{"schemaVersion":"jobsearcher.job.v1","id":"564ece3d213175efa4ecb54b","url":"https://jobsearcher.com/jobs/564ece3d213175efa4ecb54b","canonicalUrl":"https://jobsearcher.com/jobs/564ece3d213175efa4ecb54b","title":"SIEM/Detection Engineer","description":"Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!\n\nWhat You'll Be Doing\n\nAs a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.\nDevelop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards\nBuild and improve detection logic to identify suspicious and malicious activity while reducing false positives\nSupport the onboarding, parsing, normalization, and validation of security log sources\nIdentify gaps in logging, telemetry, and detection coverage and help implement improvements\nTranslate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK\nSupport SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources\nTroubleshoot SIEM data ingestion, search, alerting, and performance issues\nDocument detection logic, configurations, processes, and recommended improvements\nWhat We're Looking For\n10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies\nStrong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development\nExperience developing and tuning security detections in a SOC environment\nUnderstanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments\nExperience onboarding and troubleshooting security data sources within a SIEM\nStrong understanding of common attack techniques and how to translate them into detection logic\nFamiliarity with MITRE ATT&CK, incident response, and threat hunting\nRelevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification\n\nNice to Have\nPrevious SOC Analyst or incident response experience\nExperience supporting DoD, Intelligence Community, or other federal environments\nExperience with AWS and cloud-based security telemetry\nExperience with Python, PowerShell, or other scripting languages\ndNkw8zq1v5","company":"Mantis Security","rawCompany":"mantis security","city":"Reston","state":"VA","isRemote":false,"isActive":false,"createdAt":"2026-09-10T09:42:35.432Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"SIEM/Detection Engineer","description":"Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!\n\nWhat You'll Be Doing\n\nAs a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.\nDevelop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards\nBuild and improve detection logic to identify suspicious and malicious activity while reducing false positives\nSupport the onboarding, parsing, normalization, and validation of security log sources\nIdentify gaps in logging, telemetry, and detection coverage and help implement improvements\nTranslate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK\nSupport SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources\nTroubleshoot SIEM data ingestion, search, alerting, and performance issues\nDocument detection logic, configurations, processes, and recommended improvements\nWhat We're Looking For\n10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies\nStrong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development\nExperience developing and tuning security detections in a SOC environment\nUnderstanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments\nExperience onboarding and troubleshooting security data sources within a SIEM\nStrong understanding of common attack techniques and how to translate them into detection logic\nFamiliarity with MITRE ATT&CK, incident response, and threat hunting\nRelevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification\n\nNice to Have\nPrevious SOC Analyst or incident response experience\nExperience supporting DoD, Intelligence Community, or other federal environments\nExperience with AWS and cloud-based security telemetry\nExperience with Python, PowerShell, or other scripting languages\ndNkw8zq1v5","datePosted":"2026-09-10T09:42:35.432Z","dateModified":"2026-09-10T09:42:35.432Z","hiringOrganization":{"@type":"Organization","name":"Mantis Security","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Reston","addressRegion":"VA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"564ece3d213175efa4ecb54b"},"url":"https://jobsearcher.com/jobs/564ece3d213175efa4ecb54b"}}