This job is closed
Applications are no longer available for this announcement. Explore current related opportunities below.
Job description
MANTECH seeks a motivated, career and customer-oriented Principal Cyber Threat Analyst to join our team in Denver, CO .
Responsibilities include but are not limited to:
Conducting proactive threat hunts to uncover previously undetected adversary behavior, performing in-depth host and network log analysis, and delivering systematic threat assessments
Managing cyber intelligence requirements and focusing cyber intelligence collection efforts; identifying emerging cyber technologies, capabilities, or weapons which pose a threat to US or Allied systems
Producing comprehensive cybersecurity reports, providing sourced and summarized threat intelligence, outlining threat hunt findings and limitations, and presenting recommendations to system owners, cyber defenders, and policy makers
Researching known adversarial Tactics, Techniques, and Procedures (TTPs) to identify foundational components, isolate associated host or network events, and enable threat mitigation, detection, and response
Creating custom cybersecurity dashboards to monitor host and network activity, enabling rapid identification of successful and unsuccessful intrusion attempts
Performing analysis, correlation, and attribution of incidents to Advanced Persistent Threat (APT) groups
Conducting research and analysis of APT infrastructure and malicious binaries, external cyber threat intelligence reporting, and production
Minimum Qualifications:
Bachelor’s degree or 4+ additional years of cyber experience in lieu of a degree
5+ years of cybersecurity experience
IAT Level II certification (GSEC, Security+, SSCP, or CCNA-Security)
Experience with related security technology or disciplines such as Incidents and Warnings Management, Cybersecurity Operations, or Cybersecurity Engineering
Demonstrated experience conducting proactive threat hunts across host, network, endpoint, and security telemetry.
Experience analyzing system, network, endpoint, and security logs to identify anomalous activity, Indicators of Compromise (IOCs), and adversary behavior.
Experience conducting cyber threat intelligence analysis, including assessing adversary capabilities, intent, infrastructure, and potential impact.
Preferred Qualifications:
Familiarity with SIEM and security analytics platforms such as Splunk, Microsoft Sentinel, Elastic, or similar technologies.
Experience using threat intelligence frameworks, standards, and methodologies such as MITRE ATT&CK, Cyber Kill Chain or related frameworks.
Experience creating custom detection signatures, analytic rules, correlation logic, or threat-hunting queries.
Experience developing custom cybersecurity dashboards and visualizations to monitor host, network, and security activity.
Clearance Requirements:
Must have an active TS/SCI w/Polygraph
Physical Requirements:
The person in this position must be able to remain in a stationary position 50% of the time. Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers, via email, phone, and or virtual communication, which may involve delivering presentations.
Worksite address
denver, CO, 80202, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.