Quick Overview
Job Description
hackajob is collaborating with MANTECH to connect them with exceptional professionals for this role.
MANTECH seeks a motivated, career and customer-oriented Cybersecurity Operations Center Hunt Analyst to join our team in Chantilly, VA.
The CSOC Hunt Analyst will leverage their strong technical background and knowledge to support the customer's cyber defense operations, to include proactively discovering issues, monitoring and triaging security alerts, conducting initial investigations, documenting findings, escalating incidents, and maintaining situational awareness across the monitored environment.
Responsibilities include but are not limited to:
- Monitoring, acknowledging, investigating, and triaging incidents and alerts across Microsoft Sentinel and Splunk Enterprise Security environments.
- Writing and modifying Search Processing Language (SPL) and Kusto Query Language (KQL) queries to hunt for suspicious activities, conduct investigations, and analyze time-based security data.
- Supporting legacy Splunk operations while assisting with the migration of use cases, detections, telemetry, dashboards, and workflows to Microsoft Sentinel.
- Analyzing security telemetry flows through pipeline platforms such as Cribl Stream or Cribl Edge into SIEM systems and identifying missing or malformed telemetry.
- Supporting detection engineering by testing correlation searches and analytic rules, validating expected results, and documenting false positives and false negatives.
- Participating in threat hunts, cyber exercises, tabletop events, and detection-validation activities while utilizing approved AI-assisted tools to enhance research and workflows.
- Maintaining system baselines and configuration management items, including security event monitoring policies, standard operating procedures, and playbooks.
Minimum Qualifications:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, and 5+ years of related technical experience or High School/GED and 7+ years of related technical experience
- Experience performing cybersecurity alert triage, initial incident investigation, and writing/troubleshooting basic-to-intermediate SPL and KQL queries.
- Demonstrated experience filtering, summarizing, correlating, and analyzing time-based security data across endpoint, identity, network, and cloud audit logs.
- Understanding of telemetry pipelines, data onboarding, normalization, parsing, routing, enrichment, and field mapping concepts.
- Experience creating, maintaining, and communicating complex technical documentation, including standard operating procedures, investigation notes, and playbooks.
- Must meet applicable DoD 8140/8570 workforce requirements, including an active IAT Level II certification (e.g., Security+ CE, CySA+, GSEC, CCNA Security, or CASP+ CE).
Preferred Qualifications:
- Demonstrated working knowledge of Microsoft Sentinel (incidents, analytics rules, workbooks, KQL) and Splunk Enterprise Security (notable events, SPL, dashboards).
- Experience supporting an operational transition or migration from Splunk to Microsoft Sentinel and working with Cribl Stream/Edge.
- Relevant technical certifications such as Microsoft SC-200, Splunk Core/Enterprise Security, Cribl certification, or advanced cyber certifications.
- Familiarity with MITRE ATT&CK, threat-informed defense, adversary emulation, automated workflows, and AI-enabled cybersecurity tooling.
Clearance Requirements:
- An active TS/SCI with Polygraph is required
Physical Requirements:
- Must be able to remain in a stationary position 50% of the time.
- Needs to occasionally move about inside the office to access file cabinets, office machinery, etc.
- Frequently communicates with co-workers, management, and customers, which may involve delivering presentations. Must be able to exchange accurate information in these situations.
Similar jobs
- RA
Software / System Safety Engineer II
NewRaytheon
Provo, UT🇺🇸Hybrid18 hours agoTechnology - RA
Systems Engineer II - Modeling, Simulation & Analysis (Onsite)
NewRaytheon
El Paso, TX🇺🇸Hybrid18 hours agoMATLABLinearC+++1Technology - RA
Senior Systems Engineer – Software Systems (Onsite)
NewRaytheon
Provo, UT🇺🇸On-site18 hours agoMATLABAgileAzure+3Technology - RA
Principal Systems Integration and Test Engineer
NewRaytheon
Tucson, AZ🇺🇸$107.5k - $204.5k/yrHybrid18 hours agoTechnology - RA
Senior Software Engineer with Test Solutions
NewRaytheon
San Diego, CA🇺🇸$86.8k - $165.2k/yrOn-site18 hours agoTCP/IPAgileAzure+4Technology - RA
Principal Systems Engineer - Modeling Simulation & Analysis Engineer
NewRaytheon
Austin, TX🇺🇸On-site18 hours agoMATLABLinearC+++2Technology - RA
Sr. Principal Systems Engineer - Missile Guidance, Navigation, & Control Engineer
NewRaytheon
Austin, TX🇺🇸$132.4k - $251.6k/yrOn-site18 hours agoMATLABAgileC+++1Technology - RA
Principal Systems Engineer - Requirements Development/Requirements Management (Top Secret)
NewRaytheon
Austin, TX🇺🇸$107.5k - $204.5k/yrHybrid18 hours agoAgileTechnology - RA
Senior Software Engineer with Test Solutions
NewRaytheon
Miami, FL🇺🇸$86.8k - $165.2k/yrOn-site18 hours agoTCP/IPAgileAzure+4Technology - RA
Software Engineer II
NewRaytheon
San Diego, CA🇺🇸$68.9k - $131.1k/yrHybrid18 hours agoMachine LearningAgileAssembly+1Technology - RA
Systems Engineer II - Signal Processing (Onsite)
NewRaytheon
Phoenix, AZ🇺🇸Hybrid18 hours agoMATLABAzureC+++2Technology - RA
Principal Systems Engineer - Modeling Simulation & Analysis Engineer
NewRaytheon
Miami, FL🇺🇸$107.5k - $204.5k/yrOn-site18 hours agoMATLABLinearC+++2Technology