Cyber Detection Engineering Lead
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+5 more
Job description
MANTECH seeks a motivated and customer-oriented Cyber Detection Engineering Lead to join our team in McLean, VA. In this role you lead the mission to enhance cybersecurity detection and response capabilities by developing high-fidelity detection logic, automating security workflows, and strengthening threat-hunting operations. This role serves as a technical leader and liaison with customer staff, overseeing project and task workflow while improving the organization?s ability to identify, analyze, and respond to evolving cyber threats., * Developing, optimizing, and deploying custom detection rules across SIEM platforms and creating signatures and detection rules for malware and network-based threats
- Building, testing, and tuning security analytics pipelines to reduce false positives and improve alert fidelity
- Designing and implementing SOAR playbooks to streamline and enhance security operations
- Automating threat intelligence ingestion, correlation, and alerting mechanisms
- Developing integration scripts between security tools and data sources to enhance visibility and response capabilities
- Developing and maintaining robust detection logic mapped to MITRE ATT&CK techniques
- Conducting continuous security log analysis to identify anomalies and potential threats
- Collaborating with Incident Response teams to provide detection logic for emerging threats
- Leveraging EDR solutions to detect and investigate endpoint threats
- Analyzing Windows internals and system logs to identify malicious activities and forensic artifacts
- Serving as a liaison with customer staff and overseeing project and task workflow to ensure successful mission execution
Requirements
- High School Diploma and 7+ years of experience in cybersecurity with a focus on detection engineering, threat hunting, incident response, or CNO/CNE
- Experience with Python or a similar language for automation and data analysis
- Hands-on experience with SIEM platforms such as Splunk, ELK, Sentinel, Chronicle, or similar technologies
- Experience applying the MITRE ATT&CK framework for adversary tactics and techniques mapping
- Experience with YARA, Snort, Suricata, or other signature-based detection technologies
- Experience with Windows internals and forensic artifacts for endpoint security investigations, * Bachelors degree in Cybersecurity, Computer Science or other relevant field
- Experience with SOAR solutions and security automation workflows
- Experience with threat intelligence platforms and integrating threat intelligence feeds into security operations
- Prior experience in penetration testing, red teaming, or reverse engineering
- Certifications such as GCDA, GCIH, GCFA, OSCP, or Splunk Certified Security Professional
Clearance Requirements:
- Active/current TS/SCI with polygraph
Physical Requirements:
- Must be able to remain in a stationary position 50% of the time
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
Dev Digest 164: AI Agents, AI Blindspots and MCP security problems
The Overflow: Security and Privacy