Content Developer (CD)

Central Strategies, LLC

Washington (District of Columbia)

Hybrid

USD 120,000 - 180,000

Full time

9 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Central Strategies, LLC is seeking an experienced Content Developer to join our team on a high-visibility cybersecurity single-award IDIQ vehicle. The role focuses on proactively searching for threats, inspecting traffic for anomalies, and developing content within Splunk SIEM using SPL language and data models to detect threats against the enterprise.

You will participate in briefings to provide expert guidance on emerging threats, interface with customers for ad-hoc requests, and contribute

Qualifications

  • Active Top Secret/SCI Clearance
  • Bachelor's degree + 12 years (or Master's + 10 years) in a relevant field
  • Minimum 8 years of incident detection/response, malware analysis, or cyber forensics
  • Strong experience with cybersecurity methodologies and SOC processes
  • Advanced knowledge of TCP/IP and large-scale log analysis across heterogeneous systems
  • Expertise in two or more areas: vulnerability assessment, IDS/IPS, access control, policy enforcement, application security, protocol analysis, firewall management, incident response, or advanced threat protection
  • Experience developing advanced correlation rules using data models and Splunk knowledge objects

Responsibilities

  • Capture use cases from subscribers or team members and develop correlation rules
  • Utilize knowledge of current threats and attack vectors to develop Splunk correlation rules for continuous monitoring
  • Develop, manage, and maintain Splunk data models
  • Review logs to ensure relevant data is available for use case development
  • Develop custom regex to create knowledge objects
  • Create advanced SPL using macros, lookups, and other techniques, along with network security signatures (SNORT, YARA)
  • Build custom dashboards and reports for stakeholders
  • Train and mentor junior staff

Skills

Splunk SPL expertise
Threat detection
Log analysis
Incident response
Data modeling
Regex development
Dashboard/report development
Mentoring junior staff

Education

Bachelor's degree + 12 years (or Master's + 10 years)

Tools

Splunk
SNORT
YARA
tstats

Job description

Central Strategies is seeking an experienced Content Developer to join our team on a highly visible cybersecurity single-award IDIQ vehicle. Duties include proactively searching for threats, inspecting traffic for anomalies and new malware patterns, and investigating and analyzing logs. The candidate will develop custom content within the Splunk SIEM using advanced SPL language and data models, as well as other network security tools, to detect threats and attacks against the enterprise.

SIEM Content Developers participate in briefings to provide expert guidance on emerging threats and act as an escalation point for analysts. The role may also require authoring reports and interfacing with customers for ad-hoc requests. In addition, the candidate will contribute recommendations to improve SOC visibility and processes.

Primary Responsibilities
  • Capture use cases from subscribers or team members and develop correlation rules
  • Utilize knowledge of current threats and attack vectors to develop Splunk correlation rules for continuous monitoring
  • Develop, manage, and maintain Splunk data models
  • Review logs to ensure relevant data is available for use case development
  • Develop custom regex to create knowledge objects
  • Create advanced SPL using macros, lookups, and other techniques, along with network security signatures (SNORT, YARA)
  • Build custom dashboards and reports for stakeholders
  • Train and mentor junior staff
Basic Qualifications
  • Active Top Secret/SCI Clearance
  • Bachelor's degree + 12 years (or Master's + 10 years) in a relevant field
  • Minimum 8 years of experience in incident detection/response, malware analysis, or cyber forensics
  • Strong experience with cybersecurity methodologies and SOC processes
  • Advanced knowledge of TCP/IP and large-scale log analysis across heterogeneous systems
  • Expertise in at least two areas: vulnerability assessment, IDS/IPS, access control, policy enforcement, application security, protocol analysis, firewall management, incident response, web filtering, or advanced threat protection
  • Experience developing advanced correlation rules using tstats and data models
  • Strong experience with Splunk knowledge objects and data models
Preferred Qualifications
  • Cloud security monitoring experience (O365, Azure, AWS)
  • Splunk Advanced Searching & Reporting training
  • Splunk certifications
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Splunk SIEM Content Developer
Senior Splunk SIEM Content Developer

Central Strategies, LLC • Washington

Hybrid
USD 120,000 - 180,000
SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate, LLC. • Richmond (VA)

On-site
USD 110,000 - 140,000
SIEM Content Developer
SIEM Content Developer

Esmcorp • Columbus (OH)

On-site
USD 95,000 - 120,000
SIEM Content Developer
SIEM Content Developer

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
SIEM CONTENT DEVELOPER
SIEM CONTENT DEVELOPER

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 90,000 - 130,000
Principal Splunk-Threat Detection & Integration Engineer
Principal Splunk-Threat Detection & Integration Engineer

Quzara LLC • United States

On-site
USD 120,000 - 160,000
SIEM Content Developer & Detection Engineer
SIEM Content Developer & Detection Engineer

Esmcorp • Columbus (OH)

On-site
USD 95,000 - 120,000
Cybersecurity Engineer 3
Cybersecurity Engineer 3

Mbi Llc • Richmond (VA)

On-site
USD 110,000 - 160,000
SIEM Content Developer
SIEM Content Developer

Electrosoft • Columbus (OH)

On-site
USD 145,000 - 155,000