incident response in large scale environments.
- Familiarity with data platforms such as AWS Security Lake and Databricks for large‑scale data analysis.
- Experience with Assume Breach methodologies and proficient understanding of advanced attack methodologies of nation‑state adversaries.
- Proficient knowledge of the MITRE ATT&CK framework.
- Technical experience in some of the following areas:
Endpoint Detection & Response, Active Directory and authentication anomalies, Suricata, Zeek, full packet capture technologies, firewall, proxy, and sandbox technologies. - Experience with memory analysis, host‑based anomaly detection, network anomaly detection, and authentication anomaly detection.
- Experience leveraging large language models to enhance detection and response capabilities.
Applicants must have or be able to obtain a Secret security clearance. Eligibility requires U.S. citizenship.
BenefitsAPL provides a robust benefits package including retirement contributions, paid time off, medical, dental, vision, life insurance, short‑term and long‑term disability, flexible spending accounts, education assistance, and training and development opportunities. A flexible work/life balance, education assistance, and a vibrant, welcoming culture are also offered.
EEO StatementAll qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, gender identity or expression, sexual orientation, national origin, age, physical or mental disability, genetic information, veteran status, occupation, marital or familial status, political opinion, personal appearance, or any other characteristic protected by applicable law. APL is committed to providing reasonable accommodation to individuals of all abilities, including those with disabilities.
If you require a reasonable accommodation to participate in any part of the hiring process, please contact Accommodations.
- Seniority level:
Mid‑Senior level - Employment type:
Full‑time - Job function:
Engineering and Information Technology - Industries:
Defense and Space Manufacturing - Location:
Baltimore‑Washington metro area (APL campus) - Apply at: http://(Use the "Apply for this Job" box below)./careers
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).