SIEM Content Developer

Esmcorp

Columbus (OH)

On-site

USD 95,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Enterprise Solutions and Management (ESM) seeks a SIEM Content Developer to research and develop threat-detection use cases, collaborating with stakeholders to identify gaps in controls and data quality. The role involves scripting to enhance SIEM capabilities and prioritizing alerting for critical systems.

Candidate must have CSSP Analyst certification or equivalent, SIEM content development experience, and relevant IT background. Top Secret clearance is required for federal programs.

Qualifications

  • Five years of relevant IT experience.
  • Three years with a SIEM in content development or incident response.
  • Three years of system and/or network administration experience.
  • Must maintain CSSP Analyst certification (CEH, CFR, GCIA, GCISP) or equivalent.
  • SIEM certification required.

Responsibilities

  • Research and develop threat detection use cases based on emerging threats, threat intelligence, and analyst feedback.
  • Collaborates with stakeholders and cybersecurity tool SMEs to identify gaps in security controls, analytics, and data quality.
  • Develops custom scripts to enhance SIEM capabilities and improves data feeds to support effective detection.
  • Identifies critical systems and application components to establish alerting priorities and develop tailored detection signatures.

Skills

data interpretation
log formats
MITRE ATT&CK
python powershell spl
defense in depth

Job description

Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that provides strategic IT services that meet mission needs for Defense and Federal customers. We are hiring SIEM Content Developer to support an enterprise-level program within a federal environment.

Job Description and Responsibilities

Research and develop threat detection use cases based on emerging threats, threat intelligence, and analyst feedback. Collaborates with stakeholders and cybersecurity tool SMEs to identify gaps in security controls, analytics, and data quality. Develops custom scripts to enhance SIEM capabilities and improves data feeds to support effective detection. Identifies critical systems and application components to establish alerting priorities and develop tailored detection signatures.

Required Knowledge, Skills and Abilities (KSA)
  • Skill collecting and interpreting qualitative and quantitative data from multiple sources
  • Knowledge of log formats and network architecture.
  • Knowledge of the MITRE ATT&CK framework
  • Skill developing and maintaining scripts with Python, Powershell or SPL
  • Ability to understand Defense in Depth
Desired KSA
  • Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations
  • Candidate must communicate effectively with team members, team lead, management, and government customer(s)
  • Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision
Minimum Training, Education, and Certifications
  • Five (5) years of relevant IT experience
  • Three (3) years working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and/or Network Administration experience
  • Must maintain CSSP Analyst certification by having one of the following or equivalent - (CEH, CFR, GCIA, GCISP)
  • SIEM certification
Minimum Clearance
  • Top Secret
Physical Requirements
  • Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Regularly required to stoop, kneel, bend, crouch and lift up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus.
  • Physical demands associated with this position include extensive walking (including stairs) throughout offices and between buildings. May require use of public transportation, personal or Government vehicle to drive to local and/or remote office locations.
Additional Requirements
  • Other duties as assigned

ESM provides equal employment opportunity to all individuals regardless of race, color, creed, religion, gender, age, sexual orientation, national origin or ancestry, disability, genetic information, veteran status, gender identification or any other characteristic protected by state, federal or local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
SIEM Content Developer & Detection Engineer
SIEM Content Developer & Detection Engineer

Esmcorp • Columbus (OH)

On-site
USD 95,000 - 120,000
SIEM Content Developer
SIEM Content Developer

electro soft • Columbus (OH)

On-site
USD 145,000 - 155,000
SIEM CONTENT DEVELOPER
SIEM CONTENT DEVELOPER

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 90,000 - 130,000
Incident Response & Threat Detection Analyst
Incident Response & Threat Detection Analyst

Esmcorp • Columbus (OH)

On-site
USD 90,000 - 130,000
SIEM Content Developer
SIEM Content Developer

Electrosoft • Columbus (OH)

On-site
USD 145,000 - 155,000
SIEM Content Developer
SIEM Content Developer

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
SIEM Content Developer - Threat Detection & Automation
SIEM Content Developer - Threat Detection & Automation

electro soft • Columbus (OH)

On-site
USD 145,000 - 155,000
SIEM Content Engineer for Threat Detection & Automation
SIEM Content Engineer for Threat Detection & Automation

AGE Solutions • Columbus (OH)

On-site
USD 115,000 - 135,000
Paid Leave
Bonuses
401k Match
+7
SIEM Content Developer
SIEM Content Developer

Amyx, Inc. • Fort Belvoir (VA)

On-site
USD 90,000 - 120,000
Medical, Dental, and Vision Plans
401(k) with matching contributions
Flexible Spending Accounts
+3