Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!
What You'll Be Doing
As a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.
- Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
- Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
- Support the onboarding, parsing, normalization, and validation of security log sources
- Identify gaps in logging, telemetry, and detection coverage and help implement improvements
- Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
- Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
- Troubleshoot SIEM data ingestion, search, alerting, and performance issues
- Document detection logic, configurations, processes, and recommended improvements
- 10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
- Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
- Experience developing and tuning security detections in a SOC environment
- Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
- Experience onboarding and troubleshooting security data sources within a SIEM
- Strong understanding of common attack techniques and how to translate them into detection logic
- Familiarity with MITRE ATT&CK, incident response, and threat hunting
- Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification
Nice to Have
- Previous SOC Analyst or incident response experience
- Experience supporting DoD, Intelligence Community, or other federal environments
- Experience with AWS and cloud-based security telemetry
- Experience with Python, PowerShell, or other scripting languages
Skills Required
- 10+ years of cybersecurity experience with hands-on SIEM experience
- Experience with Splunk, Elastic, Microsoft Sentinel, or a comparable enterprise SIEM platform
- Strong understanding of security logs, event correlation, and detection methodologies
- Working knowledge of Windows, Linux, network, firewall, authentication, and cloud logging
- Experience creating and tuning queries, alerts, correlation rules, and dashboards
- Understanding of common attack techniques and ability to translate threats into detection logic
- Familiarity with MITRE ATT&CK and its application to security monitoring and detection
- Strong analytical, troubleshooting, and technical communication skills
- Security+ or equivalent cybersecurity certification
- Active TS/SCI security clearance
- Experience supporting DoD, Intelligence Community, or other federal environments
- Splunk, Elastic, or Microsoft security certifications
- Experience with AWS security logging and cloud-based data sources
- Experience with Python, PowerShell, or other scripting languages
What We Do
Mantis Security provides purpose-built cybersecurity solutions that safeguard some of the nation's most sensitive information assets. Our security consultants work with data owners and system developers to provide modern security approaches in software systems architectures and security engineering while maintaining the traditional cornerstone of information assurance. Our solutions balance security and functionality objectives to ensure that your sensitive data remains well-protected while empowering users to focus on mission accomplishment. Mantis Security provides expertise in Application Security Testing, Information Assurance, Security Engineering, Cloud Security, DevSecOps, Cyber Data Science, Security Architecture, Cyberspace Operations, and Critical Infrastructure Security. Mantis Security is an AWS Partner and a CMU/SEI Partner for Insider Threat Vulnerability Assessments. http://www.mantis-security.com









