waypointjobs

MANTECH

Principal Cyber Threat Analyst

denver, CO

Check who can apply and the requirements below before continuing.

This job is closed

Applications are no longer available for this announcement. Explore current related opportunities below.

Job description

MANTECH seeks a motivated, career and customer-oriented Principal Cyber Threat Analyst to join our team in Denver, CO .

Responsibilities include but are not limited to:

Conducting proactive threat hunts to uncover previously undetected adversary behavior, performing in-depth host and network log analysis, and delivering systematic threat assessments

Managing cyber intelligence requirements and focusing cyber intelligence collection efforts; identifying emerging cyber technologies, capabilities, or weapons which pose a threat to US or Allied systems

Producing comprehensive cybersecurity reports, providing sourced and summarized threat intelligence, outlining threat hunt findings and limitations, and presenting recommendations to system owners, cyber defenders, and policy makers

Researching known adversarial Tactics, Techniques, and Procedures (TTPs) to identify foundational components, isolate associated host or network events, and enable threat mitigation, detection, and response

Creating custom cybersecurity dashboards to monitor host and network activity, enabling rapid identification of successful and unsuccessful intrusion attempts

Performing analysis, correlation, and attribution of incidents to Advanced Persistent Threat (APT) groups

Conducting research and analysis of APT infrastructure and malicious binaries, external cyber threat intelligence reporting, and production

Minimum Qualifications:

Bachelor’s degree or 4+ additional years of cyber experience in lieu of a degree

5+ years of cybersecurity experience

IAT Level II certification (GSEC, Security+, SSCP, or CCNA-Security)

Experience with related security technology or disciplines such as Incidents and Warnings Management, Cybersecurity Operations, or Cybersecurity Engineering

Demonstrated experience conducting proactive threat hunts across host, network, endpoint, and security telemetry.

Experience analyzing system, network, endpoint, and security logs to identify anomalous activity, Indicators of Compromise (IOCs), and adversary behavior.

Experience conducting cyber threat intelligence analysis, including assessing adversary capabilities, intent, infrastructure, and potential impact.

Preferred Qualifications:

Familiarity with SIEM and security analytics platforms such as Splunk, Microsoft Sentinel, Elastic, or similar technologies.

Experience using threat intelligence frameworks, standards, and methodologies such as MITRE ATT&CK, Cyber Kill Chain or related frameworks.

Experience creating custom detection signatures, analytic rules, correlation logic, or threat-hunting queries.

Experience developing custom cybersecurity dashboards and visualizations to monitor host, network, and security activity.

Clearance Requirements:

Must have an active TS/SCI w/Polygraph

Physical Requirements:

The person in this position must be able to remain in a stationary position 50% of the time. Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers, via email, phone, and or virtual communication, which may involve delivering presentations.

Worksite address

denver, CO, 80202, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Explore related searches

Current related jobs