Herndon, Virginia

Where applicable, confirmation that you meet customer requirements for facility access which may include proof of vaccination and/or attestation and testing, unless an accommodation has been approved.

Secure our Nation, Ignite your Future

Can you protect and defend the most coveted targets in the world to ensure the safety of information systems assets and protect systems from intentional or inadvertent access or destruction? Join ManTech and help protect our national security while working on innovative projects that offer opportunities for advancement. We encourage our team members to share and grow their skills and expertise while creating robust and state-of-the-art solutions.

Join our Adversarial Pursuit team as a Cyber Threat Hunt Subject Matter Expert (SME) on this Agency-level Cyber Security support contract. Help strengthen an established unit of elite cyber defense experts by advising strategic vision and tactical implementation to protect our customer's varied networks from all enemies. 

Responsibilities include, but are not limited to:

  • Provide strategic and tactical direction to cyber hunters and leadership based on trends and actionable intelligence related to threat capabilities

  • Coordinate hunt activities between various internal and external hunt groups  

  • Construct and exploit threat intelligence to detect, respond, and defeat advanced persistent threats (APTs)

  • Fully analyze network and host activity in successful and unsuccessful intrusions by advanced attackers

  • Build fly-away kits utilizing an agile approach to identify the appropriate tools and technologies necessary to conduct hunt missions

  • Conduct advanced threat hunt operations using known adversary tactics, techniques and procedures as well as indicators of attack in order to detect adversaries with persistent access to the enterprise

  • Create and add custom signatures, to mitigate highly dynamic threats to the enterprise using the latest threat information obtained from multiple sources

  • Perform malware analysis on samples obtained during the course of an investigation or hunt operation in order to create custom signatures

  • Develop and produce reports on all activities and incidents to help maintain day to day status, develop and report on trends, and provide focus and situational awareness on all issues 

  • Piece together intrusion campaigns, threat actors, and nation-state organizations

  • Manage, share, and receive intelligence on APT adversary groups

  • Generate intelligence from their own data sources and share it accordingly

  • Identify, extract, and leverage intelligence from APT intrusions

  • Expand upon existing intelligence to build profiles of adversary groups Leverage intelligence to better defend against and respond to future intrusions

  • Correlate data from intrusion detection and prevention systems with data from other sources such as firewall, web server, and DNS logs

  • Notify the management team of significant changes in the security threat against the government networks in a timely manner and in writing via established reporting methods

  • Coordinate with appropriate organizations within the intelligence community regarding possible security incidents.  Conduct intra-office research to evaluate events as necessary, maintain the current list of coordination points of contact.

  • Review assembled data with firewall administrators, engineering, system administrators and other appropriate groups to determine the risk of a given event

  • Maintain knowledge of the current security threat level by monitoring related Internet postings, Intelligence reports, and other related documents as necessary

Required Experience/Skills:

  • Minimum of 10 years of progressively responsible experience in Computer Science, Cyber Security, Security Engineering, Network Engineering with emphasis in cyber security issues and operations, computer incident response, systems architecture, data management Or 4 additional years of experience in lieu of degree

  • Expert analytical and problem solving skills

  • Demonstrated experience working nation state intrusion sets

  • The ideal candidate will have expert level experience in one or more of the following disciplines:

  • Windows and/or Linux operating systems

  • Network forensics

  • Demonstrated ability using at enterprise scale:

  • SysMon or EDR solutions for host-based Cyber Threat Hunting, or

  • Netflow/pcap or NDR solutions for network-oriented Cyber Threat Hunting

  • Malware analysis/reverse engineering

  • Exploit development

  • On-net pursuit/response

Required Tools:

  • Familiarity with the following classes of enterprise cyber defense technologies:

  • Security Information and Event Management (SIEM) systems

  • Network Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)

  • Host Intrusion Detection System/Intrusion Prevention Systems (IDS/IPS)

  • Network and Host malware detection and prevention (NDR/EDR)

  • Network and Host forensic applications

  • Web/Email gateway security technologies

  • Security Orchestration, Automation, and Response (SOAR)


Required Certifications:
CISSP or CEH
DoD 8570 IAT Level III or CSSP-SPM

Required Degree:
BS (bachelor's degree in electrical engineering, computer engineering, computer science, or other closely related IT discipline)

 
Security Requirements:
TS/SCI with Poly

5.24.IGLB.JD.22

For all positions requiring access to technology/software source code that is subject to export control laws, employment with the company is contingent on either verifying U.S.-person status or obtaining any necessary license. The applicant will be required to answer certain questions for export control purposes, and that information will be reviewed by compliance personnel to ensure compliance with federal law. ManTech may choose not to apply for a license for such individuals whose access to export-controlled technology or software source code may require authorization and may decline to proceed with an applicant on that basis alone.

ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.

If you require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please contact ManTech's Corporate EEO Department at (703) 218-6000. ManTech is an affirmative action/equal opportunity employer - minorities, females, disabled and protected veterans are urged to apply. ManTech's utilization of any external recruitment or job placement agency is predicated upon its full compliance with our equal opportunity/affirmative action policies. ManTech does not accept resumes from unsolicited recruiting firms. We pay no fees for unsolicited services.

If you are a qualified individual with a disability or a disabled veteran, you have the right to request an accommodation if you are unable or limited in your ability to use or access http://www.mantech.com/careers/Pages/careers.aspx as a result of your disability. To request an accommodation please click careers@mantech.com and provide your name and contact information.

Herndon, Virginia

ManTech was founded in 1968 to provide advanced technological services to the United States government. We began with a single contract with the U.S. Navy to develop war-gaming models for the submarine community. Over the years, our government's technology needs have increased dramatically in scope and sophistication, and we have grown to meet that challenge.

 

For more than 4 decades, we kept a careful eye on where emerging technologies were taking the government, and we developed the resources to master those technologies—by staying close to our customers and anticipating their needs, hiring talented professionals to propel us into the future, and acquiring companies with proven capabilities.

 

Today, we are a multi-billion-dollar public company that provides the innovation, adaptability, and critical thinking our government needs for success in defense, intelligence, law enforcement, science, administration, health, and other fields—throughout the nation and in many countries throughout the world. We are now applying the lessons learned in the unforgiving arena of national security to help the private sector protect networks and critical information.

Similar jobs