Avatar for Mantis Security
Mantis Security
Actively Hiring
Cybersecurity solutions for sensitive information assets

SIEM/Detection Engineer

  • |10 years of exp
  • |Full Time
Posted: 1 month ago
Job Location
Remote Work Policy

In office

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Identity
Linux
Dashboards
Windows
Splunk
Network
Incident Response
Threat Hunting
Endpoint
MITRE ATT&CK
Cloud Environments
Alert Development
Correlation Searches
Security Detections
Common Attack Techniques
SPL Searches
Security Data Sources

About the job

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next SIEM Engineer to join our team of experts!

What You'll Be Doing

As a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.

  • Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
  • Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
  • Support the onboarding, parsing, normalization, and validation of security log sources
  • Identify gaps in logging, telemetry, and detection coverage and help implement improvements
  • Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
  • Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
  • Troubleshoot SIEM data ingestion, search, alerting, and performance issues
  • Document detection logic, configurations, processes, and recommended improvements

What We're Looking For

  • 10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
  • Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
  • Experience developing and tuning security detections in a SOC environment
  • Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
  • Experience onboarding and troubleshooting security data sources within a SIEM
  • Strong understanding of common attack techniques and how to translate them into detection logic
  • Familiarity with MITRE ATT&CK, incident response, and threat hunting
  • Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification

Nice to Have

  • Previous SOC Analyst or incident response experience
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Experience with AWS and cloud-based security telemetry
  • Experience with Python, PowerShell, or other scripting languages

About the company

Mantis Security company logo
Cybersecurity solutions for sensitive information assets11-50 Employees
Learn more about Mantis Security image