SIEM CONTENT DEVELOPER

iP-Plus Consulting, Inc.

Columbus (OH)

On-site

USD 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

iP-Plus Consulting, Inc. is seeking a Threat Detection Analyst to research and develop new use cases based on emerging threats and threat intelligence.

You will work with stakeholders and cybersecurity tool SMEs to identify gaps in protection and analytics capabilities, develop custom SIEM scripts, and review data feeds for improvements. The role focuses on creating alerting priorities and signatures aligned with MITRE ATT&CK and defense-in-depth principles, collaborating across programs.

Qualifications

  • 5 years of relevant IT experience.
  • 3 years working with a SIEM in a content development or Incident Response role.
  • 3 years of System and/or Network Administration experience.
  • Understanding of various log formats.
  • Understanding of the MITRE ATT&CK framework.
  • Strong understanding of network architecture.
  • Experience developing and maintaining scripts (PowerShell, Python or SPL).
  • Understanding of Defense-in-Depth.
  • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5).

Responsibilities

  • Researches and develops new threat detection use cases based on emerging threats, threat intelligence research and Threat Detection Analyst feedback.
  • Works with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities.
  • Develops custom scripts to enhance SIEM functionality.
  • Reviews the quality of data feeds and recommend and/or implement improvements.
  • Collaborates with stakeholders to identify critical systems and application components to develop alerting priorities and create signatures tailored to individual programs and applications.

Skills

SIEM experience
System & Network administration
MITRE ATT&CK knowledge
Scripting (PowerShell/Python/SPL)
Threat detection concepts
Defense-in-Depth
Log formats knowledge
Network architecture understanding
DOD Top Secret Clearance

Job description

Researches and develops new threat detection use cases based on emerging threats, threat intelligence research and Threat Detection Analyst feedback. Works with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities. Develops custom scripts to enhance SIEM functionality. Reviews the quality of data feeds and recommend and/or implement improvements. Collaborates with stakeholders to identify critical systems and application components to develop alerting priorities and create signatures tailored to individual programs and applications.

Required Qualifications:

  • 5 years of relevant IT experience
  • 3 years working with a SIEM in a content development or Incident Response role
  • 3 years of System and/or Network Administration experience
  • Understanding of various log formats
  • Understanding of the MITRE ATT&CK framework
  • Strong understanding of network architecture
  • Experience developing and maintaining scripts (preferably using Powershell, Python or SPL)
  • Understanding of Defense-in-Depth
  • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5)

REQ: CSSP

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Threat Detection SIEM Content Engineer
Threat Detection SIEM Content Engineer

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 90,000 - 130,000
Cybersecurity Detection Engineer — SIEM & Threat Analytics
Cybersecurity Detection Engineer — SIEM & Threat Analytics

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
SIEM Analyst
SIEM Analyst

Mantis Security Corporation • Reston (VA)

On-site
USD 110,000 - 170,000
Cybersecurity Analytics Engineer - SIEM & Threat Detection
Cybersecurity Analytics Engineer - SIEM & Threat Detection

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 180,000
Cybersecurity Advanced Analytics Specialist
Cybersecurity Advanced Analytics Specialist

Si Tec Consulting • Springfield (VA)

On-site
USD 150,000 - 210,000
Cybersecurity Advanced Analytics Specialist
Cybersecurity Advanced Analytics Specialist

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 180,000