Booz Allen Hamilton

Data & Detection Engineer

Booz Allen Hamilton Fort Belvoir, Virginia, United States · $99K–$225K/yr

Software Development · 10,001+ employees

20 h ago
Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Data & Detection Engineer will lead the development and implementation of security solutions to protect military infrastructure and critical AI/ML networks. This role involves analyzing complex security challenges, identifying vulnerabilities, and utilizing AIOps workflows to automate threat detection and root cause analysis.

What they look for

Elastic Stack Machine Learning Anomaly Detection Cybersecurity AIOps Network Security System Security Engineering Python Powershell Log Analysis Root Cause Analysis SIEM Vulnerability Assessment Zero Trust Threat Assessment Infrastructure Controls

Requirements

Candidates must possess a Bachelor's degree, an IASAE II certification (such as CASP+, CISSP, or CSSLP), and an active TS/SCI security clearance. Proficiency in Elastic machine learning implementation, log pattern analysis, and platform health monitoring is required.

Benefits

Health insurance Life insurance Disability insurance Financial planning Retirement benefits Paid leave Professional development Tuition assistance Work-life programs Dependent care Recognition awards

Full description

Data & Detection EngineerThe Opportunity: 

Are you looking for an opportunity to share your experience in system security engineering to help our country and assist our clients with critical missions? As a systems security and network security engineer, you can identify the Information System Security Engineering needed to assess vulnerabilities and recommend the best solution and security strategy. We need your experience to lead the development and implementation of security solutions that will protect our military.

On our team, you’ll troubleshoot and analyze complex challenges for customers using your knowledge of network and security devices, applications, and identifying tools. You’ll use your curiosity for technology and market trends to further research and develop security solutions. Using your knowledge and experience in cybersecurity, you’ll assess security threats and implement infrastructure controls.

In this role, you’ll closely impact the DoD by protecting their infrastructure. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers.

Work with us as we secure and protect critical AI or ML networks for the better.

Join us. The world can’t wait. 

You Have: 

  • Experience with Elastic machine learning implementation, including designing, configuring, and managing Elastic's unsupervised machine learning jobs to automatically model system, application, and network behavior to detect anomalies in real-time, such as identifying unusual patterns in log data and metrics.
  • Experience with AI-powered alerting, including developing and fine-tuning sophisticated alerting rules based on Elastic's anomaly detection and forecasting features, reducing alert fatigue by moving beyond simple static thresholds and focusing on statistically significant deviations from the norm
  • Experience with log categorization and pattern analysis, including utilizing Elastic's AI features to automatically categorize and identify patterns in unstructured log data, helping to quickly surface new or unusual event types that could indicate a security incident or operational problem.
  • Ability to conduct root cause analysis automation and build and manage AIOps workflows that correlate anomalies and alerts across the Elastic Stack to help automate the initial stages of root cause analysis, providing rich context to the SOC or operations teams.
  • Ability to perform platform health monitoring and apply AIOps principles to monitor the health and performance of the SIEM/data platform itself, using Elastic's forecasting capabilities to predict future resource needs, such as disk space or memory, and prevent outages
  • TS/SCI clearance
  • Bachelor’s degree
  • IASAE II Certification such as CASP+, CISSP, or CSSLP

Nice If You Have: 

  • Experience integrating ML/AI capabilities to automate, enhance, and accelerate IT operations and security monitoring.
  • Experience with automation tools and scripting languages, such as Python and Powershell.
  • Experience designing, configuring, and managing unsupervised machine learning jobs to automatically model system, application, and network behavior to detect anomalies in real-time, including identifying unusual patterns in log data, metrics, and APM traces
  • Experience developing and fine-tuning sophisticated alerting rules based on Elastic's anomaly detection and forecasting features, reducing alert fatigue by moving beyond simple static thresholds and focusing on statistically significant deviations from the norm
  • Experience utilizing ML/AI features to automatically categorize and identify patterns in unstructured log data, helping to quickly surface new or unusual event types that could indicate a security incident or operational problem
  • Experience building and managing AIOps workflows that correlate anomalies and alerts to help automate the initial stages of root cause analysis, providing rich context to the SOC or operations teams
  • Experience applying AIOps principles to monitor the health and performance of the SIEM/data platform itself, using Elastic's forecasting capabilities to predict future resource needs, such as disk space, or memory, and prevent outages
  • Knowledge of Zero Trust principles and frameworks, such as NIST 800-207
  • Offensive Security Certified Professional (OSCP), GIAC Certified Incident Handler (GCIH), or GIAC Vulnerability Assessment Professional (GVAP) Certification

Clearance:

Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required.  

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.