JOBSEARCHER

Cloud Security Engineer

MANTECH seeks a highly technical Cloud Security Engineer to join our team in Herndon, VA. Join a dedicated team of cybersecurity experts focused on enhancing the customer’s cloud incident response posture. The ideal candidate brings a strong background in Amazon Web Services (AWS), cyber development, scripting, and automation, coupled with deep expertise in Security Information and Event Management (SIEM) tools.Responsibilities include, but are not limited to:Systems Design & Architecture: Consult on the design, architecture, and implementation of cloud security monitoring systems at enterprise scale.Development and Scripting: Develop and maintain scripts and automation tools using Python or similar programming languages.Automation and Orchestration: Design and implement automated incident response playbooks to streamline CSOC processes.Collaboration and Mentorship: Work closely with CSOC team members to share insights and coordinate response efforts. Provide technical expertise and mentorship to junior staff; plan and implement cyber exercises and drills to sharpen team skills; and prepare reference and training materials for cloud and incident response.Continuous Improvement: Stay current on cybersecurity trends, threats, and technologies. Identify opportunities for process improvement and implement best practices. Maintain up-to-date knowledge of relevant AI concepts pertaining to cloud and incident response security.Splunk Detection Development: Develop, tune, and optimize detection rules for AWS and other cloud-based platforms using Splunk Query Language.Minimum Qualifications:7+ years of experience with cloud security or cyber operations7+ years of experience with Operating Systems, Network Infrastructure, Security Principles or System Architecture5+ years of experience with AWS3+ years of experience coding and scripting in PythonPreferred Qualifications:Bachelor’s degree in Computer Science, Information Technology, or a related technical fieldExperience with automation and SOAR platformsExperience in one of the following: incident response, threat hunt, or detection engineeringExperience with Azure/OCIRelevant certifications (e.g., CISSP, GIAC, CEH)Clearance Requirements: Active/current TS/SCI with Polygraph is required for this positionPhysical Requirements: Must be able to remain in a stationary position 50% of the time