SIEM Analyst

Reston, VA
Full Time
Mid Level

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Analyst to join our team of experts!


What You'll Be Doing

As a SIEM Analyst at Mantis Security, you'll help maintain and improve the security monitoring capabilities that give our customers visibility into their environments. You'll work closely with SOC analysts, engineers, and other cybersecurity professionals to make sure the right data is being collected, analyzed, and turned into actionable security information.

 
  • Monitor and analyze security events and alerts within the SIEM
  • Develop, tune, and maintain correlation rules, alerts, dashboards, and searches
  • Investigate security events by correlating activity across multiple log and data sources
  • Support the onboarding, parsing, normalization, and validation of new log sources
  • Identify and troubleshoot gaps in logging, data ingestion, and security visibility
  • Help reduce false positives and improve the accuracy and effectiveness of security detections
  • Support incident investigations, threat hunting, and reporting requirements
  • Document SIEM configurations, detection logic, processes, and recommended improvements

What We're Looking For
  • 10+ years of cybersecurity experience with hands-on SIEM experience
  • Experience with Splunk, Elastic, Microsoft Sentinel, or a comparable enterprise SIEM platform
  • Strong understanding of security logs, event correlation, and detection methodologies
  • Working knowledge of Windows, Linux, network, firewall, authentication, and cloud logging
  • Experience creating and tuning queries, alerts, correlation rules, and dashboards
  • Understanding of common attack techniques and the ability to translate threats into detection logic
  • Familiarity with MITRE ATT&CK and its application to security monitoring and detection
  • Strong analytical, troubleshooting, and technical communication skills
  • Security+ or equivalent cybersecurity certification
  • Active TS/SCI security clearance required.

Nice to Have
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Splunk, Elastic, or Microsoft security certifications
  • Experience with AWS security logging and cloud-based data sources
  • Experience with Python, PowerShell, or other scripting languages

Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*