SOC Analyst – Senior
ManTechAbout the role
General information
Requisition # R60612 Locations USA-AL-Huntsville Posting Date 05/21/2025 Security Clearance Required TS/SCI Remote Type Onsite Time Type Full timeDescription & Requirements
Transform the future of federal services with ManTech! Join a vibrant, energetic team committed to enhancing national security and public services through innovative tech. Since 1968, we’ve partnered with Federal Civilian sectors to deliver impactful solutions. Engage in exciting projects in Digital Transformation, Cybersecurity, IT, Data Analytics and more. Ignite your career and drive change. Your journey starts now—innovate and excel with ManTech!ManTech seeks a highly skilled and knowledgeable Senior SOC Analyst to support a 24x7x365 Watch Floor team and safeguard the confidentiality, integrity, and availability of an organizations information assets. This position is located on customer site in Huntsville, AL. There are two (2) shifts available: Morning and Afternoon/Evening with rotation to support to weekends/holidays.
As a Senior SOC Analyst your duties include analyzing relevant cyber security event data and other data sources for attack indicators and potential security breaches; produce reports, assist in coordination during incidents; and coordinate with the engineering team to ensure all security monitoring systems are on-line, up to date, and fully operational.
Responsibilities for this position include but are not limited to:
Monitoring intrusion detection and prevention systems and other security event data sources daily.
Determining if security events monitored should be escalated to incidents and follow all applicable incident response and reporting processes and procedures.
Correlating data from SIEM / Splunk and Endpoint Detection and Response (EDR) systems with data from other sources such as firewall, web server, and Syslogs.
Tuning and filtering of events and information, creating custom views and content with the assistance of the Engineering and DevOps team.
Conduct monitoring, analyzing, and responding to threats, contribute to Computer Network Defense, and create solutions to augment Defensive Cyber Operations.
Lead threat hunts with other team members for potential APTs / TTPs.
Documenting each incident in the existing ticketing system; documenting procedures for handling each security event detected.
Coordinating with the DevOps and engineering team to ensure production SOC systems are operational and maintained.
Reviewing data with the Cyber Threat Intelligence Team, Incident Response Team and other appropriate groups to determine the risk and threat of an event.
Creating custom queries and develop new use cases to better correlate security event information.
Identifying misuse, malware, or unauthorized activity on monitored networks and infrastructure.
Developing and/or maintaining SOC Standard Operating Procedures (SOPs) and/or Playbooks, which define repeatable processes for acti
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s