SIEM Analyst
Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Analyst to join our team of experts!
What You'll Be Doing
As a SIEM Analyst at Mantis Security, you'll help maintain and improve the security monitoring capabilities that give our customers visibility into their environments. You'll work closely with SOC analysts, engineers, and other cybersecurity professionals to make sure the right data is being collected, analyzed, and turned into actionable security information.
Monitor and analyze security events and alerts within the SIEM
Develop, tune, and maintain correlation rules, alerts, dashboards, and searches
Investigate security events by correlating activity across multiple log and data sources
Support the onboarding, parsing, normalization, and validation of new log sources
Identify and troubleshoot gaps in logging, data ingestion, and security visibility
Help reduce false positives and improve the accuracy and effectiveness of security detections
Support incident investigations, threat hunting, and reporting requirements
Document SIEM configurations, detection logic, processes, and recommended improvements
What We're Looking For
10+ years of cybersecurity experience with hands-on SIEM experience
Experience with Splunk, Elastic, Microsoft Sentinel, or a comparable enterprise SIEM platform
Strong understanding of security logs, event correlation, and detection methodologies
Working knowledge of Windows, Linux, network, firewall, authentication, and cloud logging
Experience creating and tuning queries, alerts, correlation rules, and dashboards
Understanding of common attack techniques and the ability to translate threats into detection logic
Familiarity with MITRE ATT&CK and its application to security monitoring and detection
Strong analytical, troubleshooting, and technical communication skills
Security+ or equivalent cybersecurity certification
Active TS/SCI security clearance required.
Nice to Have
Experience supporting DoD, Intelligence Community, or other federal environments
Splunk, Elastic, or Microsoft security certifications
Experience with AWS security logging and cloud-based data sources
Experience with Python, PowerShell, or other scripting languages
dNkw8zq1v5