ManTech is seeking a highly technical Cyber Engineer to join our Cyber Security Operations Center (CSOC) in McLean, VA. The ideal candidate will possess a strong background in cyber development, scripting, data engineering, and automation, with a keen understanding of endpoint detection and response (EDR), digital forensics, security orchestration, automation, and response (SOAR), and security information and event management (SIEM) tools like Splunk or Elk. This role is critical in enhancing our cyber defense capabilities through innovative solutions and automation for our Intelligence Community customer.
Responsibilities include, but are not limited to:
- Development and Scripting: Develop and maintain scripts and automation tools using Python or similar programming languages. Create and optimize Jupyter Notebooks for data analysis and reporting.
- Data Engineering: Design, build, and maintain data pipelines and ETL processes using tools such as Apache NiFi and Diode. Integrate data from various sources to support security operations and analytics.
- Automation and Orchestration: Implement and manage automation workflows using SOAR platforms. Develop automated incident response playbooks to streamline CSOC processes.
- Endpoint Detection and Response (EDR): Deploy, configure, and manage EDR solutions to detect and respond to security threats. Conduct thorough investigations and analysis of EDR alerts. Digital Forensics: Perform digital forensic investigations to identify and analyze security incidents. Collect, preserve, and analyze digital evidence in accordance with legal and organizational requirements.
- Security Information and Event Management (SIEM): Configure and maintain SIEM tools like Splunk or Elk for real-time monitoring and threat detection. Develop and refine correlation rules, dashboards, and reports to enhance threat visibility.
- Collaboration and Mentorship: Work closely with other CSOC team members to share insights and coordinate response efforts. Provide technical expertise and mentorship to junior staff. Help plan and implement cyber exercises and drills to sharpen the skills of team members.
- Continuous Improvement: Stay up to date on the latest cybersecurity trends, threats, and technologies. Identify opportunities for process improvement and implement best practices.
Minimum Qualifications:
- 10+ years of experience in a similar role within a cybersecurity environment
- Experience with Python or similar programming languages
- Experience with data engineering tools and techniques, including ETL processes and Apache NiFi or similar
- Experience with automation and SOAR platforms
- Experience using EDR solutions or digital forensics methodologies
- Experience using SIEM tools like Splunk, Elk or similar
- High School Diploma
Preferred Qualifications:
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- Relevant certifications (e.g., CISSP, GIAC, CEH)
- Strong analytical, problem-solving, and communication skills
Clearance Requirements: Current/Active TS/SCI with polygraph
Physical Requirements: Sedentary position
SKN.7.23