SIEM/Detection Engineer

Posted 6 Days Ago
Be an Early Applicant
Reston, VA, USA
In-Office
Expert/Leader
Information Technology • Security • Cybersecurity • Automation
The Role
Monitor and analyze SIEM alerts, develop and tune detection rules, dashboards, searches, and correlation logic, and investigate events across multiple log sources. Support log onboarding, parsing, normalization, validation, troubleshooting, threat hunting, incident investigations, reporting, and documentation. Improve security visibility and reduce false positives while collaborating with SOC analysts, engineers, and cybersecurity teams. The role requires extensive cybersecurity and SIEM experience plus an active TS/SCI clearance.
Summary Generated by Built In

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!


What You'll Be Doing
As a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.
  • Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
  • Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
  • Support the onboarding, parsing, normalization, and validation of security log sources
  • Identify gaps in logging, telemetry, and detection coverage and help implement improvements
  • Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
  • Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
  • Troubleshoot SIEM data ingestion, search, alerting, and performance issues
  • Document detection logic, configurations, processes, and recommended improvements
What We're Looking For
  • 10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
  • Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
  • Experience developing and tuning security detections in a SOC environment
  • Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
  • Experience onboarding and troubleshooting security data sources within a SIEM
  • Strong understanding of common attack techniques and how to translate them into detection logic
  • Familiarity with MITRE ATT&CK, incident response, and threat hunting
  • Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification

Nice to Have
  • Previous SOC Analyst or incident response experience
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Experience with AWS and cloud-based security telemetry
  • Experience with Python, PowerShell, or other scripting languages

Skills Required

  • 10+ years of cybersecurity experience with hands-on SIEM experience
  • Experience with Splunk, Elastic, Microsoft Sentinel, or a comparable enterprise SIEM platform
  • Strong understanding of security logs, event correlation, and detection methodologies
  • Working knowledge of Windows, Linux, network, firewall, authentication, and cloud logging
  • Experience creating and tuning queries, alerts, correlation rules, and dashboards
  • Understanding of common attack techniques and ability to translate threats into detection logic
  • Familiarity with MITRE ATT&CK and its application to security monitoring and detection
  • Strong analytical, troubleshooting, and technical communication skills
  • Security+ or equivalent cybersecurity certification
  • Active TS/SCI security clearance
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Splunk, Elastic, or Microsoft security certifications
  • Experience with AWS security logging and cloud-based data sources
  • Experience with Python, PowerShell, or other scripting languages
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
15 Employees
Year Founded: 2015

What We Do

Mantis Security provides purpose-built cybersecurity solutions that safeguard some of the nation's most sensitive information assets. Our security consultants work with data owners and system developers to provide modern security approaches in software systems architectures and security engineering while maintaining the traditional cornerstone of information assurance. Our solutions balance security and functionality objectives to ensure that your sensitive data remains well-protected while empowering users to focus on mission accomplishment. Mantis Security provides expertise in Application Security Testing, Information Assurance, Security Engineering, Cloud Security, DevSecOps, Cyber Data Science, Security Architecture, Cyberspace Operations, and Critical Infrastructure Security. Mantis Security is an AWS Partner and a CMU/SEI Partner for Insider Threat Vulnerability Assessments. http://www.mantis-security.com

Similar Jobs

Acquia Logo Acquia

Artificial Intelligence Engineer

AdTech • Cloud • Marketing Tech • Productivity • Software • Analytics • Automation
Easy Apply
Remote or Hybrid
United States
1100 Employees
150K-200K Annually

Rapid7 Logo Rapid7

Detection & Response Analyst

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
Arlington, VA, USA
2400 Employees

Rapid7 Logo Rapid7

Lead Detection & Response Analyst

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
Arlington, VA, USA
2400 Employees

Rapid7 Logo Rapid7

Operations Analyst

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
United States
2400 Employees
82K-110K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account