Detection Engineering Lead

ManTech

McLean (VA)

On-site

USD 140,000 - 190,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

MANTECH seeks a motivated Cyber Detection Engineering Lead to join our team in McLean, VA. You will lead detection engineering initiatives, develop high-fidelity rules, and automate security workflows to strengthen threat-hunting operations.

The role requires extensive SIEM experience, Python automation, and hands-on work with MITRE ATT&CK mappings to identify and respond to evolving cyber threats. Collaboration with customer staff is essential for mission success and incident response support.

Qualifications

  • High School Diploma and 7+ years of cybersecurity experience with a focus on detection engineering, threat hunting, incident response, or CNO/CNE.
  • Experience with Python or a similar language for automation and data analysis.
  • Hands-on experience with SIEM platforms such as Splunk, ELK, Sentinel, Chronicle, or similar technologies.
  • Experience applying the MITRE ATT&CK framework for adversary tactics and techniques mapping.
  • Experience with YARA, Snort, Suricata, or other signature-based detection technologies.
  • Experience with Windows internals and forensic artifacts for endpoint security investigations.

Responsibilities

  • Developing, optimizing, and deploying custom detection rules across SIEM platforms and creating signatures for malware and network-based threats.
  • Building, testing, and tuning security analytics pipelines to reduce false positives and improve alert fidelity.
  • Designing and implementing SOAR playbooks to streamline security operations.
  • Automating threat intelligence ingestion, correlation, and alerting mechanisms.
  • Developing integration scripts between security tools and data sources to enhance visibility and response capabilities.
  • Maintaining detection logic mapped to MITRE ATT&CK techniques.

Skills

Python automation
Threat hunting
Incident response
MITRE ATT&CK mapping
Windows forensics

Education

Bachelor's degree in Cybersecurity or Computer Science

Tools

Splunk
ELK
Sentinel
Chronicle
YARA
Snort/Suricata

Job description

MANTECH seeks a motivated and customer-oriented Cyber Detection Engineering Lead to join our team in McLean, VA . In this role you lead the mission to enhance cybersecurity detection and response capabilities by developing high-fidelity detection logic, automating security workflows, and strengthening threat-hunting operations. This role serves as a technical leader and liaison with customer staff, overseeing project and task workflow while improving the organization’s ability to identify, analyze, and respond to evolving cyber threats.

Responsibilities include but are not limited to:
  • Developing, optimizing, and deploying custom detection rules across SIEM platforms and creating signatures and detection rules for malware and network-based threats

  • Building, testing, and tuning security analytics pipelines to reduce false positives and improve alert fidelity

  • Designing and implementing SOAR playbooks to streamline and enhance security operations

  • Automating threat intelligence ingestion, correlation, and alerting mechanisms

  • Developing integration scripts between security tools and data sources to enhance visibility and response capabilities

  • Developing and maintaining robust detection logic mapped to MITRE ATT&CK techniques

  • Conducting continuous security log analysis to identify anomalies and potential threats

  • Collaborating with Incident Response teams to provide detection logic for emerging threats

  • Leveraging EDR solutions to detect and investigate endpoint threats

  • Analyzing Windows internals and system logs to identify malicious activities and forensic artifacts

  • Serving as a liaison with customer staff and overseeing project and task workflow to ensure successful mission execution

Minimum Qualifications:
  • High School Diploma and 7+ years of experience in cybersecurity with a focus on detection engineering, threat hunting, incident response, or CNO/CNE

  • Experience with Python or a similar language for automation and data analysis

  • Hands-on experience with SIEM platforms such as Splunk, ELK, Sentinel, Chronicle, or similar technologies

  • Experience applying the MITRE ATT&CK framework for adversary tactics and techniques mapping

  • Experience with YARA, Snort, Suricata, or other signature-based detection technologies

  • Experience with Windows internals and forensic artifacts for endpoint security investigations

Preferred Qualifications:
  • Bachelors degree in Cybersecurity, Computer Science or other relevant field

  • Experience with SOAR solutions and security automation workflows

  • Experience with threat intelligence platforms and integrating threat intelligence feeds into security operations

  • Prior experience in penetration testing, red teaming, or reverse engineering

  • Certifications such as GCDA, GCIH, GCFA, OSCP, or Splunk Certified Security Professional

Clearance Requirements:
  • Active/current TS/SCI with polygraph
Physical Requirements:
  • Must be able to remain in a stationary position 50% of the time

MANTECH International Corporation considers all qualified applicants for employment without regard to disability or veteran status or any other status protected under any federal, state, or local law or regulation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Detection Engineering Lead – SIEM & SOAR Architect
Cyber Detection Engineering Lead – SIEM & SOAR Architect

ManTech • McLean (VA)

On-site
USD 140,000 - 190,000
Cyber Security Engineer at ManTech McLean, VA
Cyber Security Engineer at ManTech McLean, VA

ManTech • McLean (VA)

On-site
USD 100,000 - 140,000
Cyber Security Engineer – Threat Detection (1401)
Cyber Security Engineer – Threat Detection (1401)

Sharp Decisions • Charlotte (NC)

Hybrid
USD 105,000 - 145,000
Cybersecurity Detection Engineer 3643279
Cybersecurity Detection Engineer 3643279

Axiom-Path • Charlotte (NC)

Hybrid
USD 110,000 - 150,000
Detection Analyst (Elastic)
Detection Analyst (Elastic)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 110,000 - 140,000
Cybersecurity Incident Response Analyst
Cybersecurity Incident Response Analyst

MANTECH • McLean (VA)

On-site
USD 90,000 - 130,000
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Threat Hunter/Detection Engineer - Tier 3
Threat Hunter/Detection Engineer - Tier 3

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 130,000 - 150,000
Cyber Security Detections Engineer at McIntire Solutions Springfield, VA
Cyber Security Detections Engineer at McIntire Solutions Springfield, VA

McIntire Solutions • Springfield (VA)

On-site
USD 80,000 - 110,000
Senior Cybersecurity Manager
Senior Cybersecurity Manager

Amtex Systems Inc • Atlanta (GA)

Hybrid
USD 120,000 - 150,000