SIEM Content Developer - Threat Detection & Automation

electro soft

Columbus (OH)

On-site

USD 145,000 - 155,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Electrosoft Services, LLC is seeking a SIEM Content Developer to research and develop new threat detection use cases based on emerging threats and analyst feedback. You will collaborate with stakeholders and SIEM SMEs to tailor signatures and improve analytics capabilities.

The role requires 5+ years IT experience, 3+ years with a SIEM, admin experience, scripting with PowerShell/Python/SPL, and knowledge of MITRE ATT&CK. A TS/IT-I- or Tier 5-ready clearance is required or pursued.

Qualifications

  • Five (5) years of relevant IT experience.
  • Three (3) years working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and/or Network Administration experience.
  • Understanding of the MITRE ATT&CK framework.
  • Strong understanding of network architecture.
  • Experience developing and maintaining scripts (PowerShell, Python or SPL).
  • Must possess a current DOD Top Secret Clearance or eligibility for IT-I/ Tier 5 at time of proposal submission.

Responsibilities

  • Researches and develops new threat detection use cases based on emerging threats, threat intelligence research and Threat Detection Analyst feedback.
  • Develops custom scripts to enhance SIEM functionality.
  • Reviews data feeds quality and recommends improvements.
  • Collaborates with stakeholders to identify critical systems and applications and create signatures.

Tools

PowerShell
Python
SPL

Job description

Electrosoft Services, LLC is seeking a SIEM Content Developer to research and develop new threat detection use cases based on emerging threats and analyst feedback. You will collaborate with stakeholders and SIEM SMEs to tailor signatures and improve analytics capabilities.

The role requires 5+ years IT experience, 3+ years with a SIEM, admin experience, scripting with PowerShell/Python/SPL, and knowledge of MITRE ATT&CK. A TS/IT-I- or Tier 5-ready clearance is required or pursued.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Content Engineer for Threat Detection & Automation
SIEM Content Engineer for Threat Detection & Automation

AGE Solutions • Columbus (OH)

On-site
USD 115,000 - 135,000
Paid Leave
Bonuses
401k Match
+7
SIEM CONTENT DEVELOPER
SIEM CONTENT DEVELOPER

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 90,000 - 130,000
SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
SIEM Content Developer
SIEM Content Developer

Electrosoft • Columbus (OH)

On-site
USD 145,000 - 155,000
Senior SIEM Content Developer for Threat Detection
Senior SIEM Content Developer for Threat Detection

Electrosoft • Columbus (OH)

On-site
USD 145,000 - 155,000
SIEM Content Developer
SIEM Content Developer

electro soft • Columbus (OH)

On-site
USD 145,000 - 155,000
SIEM Content Developer - Threat Detection (TS Clearance)
SIEM Content Developer - Threat Detection (TS Clearance)

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
SIEM Content Developer
SIEM Content Developer

Career Listings • Columbus (OH)

On-site
USD 90,000 - 120,000
401(k)
401(k) matching
Dental insurance
+6
Threat Detection SIEM Content Engineer
Threat Detection SIEM Content Engineer

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 90,000 - 130,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000