SIEM/Detection Engineer

Mantis Security Corporation

Reston (VA)

On-site

USD 140,000 - 190,000

Full time

8 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Mantis Security Corporation is seeking an experienced SIEM Engineer to join our team in Reston, VA. You will help improve threat detection by ensuring security data is collected, correlated, and transformed into effective detections, working closely with SOC analysts and engineers.

You will develop Splunk searches and dashboards, tune detection logic, onboard log sources, and translate attacker techniques into actionable detections.

Qualifications

  • 10+ years of cybersecurity experience with hands-on SIEM or security monitoring
  • Strong Splunk experience with SPL searches, correlation searches, dashboards and alerts
  • Experience developing and tuning detections in a SOC environment
  • Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud
  • Experience onboarding and troubleshooting security data sources within a SIEM
  • Strong ability to translate attacker techniques into detection logic
  • Familiarity with MITRE ATT&CK, incident response and threat hunting
  • Relevant cybersecurity or SIEM certifications such as Security+, CySA+, GIAC, or Splunk certification

Responsibilities

  • Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
  • Build and improve detection logic to identify suspicious activity while reducing false positives
  • Support onboarding, parsing, normalization, and validation of security log sources
  • Identify gaps in logging, telemetry, and detection coverage and implement improvements
  • Translate emerging threats into actionable detections using MITRE ATT&CK
  • Support SOC investigations and threat hunting with queries across data sources
  • Troubleshoot SIEM data ingestion, search, alerting, and performance issues
  • Document detection logic, configurations, processes, and improvements

Skills

SIEM
Splunk
Threat detection
SOC operations
Dashboard development
Security monitoring
Threat hunting
MITRE ATT&CK

Education

Security+ / CySA+ / GIAC
Splunk Certification

Tools

Splunk

Job description

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!

What You’ll Be Doing

As a SIEM / Detection Engineer at Mantis Security, you’ll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You’ll work closely with SOC analysts and engineers to continuously improve the team’s visibility and detection capabilities.

  • Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
  • Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
  • Support the onboarding, parsing, normalization, and validation of security log sources
  • Identify gaps in logging, telemetry, and detection coverage and help implement improvements
  • Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
  • Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
  • Troubleshoot SIEM data ingestion, search, alerting, and performance issues
  • Document detection logic, configurations, processes, and recommended improvements
What We’re Looking For
  • 10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
  • Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
  • Experience developing and tuning security detections in a SOC environment
  • Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
  • Experience onboarding and troubleshooting security data sources within a SIEM
  • Strong understanding of common attack techniques and how to translate them into detection logic
  • Familiarity with MITRE ATT&CK, incident response, and threat hunting
  • Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification
Nice to Have
  • Previous SOC Analyst or incident response experience
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Experience with AWS and cloud-based security telemetry
  • Experience with Python, PowerShell, or other scripting languages
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Splunk SIEM & Threat Detection Engineer
Senior Splunk SIEM & Threat Detection Engineer

Mantis Security Corporation • Reston (VA)

On-site
USD 140,000 - 190,000
SOC Analyst
SOC Analyst

Mantis Security Corporation • Reston (VA)

On-site
USD 100,000 - 150,000
SOC Engineer
SOC Engineer

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000
SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
Senior Splunk SIEM Engineer — Threat Detection & Response
Senior Splunk SIEM Engineer — Threat Detection & Response

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Software Engineer, Information Security
Senior Software Engineer, Information Security

COMMURE Incorporated • Mountain View (CA)

On-site
USD 130,000 - 160,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

TALENT Software Services • Richmond (VA)

On-site
USD 120,000 - 170,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate • Richmond (VA)

On-site
USD 120,000 - 180,000
Senior SOC Engineer - Detection, Threat Hunting & SIEM
Senior SOC Engineer - Detection, Threat Hunting & SIEM

IT Data Consulting, LLC • Reston (VA)

On-site