Threat Detection SIEM Content Engineer

iP-Plus Consulting, Inc.

Columbus (OH)

On-site

USD 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

iP-Plus Consulting, Inc. is seeking a Threat Detection Analyst to research and develop new use cases based on emerging threats and threat intelligence.

You will work with stakeholders and cybersecurity tool SMEs to identify gaps in protection and analytics capabilities, develop custom SIEM scripts, and review data feeds for improvements. The role focuses on creating alerting priorities and signatures aligned with MITRE ATT&CK and defense-in-depth principles, collaborating across programs.

Qualifications

  • 5 years of relevant IT experience.
  • 3 years working with a SIEM in a content development or Incident Response role.
  • 3 years of System and/or Network Administration experience.
  • Understanding of various log formats.
  • Understanding of the MITRE ATT&CK framework.
  • Strong understanding of network architecture.
  • Experience developing and maintaining scripts (PowerShell, Python or SPL).
  • Understanding of Defense-in-Depth.
  • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5).

Responsibilities

  • Researches and develops new threat detection use cases based on emerging threats, threat intelligence research and Threat Detection Analyst feedback.
  • Works with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities.
  • Develops custom scripts to enhance SIEM functionality.
  • Reviews the quality of data feeds and recommend and/or implement improvements.
  • Collaborates with stakeholders to identify critical systems and application components to develop alerting priorities and create signatures tailored to individual programs and applications.

Skills

SIEM experience
System & Network administration
MITRE ATT&CK knowledge
Scripting (PowerShell/Python/SPL)
Threat detection concepts
Defense-in-Depth
Log formats knowledge
Network architecture understanding
DOD Top Secret Clearance

Job description

iP-Plus Consulting, Inc. is seeking a Threat Detection Analyst to research and develop new use cases based on emerging threats and threat intelligence.

You will work with stakeholders and cybersecurity tool SMEs to identify gaps in protection and analytics capabilities, develop custom SIEM scripts, and review data feeds for improvements. The role focuses on creating alerting priorities and signatures aligned with MITRE ATT&CK and defense-in-depth principles, collaborating across programs.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SIEM Content Developer
SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
SIEM CONTENT DEVELOPER
SIEM CONTENT DEVELOPER

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 90,000 - 130,000
Threat Detection SIEM Content Developer
Threat Detection SIEM Content Developer

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000
Senior Cybersecurity Analytics Specialist - SIEM & Threats
Senior Cybersecurity Analytics Specialist - SIEM & Threats

Si Tec Consulting • Springfield (VA)

On-site
USD 150,000 - 210,000
Cyber Threat Hunter & Incident Response Lead
Cyber Threat Hunter & Incident Response Lead

iP-Plus Consulting, Inc. • Columbus (OH)

On-site
USD 110,000 - 150,000
Cybersecurity Analytics Engineer - SIEM & Threat Detection
Cybersecurity Analytics Engineer - SIEM & Threat Detection

Si Tec Consulting • West Springfield (VA)

On-site
USD 120,000 - 180,000
Detection & Response Engineer — Threat Hunting & SIEM Pro
Detection & Response Engineer — Threat Hunting & SIEM Pro

Coalfire • United States

Hybrid
USD 120,000 - 150,000
Flexible work model
Certification reimbursement
Comprehensive insurance options
+1
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Detection Engineer: SIEM & Threat Analytics
Detection Engineer: SIEM & Threat Analytics

CBIZ • Independence Township (OH)

On-site
USD 110,000 - 170,000
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC • Fort Belvoir (VA)

On-site
USD 80,000 - 110,000