Rooted
Back to jobs
CI
Open role

CACI International

Detection Engineer

Reston, Virginia· ONSITE

Hacker+ signal

About the role

You translate known attacker techniques into detection rules that work against real production data. The difficulty is not writing a rule that fires on a test case; it is writing one that still identifies the technique months later while producing few enough false positives that the on-call team can trust it. You also run threat hunts to find activity that current detections would have missed.

What you will do

  • Build detections from real attacker behaviour
  • Measure each rule's false positive rate and own it
  • Hunt for what current detections would have missed

What they ask for

  • Knows what attacks look like in telemetry, not just in theory
  • Query languages and a scripting language
  • Willing to delete your own rules when they stop earning their place

Nice to have

  • Purple team experience
  • Sigma rules
  • Incident response background

What applying with Rooted means

This role accepts applications with Rooted context. Instead of sending only a resume, you can attach a verifiable credential with your proofs, rank, and technical evidence.

Your application includes your Rooted credential: rank, verified proofs, and supporting evidence.

You can read this role without an account. To apply you need a Rooted credential.

This role is curated by Rooted. Rooted is not the hiring company unless explicitly stated. The hiring company is CACI International. Confirm the final details with the original source or during the application process.

Posted 2026-08-13