Enable job alerts via email!

Content Developer (SIEM Cyber Security)

sss-anc

San Antonio (TX)

On-site

USD 60,000 - 100,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a skilled Content Developer specializing in SIEM Cyber Security. This role at Lackland Air Force Base involves analyzing DCO events, developing dashboards, and enhancing security measures through advanced SIEM technologies. The ideal candidate will possess extensive experience with SIEM tools such as ArcSight and Splunk, alongside a strong background in network traffic analysis and cybersecurity protocols. Join a team that values innovation and offers a comprehensive benefits package, including medical, dental, and vision insurance, paid time off, and a 401(k) plan with company matching. This is a unique opportunity to contribute to critical security operations in a dynamic environment.

Benefits

Paid holidays
Paid time off
Medical insurance
Dental insurance
Vision insurance
Flexible spending accounts
Short and long term disability
Company paid life insurance
401(k) with company match
Tuition reimbursement

Qualifications

  • 5+ years of experience with SIEM technologies like ArcSight, Splunk, and ELK.
  • Extensive knowledge of network traffic analysis and cybersecurity practices.

Responsibilities

  • Analyze DCO events and apply SIEM best practices.
  • Develop dashboards and visualizations for threat detection.
  • Provide training and knowledge transfer to personnel.

Skills

SIEM technology
Network Traffic Analysis
Cybersecurity Knowledge
Python
PowerShell
IDS/IPS systems
MITRE ATT&CK framework
Security Orchestration Automation Response (SOAR)

Education

BA/BS or MA/MS in relevant field
SANS GCDA or equivalent certification

Tools

ArcSight
Splunk
ELK
Phantom
Demisto

Job description

Lackland Air Force Base, San Antonio, TX, USA ● San Antonio, TX, USA Req #7127

Friday, February 7, 2025

STS Systems Support, LLC. (SSS) is seeking a Content Developer (SIEM Cyber Security) at Lackland AFB in San Antonio, TX.

Requirements:

  • Active TS/SCI
  • More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK.
  • More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS
  • Extensive knowledge with IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (i.e., Air Force, Navy, Army, DC3, DISA).
  • More than three (3) years of experience with Network Traffic Analysis; ports and protocols. SANS GCDA or equivalent certification(s).
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)
  • More than one (1) year of experience with Security, Orchestration, Automation, and Response (SOAR) platforms such as Phantom and/or Demisto. Proficient in Python and PowerShell.

Duties:

  • Analyze DCO events.
  • Apply current industry SIEM best‐practices.
  • Use security alerts correlated with log enrichment data to enhance the operator’s ability to identify real attacks.
  • Establish security control effectiveness and monitor for unauthorized outbound connections.
  • Create detections by analyzing log data across the enterprise. (CDRL A007)
  • Develop dashboards and visualizations to identify adversarial activity. (CDRL A007)
  • Use log data to establish and implement virtual tripwires for early detection.
  • Analyze and ingest security logs into the SIEM in order to optimize for performance of the SIEM.
  • Conduct designing, implementing, and testing of various SIEM solutions. (CDRL A007)
  • Create and support the creation of SIEM Use Cases and understand what alerts and log enrichment is necessary to meet the required acceptable false positive rate. (CDRL A008)
  • Create, test, and validate filters and rules. (CDRL A007)
  • Build and implement event correlation rules, logic, and content in the SIEM. (CDRL A007)
  • Tune SIEM event correlation rules and logic to filter out security events associated with known and well established network behavior, known false positives and/or known errors.
  • Analyze malware threats to develop behavior based detections that alert and/or prevent malicious activity.
  • Automate tasks in the SIEM using a common programming or scripting language.
  • Create scheduled and ad‐hoc reporting with SEIM tools. (CDRL A007 and A008)
  • Create and maintain SIEM documentation. (CDRL A008)
  • Develop and execute a process to review and maintain SIEM resources such as rules, filters, lists, trends and reports.
  • Utilize SIEM to develop metrics collection, analysis, and create reports upon request.
  • Provide training to government personnel as requested.
  • Provide knowledge transfer of tools, processes and procedures to government personnel as requested.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).

Support operational leaderships tasking as it relates to Content Development functions and responsibilities.

STS Systems Support, LLC offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

SSS is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Artist in Residence: Content Creator (San Antonio)

Jolt Action

San Antonio

Remote

USD 60’000 - 80’000

Yesterday
Be an early applicant

Content Developer (SIEM Cyber Security)

Bristol Bay Native Corporation

San Antonio

On-site

USD 60’000 - 100’000

30+ days ago

Business Development & Capture Associate (DoD Domain | Remote)

Rackner

Washington

Remote

USD 50’000 - 90’000

5 days ago
Be an early applicant

Business Development & Capture Manager (DoD Domain | Remote)

Rackner

San Antonio

Remote

USD 80’000 - 120’000

5 days ago
Be an early applicant

Field Marketing Specialist

PowerDMARC

San Antonio

Remote

USD 50’000 - 65’000

2 days ago
Be an early applicant

Cybersecurity - TVM - Vulnerability Management - Senior - Consulting - Location OPEN 1

EY

Tampa

Remote

USD 90’000 - 120’000

Today
Be an early applicant

AI Training for Business to Business Digital Domain

Outlier

Ponce

Remote

USD 80’000 - 100’000

Yesterday
Be an early applicant

Tampa Cyber Security Tutor

Varsity Tutors, a Nerdy Company

Tampa

Remote

USD 80’000 - 100’000

Yesterday
Be an early applicant

St. Petersburg Cyber Security Tutor

Varsity Tutors, a Nerdy Company

Saint Petersburg

Remote

USD 80’000 - 100’000

Yesterday
Be an early applicant