Detection Engineering Lead - MANTECH

OpenTalent

McLean (VA)

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

MANTECH seeks a motivated Cyber Detection Engineering Lead to join our team in McLean, VA. You will guide detection logic development, automate security workflows, and strengthen threat-hunting operations while liaising with customer staff to ensure mission success.

Responsibilities include deploying custom detection rules across SIEMs, building analytics pipelines, designing SOAR playbooks, and mapping detection logic to MITRE ATT&CK techniques to improve incident response and threat detection.

Qualifications

  • 7+ years in cybersecurity with focus on detection engineering and threat hunting.
  • Experience with Python or similar for automation.
  • Hands-on with SIEMs like Splunk, ELK, Sentinel, Chronicle.
  • Experience mapping techniques to MITRE ATT&CK.

Responsibilities

  • Develop, optimize, and deploy detection rules across SIEM platforms.
  • Build and tune security analytics pipelines to reduce false positives.
  • Design and implement SOAR playbooks for security operations.
  • Automate threat intel ingestion, correlation, and alerting.
  • Coordinate with Incident Response and customer staff to ensure mission success.
  • Liaise with customers and oversee project workflow.

Skills

Threat hunting
Incident response
Automation scripting
MITRE ATT&CK
Python

Education

Bachelor's degree in Cybersecurity/CS

Tools

Splunk
ELK
Sentinel
Chronicle

Job description

MANTECH seeks a motivated and customer-oriented Cyber Detection Engineering Lead to join our team in McLean, VA . In this role you lead the mission to enhance cybersecurity detection and response capabilities by developing high-fidelity detection logic, automating security workflows, and strengthening threat-hunting operations. This role serves as a technical leader and liaison with customer staff, overseeing project and task workflow while improving the organization’s ability to identify, analyze, and respond to evolving cyber threats.

Responsibilities include but are not limited to:

  • Developing, optimizing, and deploying custom detection rules across SIEM platforms and creating signatures and detection rules for malware and network-based threats
  • Building, testing, and tuning security analytics pipelines to reduce false positives and improve alert fidelity
  • Designing and implementing SOAR playbooks to streamline and enhance security operations
  • Automating threat intelligence ingestion, correlation, and alerting mechanisms
  • Developing integration scripts between security tools and data sources to enhance visibility and response capabilities
  • Developing and maintaining robust detection logic mapped to MITRE ATT&CK techniques
  • Conducting continuous security log analysis to identify anomalies and potential threats
  • Collaborating with Incident Response teams to provide detection logic for emerging threats
  • Leveraging EDR solutions to detect and investigate endpoint threats
  • Analyzing Windows internals and system logs to identify malicious activities and forensic artifacts
  • Serving as a liaison with customer staff and overseeing project and task workflow to ensure successful mission execution

Minimum Qualifications:

  • High School Diploma and 7+ years of experience in cybersecurity with a focus on detection engineering, threat hunting, incident response, or CNO/CNE
  • Experience with Python or a similar language for automation and data analysis
  • Hands-on experience with SIEM platforms such as Splunk, ELK, Sentinel, Chronicle, or similar technologies
  • Experience applying the MITRE ATT&CK framework for adversary tactics and techniques mapping
  • Experience with YARA, Snort, Suricata, or other signature-based detection technologies
  • Experience with Windows internals and forensic artifacts for endpoint security investigations

Preferred Qualifications:

  • Bachelors degree in Cybersecurity, Computer Science or other relevant field
  • Experience with SOAR solutions and security automation workflows
  • Experience with threat intelligence platforms and integrating threat intelligence feeds into security operations
  • Prior experience in penetration testing, red teaming, or reverse engineering
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection Engineering Lead with Security Clearance - MANTECH
Detection Engineering Lead with Security Clearance - MANTECH

OpenTalent • Fairfax (VA)

On-site
USD 120,000 - 160,000
Senior Cyber Detection & SOAR Lead
Senior Cyber Detection & SOAR Lead

OpenTalent • McLean (VA)

On-site
USD 120,000 - 160,000
Cyber Hunt Analyst
Cyber Hunt Analyst

MANTECH • McLean (VA)

On-site
USD 90,000 - 130,000
Cybersecurity Detection Engineer 3643279
Cybersecurity Detection Engineer 3643279

Axiom-Path • Charlotte (NC)

Hybrid
USD 110,000 - 150,000
Cyber Security Engineer at ManTech McLean, VA
Cyber Security Engineer at ManTech McLean, VA

ManTech • McLean (VA)

On-site
USD 100,000 - 140,000
Cyber Security Analyst
Cyber Security Analyst

Netrolynx AI • United States

On-site
USD 110,000 - 160,000
Cyber Defense Platforms Staff Engineer
Cyber Defense Platforms Staff Engineer

Scorpion Therapeutics • Cambridge (MA)

On-site
USD 170,000 - 230,000
Cyber Threat Hunter — TS/SCI Clearance, Proactive Defense
Cyber Threat Hunter — TS/SCI Clearance, Proactive Defense

ManTech • Illinois

On-site
USD 92,000 - 154,000
Health Insurance
Life Insurance
Paid Time Off
+5
Detection Engineer, Security Operations & Telemetry
Detection Engineer, Security Operations & Telemetry

Saronic • Austin (TX)

On-site
Detection Engineer – Manager
Detection Engineer – Manager

Jobtailor • New York (NY)

On-site
USD 120,000 - 180,000