Cyber Systems Engineering, Lead Associate

Peraton

Wiesbaden

Vor Ort

EUR 60.000 - 85.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

A cybersecurity solutions provider is seeking a Content Developer (Data Scientist) for its Regional Cyber Center-Europe program, located in Wiesbaden, Germany. The role involves developing and maintaining SIEM detection content and designing automated data analytics pipelines to improve threat detection. Candidates must have at least 5 years of relevant experience, active DoD TS/SCI clearance, and U.S. citizen status. Expertise in the Elastic Stack and strong Python skills are preferred.

Qualifikationen

  • 5 years of experience in data science, analytics, or SIEM content development.
  • Active DoD TS/SCI clearance required.
  • U.S. citizenship is mandatory.

Aufgaben

  • Develop and maintain SIEM detection content for threat detection.
  • Design data analytics pipelines for security telemetry processing.
  • Create machine learning models for anomaly detection.

Kenntnisse

Data science
Cybersecurity content development
Python
Elastic Stack
Splunk SPL

Ausbildung

Bachelor’s degree in STEM or Business Administration

Tools

Kibana
ArcSight
Azure

Jobbeschreibung

Required:
  • 5 years of data science, analytics, or SIEM content development experience with a Bachelor’s degree in a STEM field or Business Administration; 11 years of relevant experience may substitute for degree.
  • Must meet TESA Qualifications.
  • DoD 8140 - Cybersecurity (Cyber Defense Analyst) - Intermediate
  • Certifications — must hold active certifications (one of the following):
    • GDAT (GIAC Defending Advanced Threats); OR
    • GDSA (GIAC Defensible Security Architecture); OR
    • Elastic Certified Analyst or Engineer; OR
    • ArcSight Enterprise Security Manager Advanced Analyst Certified Expert; OR
    • Microsoft Certified: Cybersecurity Architect Expert; OR
    • Azure DevOps Engineer Expert; OR
    • TCM Security PNPT
  • U.S. citizenship required
  • Active DoD TS/SCI clearance
Preferred:
  • Deep expertise with Elastic Stack (Elasticsearch, Logstash, Kibana, Beats) for SIEM content development and data pipeline management
  • Proficiency with Splunk SPL for advanced search, correlation rule development, and dashboard creation
  • Strong Python skills for data processing, algorithm development, and automation scripting
  • Familiarity with machine learning frameworks (e.g., scikit-learn, TensorFlow) for anomaly detection use cases
  • Experience with Kibana or Grafana for building operational security dashboards and visualizations
  • Knowledge of KQL (Kusto Query Language) for Microsoft Sentinel or Azure Log Analytics environments
  • Familiarity with ArcSight ESM for content development and event correlation in enterprise environments
  • Experience with threat intelligence platforms (e.g., MISP, OpenCTI) for converting intelligence into detection content

Peraton is hiring a Content Developer (Data Scientist) for its' Regional Cyber Center-Europe program.

Location: On-site, Wiesbaden, Germany

Potentially 2nd/3rd Shift work

Responsibilities:
  • Develop, tune, and maintain SIEM detection content including correlation rules, alerts, and watch-listsin Elastic and/or Splunk to improve threat detection fidelity across CSSP monitoring systems
  • Design and build automated data analytics pipelines that ingest, normalize, and process large volumes of security telemetry to support real-time and historical threat analysis
  • Create custom algorithms and machine learning models for anomaly detection, behavioral base-lining, and advanced threat identification within DoD network environments
  • Develop interactive dashboards and data visualizations in Kibana, Splunk, or similar platforms that provide actionable situational awareness for analysts and leadership
  • Conduct metrics analysis to measure CSSP operational performance, detection coverage, and response effectiveness, producing regular reports for program management and government stakeholders
  • Support threat intelligence content development by translating finished intelligence products into actionable SIEM queries, detection signatures, and automated response playbooks
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Cyber Systems Engineering, Lead Associate
Cyber Systems Engineering, Lead Associate

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Software Engineering, Lead Associate
Cyber Software Engineering, Lead Associate

Peraton • Wiesbaden

Vor Ort
EUR 60.000 - 80.000
Senior Cyber Threat Analyst / Active TS/SCI
Senior Cyber Threat Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 70.000 - 100.000
Senior Cyber Response Analyst / Active TS/SCI
Senior Cyber Response Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Incident Handling Analyst / Active TS/SCI
Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Cyber Response Analyst / Active TS/SCI
Cyber Response Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Wiesbaden

Vor Ort
EUR 70.000 - 90.000
Senior Cyber Incident Handling Analyst / Active TS/SCI
Senior Cyber Incident Handling Analyst / Active TS/SCI

Peraton • Erbenheim

Vor Ort
EUR 88.000 - 142.000
IT Security Analyst, 3rd Level
IT Security Analyst, 3rd Level

Jobtailor • Köln

Vor Ort
EUR 60.000 - 90.000
Senior Security Analyst
Senior Security Analyst

Base Cyber Security • Münster

Hybrid
EUR 70.000 - 110.000