> Markdown version of [/jobs/ext/3451433-senior-cyber-threat-analyst](https://www.wearedevelopers.com/jobs/ext/3451433-senior-cyber-threat-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Threat Analyst - **Company:** Mantech International Corporation - **Location:** Denver, CO, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Intelligence Analysis, Log Analysis, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, Microsoft Sentinel, Splunk - **Published:** September 16, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9166070/senior-cyber-threat-analyst ## About the Role MANTECH seeks a motivated, career and customer-oriented Senior Cyber Threat Analyst to join our team in Denver, CO., * Bachelor's degree or 4+ additional years of cyber experience in lieu of a degree * 5+ years of cybersecurity experience * IAT Level II certification (GSEC, Security+, SSCP, or CCNA-Security) * Experience with related security technology or disciplines such as Incidents and Warnings Management, Cybersecurity Operations, or Cybersecurity Engineering * Demonstrated experience conducting proactive threat hunts across host, network, endpoint, and security telemetry. * Experience analyzing system, network, endpoint, and security logs to identify anomalous activity, Indicators of Compromise (IOCs), and adversary behavior. * Experience conducting cyber threat intelligence analysis, including assessing adversary capabilities, intent, infrastructure, and potential impact., * Familiarity with SIEM and security analytics platforms such as Splunk, Microsoft Sentinel, Elastic, or similar technologies. * Experience using threat intelligence frameworks, standards, and methodologies such as MITRE ATT&CK, Cyber Kill Chain or related frameworks. * Experience creating custom detection signatures, analytic rules, correlation logic, or threat-hunting queries. * Experience developing custom cybersecurity dashboards and visualizations to monitor host, network, and security activity. Clearance Requirements: * Must have an active TS/SCI w/Polygraph Physical Requirements: * The person in this position must be able to remain in a stationary position 50% of the time. Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers, via email, phone, and or virtual communication, which may involve delivering presentations. ## Description * Conducting proactive threat hunts to uncover previously undetected adversary behavior, performing in-depth host and network log analysis, and delivering systematic threat assessments * Managing cyber intelligence requirements and focusing cyber intelligence collection efforts; identifying emerging cyber technologies, capabilities, or weapons which pose a threat to US or Allied systems * Producing comprehensive cybersecurity reports, providing sourced and summarized threat intelligence, outlining threat hunt findings and limitations, and presenting recommendations to system owners, cyber defenders, and policy makers * Researching known adversarial Tactics, Techniques, and Procedures (TTPs) to identify foundational components, isolate associated host or network events, and enable threat mitigation, detection, and response * Creating custom cybersecurity dashboards to monitor host and network activity, enabling rapid identification of successful and unsuccessful intrusion attempts * Performing analysis, correlation, and attribution of incidents to Advanced Persistent Threat (APT) groups * Conducting research and analysis of APT infrastructure and malicious binaries, external cyber threat intelligence reporting, and production ## Related Videos - [ The attacker's footprint](https://www.wearedevelopers.com/videos/375-the-attacker-s-footprint) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Leveraging Large Language Models for Legacy Code Translation: Challenges and Solutions](https://www.wearedevelopers.com/videos/1157-leveraging-large-language-models-for-legacy-code-translation-challenges-and-solutions) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)