Senior Splunk SIEM Content Developer

Central Strategies, LLC

Washington (District of Columbia)

Hybrid

USD 120,000 - 180,000

Full time

12 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Central Strategies, LLC is seeking an experienced Content Developer to join our team on a high-visibility cybersecurity single-award IDIQ vehicle. The role focuses on proactively searching for threats, inspecting traffic for anomalies, and developing content within Splunk SIEM using SPL language and data models to detect threats against the enterprise.

You will participate in briefings to provide expert guidance on emerging threats, interface with customers for ad-hoc requests, and contribute

Qualifications

  • Active Top Secret/SCI Clearance
  • Bachelor's degree + 12 years (or Master's + 10 years) in a relevant field
  • Minimum 8 years of incident detection/response, malware analysis, or cyber forensics
  • Strong experience with cybersecurity methodologies and SOC processes
  • Advanced knowledge of TCP/IP and large-scale log analysis across heterogeneous systems
  • Expertise in two or more areas: vulnerability assessment, IDS/IPS, access control, policy enforcement, application security, protocol analysis, firewall management, incident response, or advanced threat protection
  • Experience developing advanced correlation rules using data models and Splunk knowledge objects

Responsibilities

  • Capture use cases from subscribers or team members and develop correlation rules
  • Utilize knowledge of current threats and attack vectors to develop Splunk correlation rules for continuous monitoring
  • Develop, manage, and maintain Splunk data models
  • Review logs to ensure relevant data is available for use case development
  • Develop custom regex to create knowledge objects
  • Create advanced SPL using macros, lookups, and other techniques, along with network security signatures (SNORT, YARA)
  • Build custom dashboards and reports for stakeholders
  • Train and mentor junior staff

Skills

Splunk SPL expertise
Threat detection
Log analysis
Incident response
Data modeling
Regex development
Dashboard/report development
Mentoring junior staff

Education

Bachelor's degree + 12 years (or Master's + 10 years)

Tools

Splunk
SNORT
YARA
tstats

Job description

Central Strategies, LLC is seeking an experienced Content Developer to join our team on a high-visibility cybersecurity single-award IDIQ vehicle. The role focuses on proactively searching for threats, inspecting traffic for anomalies, and developing content within Splunk SIEM using SPL language and data models to detect threats against the enterprise.

You will participate in briefings to provide expert guidance on emerging threats, interface with customers for ad-hoc requests, and contribute

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Content Developer (CD)
Content Developer (CD)

Central Strategies, LLC • Washington

Hybrid
USD 120,000 - 180,000
SIEM Content Developer & Detection Engineer
SIEM Content Developer & Detection Engineer

Esmcorp • Columbus (OH)

On-site
USD 95,000 - 120,000
SIEM Content Engineer for Threat Detection & Automation
SIEM Content Engineer for Threat Detection & Automation

AGE Solutions • Columbus (OH)

On-site
USD 115,000 - 135,000
Paid Leave
Bonuses
401k Match
+7
SIEM Content & Detection Engineer
SIEM Content & Detection Engineer

DirectViz Solutions, LLC • Columbus (OH)

On-site
USD 110,000 - 150,000
Competitive compensation
Comprehensive medical benefits
401(k) match
+4
SIEM Content Developer
SIEM Content Developer

Esmcorp • Columbus (OH)

On-site
USD 95,000 - 120,000
SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Senior Splunk Security Engineer — SIEM, Threat Intel & IR
Senior Splunk Security Engineer — SIEM, Threat Intel & IR

Unity Technologies Corporation • Columbus (OH)

On-site
USD 110,000 - 160,000
SIEM Content Developer
SIEM Content Developer

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
SIEM Threat Detection Content Engineer
SIEM Threat Detection Content Engineer

Age-Solutions • Columbus (OH)

On-site
USD 104,000 - 127,000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
SIEM Content Developer - Threat Detection (TS Clearance)
SIEM Content Developer - Threat Detection (TS Clearance)

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6