SIEM/Detection Engineer

Mantis Security Corporation

$120K — $145K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of cybersecurity experience, especially with SIEM technologies
  • Strong expertise in Splunk, including SPL and alert development
  • Experience in developing and tuning security detections within a SOC
  • Proficient in security logging across various environments (Windows, Linux, cloud)
  • Skilled at onboarding and troubleshooting SIEM data sources
  • Deep understanding of attack techniques and detection logic
  • Relevant cybersecurity certification (e.g., Security+, CySA+, GIAC, Splunk)

Responsibilities

  • Develop and maintain Splunk searches, correlation rules, and dashboards
  • Enhance detection logic for identifying malicious activities and minimizing false positives
  • Onboard and validate security log sources for effective analysis
  • Identify and address gaps in security logging and detection coverage
  • Translate emerging threats into actionable detection frameworks like MITRE ATT&CK
  • Support SOC investigations through effective query development
  • Troubleshoot issues related to SIEM data ingestion and performance
  • Document detection strategies and recommend process improvements

Benefits

  • Collaborative work environment with SOC analysts and engineers
  • Opportunities for professional development and skill enhancement
  • Involvement in cutting-edge security technologies and methodologies
  • Focus on improving organization-wide security posture
  • Potential for career growth within the cybersecurity team
Full Job Description
What You'll Be Doing

As a SIEM / Detection Engineer at Mantis Security, you'll help improve how we identify and respond to threats by ensuring our security data is collected, correlated, and turned into effective detections. You'll work closely with SOC analysts and engineers to continuously improve the team's visibility and detection capabilities.
  • Develop, tune, and maintain Splunk searches, alerts, correlation rules, and dashboards
  • Build and improve detection logic to identify suspicious and malicious activity while reducing false positives
  • Support the onboarding, parsing, normalization, and validation of security log sources
  • Identify gaps in logging, telemetry, and detection coverage and help implement improvements
  • Translate emerging threats and attacker techniques into actionable detections using frameworks such as MITRE ATT&CK
  • Support SOC investigations and threat hunting by developing queries and correlating activity across multiple data sources
  • Troubleshoot SIEM data ingestion, search, alerting, and performance issues
  • Document detection logic, configurations, processes, and recommended improvements
What We're Looking For
  • 10+ years of cybersecurity experience, including hands-on experience with SIEM or security monitoring technologies
  • Strong Splunk experience, including SPL searches, correlation searches, dashboards, and alert development
  • Experience developing and tuning security detections in a SOC environment
  • Understanding of security logging across Windows, Linux, network, endpoint, identity, and cloud environments
  • Experience onboarding and troubleshooting security data sources within a SIEM
  • Strong understanding of common attack techniques and how to translate them into detection logic
  • Familiarity with MITRE ATT&CK, incident response, and threat hunting
  • Relevant cybersecurity or SIEM certification such as Security+, CySA+, GIAC, or Splunk certification

Nice to Have
  • Previous SOC Analyst or incident response experience
  • Experience supporting DoD, Intelligence Community, or other federal environments
  • Experience with AWS and cloud-based security telemetry
  • Experience with Python, PowerShell, or other scripting languages

Similar Jobs

More Jobs at Mantis Security Corporation

More Information Technology Jobs

Find similar SIEM/Detection Engineer jobs: