Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!
What You'll Be DoingAs a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.
Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
Support the onboarding, parsing, normalization, and validation of security log sources
Identify gaps in logging, telemetry, and detection coverage and help implement improvements
Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
Troubleshoot SIEM data ingestion, search, alerting, and performance issues
Document detection logic, configurations, processes, and recommended improvements
What We're Looking For
10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
Experience developing and tuning security detections in a SOC environment
Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
Experience onboarding and troubleshooting security data sources within a SIEM
Strong understanding of common attack techniques and how to translate them into detection logic
Familiarity with MITRE ATT&CK, incident response, and threat hunting
Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification
Nice to Have
Previous SOC Analyst or incident response experience
Experience supporting DoD, Intelligence Community, or other federal environments
Experience with AWS and cloud-based security telemetry
Experience with Python, PowerShell, or other scripting languages
Powered by JazzHR
Numbers & Facts
Location
Reston, VA
Skills
Amazon Web Services (AWS)unmatched
Analysis Skillsunmatched
Career Developmentunmatched
Cloud Computingunmatched
CompTIA Security+unmatched
Computer Hackingunmatched
Continuous Improvementunmatched
Data Collectionunmatched
GIAC - Global Information Assurance Certificationunmatched
Huntingunmatched
Identify Issuesunmatched
Incident Responseunmatched
Information/Data Security (InfoSec)unmatched
Intelligence Communityunmatched
Internet Securityunmatched
Linux Operating Systemunmatched
Mantis Bug Tracking Softwareunmatched
Microsoft Windows Operating Systemunmatched
Onboardingunmatched
Process Improvementunmatched
Python Programming/Scripting Languageunmatched
Reporting Dashboardsunmatched
Scripting (Scripting Languages)unmatched
Security Information and Event Management (SIEM)unmatched
Security Monitoringunmatched
Software Developmentunmatched
Software Engineeringunmatched
Splunkunmatched
Staff Developmentunmatched
Telemetryunmatched
United States Department of Defense (DoD)unmatched
Windows PowerShellunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.