Description
Summary:
This role supports critical defensive cyber operations through targeted analysis and coordination, protecting national security networks from advanced persistent threats.
Highlights:
1. Support critical defensive cyber operations
2. Protect national security networks from advanced persistent threats
3. Deliver actionable incident responses to key stakeholders
Apply Now
MANTECH seeks a motivated and mission-driven Senior Cyber Security Analyst to join our team in Springfield, VA.
This role supports critical defensive cyber operations through targeted analysis and coordination. You will help protect national security networks from advanced persistent threats by identifying emerging threats, analyzing cyber activities, and delivering actionable incident responses to key stakeholders.
Responsibilities include, but are not limited to:
Provide detection, identification, and reporting of possible cyber-attacks/intrusions, anomalous activities, and misuse activities
Characterize and analyze network traffic and system data to identify anomalous activity and potential threats to resources
Perform security event and incident correlation using information gathered from a variety of sources within the enterprise
Conduct cyber incident triage to determine scope, urgency, and potential impact; identify specific vulnerabilities and recommend expeditious remediation
Track and document cyber incidents from initial detection through final resolution
Analyze and assess damage to data and infrastructure resulting from cyber incidents
Perform cyber incident trend analysis and reporting
Work on a 24x7 Shift Work basis (4/10 shift schedule; hours dependent on location)
Minimum Qualifications:
Bachelor’s degree or 4+ years of additional IT experience in lieu of a degree
5+ years of cybersecurity experience
IAT Level II certification (GSEC, Security+, SSCP, or CCNA-Security)
Knowledge of common cybersecurity threats, attack techniques, vulnerabilities, and indicators of compromise (IOCs).
Experience with SIEM (Security Information and Event Management) tools
Experience monitoring and analyzing security events, network traffic, system logs, and other security telemetry to identify suspicious or anomalous activity.
Ability to analyze security-related data and communicate findings clearly in written and verbal reports.
Preferred Qualifications:
CSSP-IR certification (CEH, CySA+)
Experience analyzing network packet captures, firewall/proxy logs, DNS traffic, authentication logs, endpoint telemetry, and system events.
Knowledge of the MITRE ATT&CK framework and ability to map observed activity to adversary tactics, techniques, and procedures (TTPs).
Ability to work effectively in a fast-paced environment while managing multiple tasks and coordinating resources
Strong interpersonal skills, including the ability to engage with senior management
Clearance Requirements:
Must have an active TS/SCI with Polygraph clearance
Physical Requirements:
Must be able to remain in a stationary position 50% of the time
Occasionally move about inside the office to access file cabinets, office machinery, or to communicate with co-workers, management, and customers via email, phone, or virtual communication, which may involve delivering presentations
Apply Now