SIEM Content Developer

Y-Tech

Fort Belvoir (VA)

On-site

USD 90,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Y-Tech is seeking a Threat Detection Analyst to research and develop new use cases for emerging threats and threat intelligence. You will work with stakeholders and cybersecurity tool SMEs to tailor analytics, create specific signatures for programs, and enhance SIEM capabilities with custom scripts.

The role requires strong SIEM experience, incident response background, and hands-on scripting in PowerShell/Python. A DOD Top Secret clearance or eligibility for IT-I/T5 is mandatory.

Qualifications

  • Five years of IT experience.
  • Three years with a SIEM in content development or Incident Response.
  • Three years of System and/or Network Administration experience.
  • Understanding of log formats.
  • Understanding of MITRE ATT&CK framework.
  • Strong understanding of network architecture.
  • Experience developing and maintaining scripts (PowerShell, Python or SPL).
  • Understanding of Defense-in-Depth.
  • Must possess a current DOD Top Secret Clearance and be eligible for IT-I/Tier 5 clearance.
  • Onboarding requires IT-II and CNDSP-IR CE certifications within six months.

Responsibilities

  • Researches and develops new threat detection use cases based on emerging threats and threat intelligence.
  • Collaborates with stakeholders to identify critical systems and develop alerting priorities and signatures.
  • Develops custom scripts to enhance SIEM functionality.
  • Reviews data feeds quality and recommends improvements.

Skills

SIEM experience
Incident Response
System Administration
Network Administration
Scripting
PowerShell
Python
MITRE ATT&CK
Network Architecture
Threat Detection
Defense in Depth

Education

IT-II Certification (Baseline)
CNDSP-CSSP-IR Certification
CNDS CE Certification

Job description

Researches and develops new threat detection use cases based on emerging threats, threat intelligence research and Threat Detection Analyst feedback. Works with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities. Develops custom scripts to enhance SIEM functionality. Reviews the quality of data feeds and recommend and\/or implement improvements.

Collaborates with stakeholders to identify critical systems and application components to develop alerting priorities and create signatures tailored to individual programs and applications.

Minimum Requirements:

  • Five (5) years of relevant IT experience
  • Three (3) years working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and\/or Network Administration experience
  • Understanding of various log formats
  • Understanding of the MITRE ATT&CK framework
  • Strong understanding of network architecture
  • Experience developing and maintaining scripts (preferably using Powershell, Python or SPL)
  • Understanding of Defense-in-Depth
  • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission.
  • Must have Baseline Certification for IT-II and CNDSP\/CSSP-IR when on boarding and must have one of the "Computer Network Defense" CE Certifications within six (6) months of on-boarding.

Work to be performed On-Site (Only). Work Locations: Columbus, OH; Battle Creek, MI; Ft. Belvoir, VA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Senior SIEM Content Developer for Threat Detection
Senior SIEM Content Developer for Threat Detection

Y-Tech • Fort Belvoir (VA)

On-site
USD 90,000 - 140,000
Content Developer (SIEM Cyber Security)
Content Developer (SIEM Cyber Security)

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 90,000 - 120,000
Paid holidays
Medical, dental, and vision insurance
401(k) with company match
Senior SIEM Analyst
Senior SIEM Analyst

theserverlab • United States

On-site
USD 80,000 - 100,000
Medical benefits
Dental benefits
Vision benefits
+2
Cybersecurity Operations Specialist -SIEM Services (Evergreen)
Cybersecurity Operations Specialist -SIEM Services (Evergreen)

General Dynamics - IT • St. Louis (MO)

On-site
USD 80,000 - 100,000
Signature Writer – Intermediate – Cyber Security
Signature Writer – Intermediate – Cyber Security

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 180,000
Paid holidays
401(k) with company match
Tuition reimbursement
SIEM Analyst II (R-00173)
SIEM Analyst II (R-00173)

Truezerotech • Virginia (MN)

On-site
USD 80,000 - 120,000
Cybersecurity Detection Engineer — SIEM & Threat Analytics
Cybersecurity Detection Engineer — SIEM & Threat Analytics

Sarela Technology Solutions • Columbus (OH)

On-site
USD 110,000 - 150,000