Job Title: SIEM Content Developer
Location: Columbus, OH
Clearance: Top Secret
Job SummaryWe are seeking an experienced
SIEM Content Developer to research, develop, and enhance threat detection capabilities within a complex cybersecurity environment. This role focuses on creating new threat detection use cases based on emerging threats, threat intelligence, and feedback from security analysts.
The SIEM Content Developer will work closely with cybersecurity stakeholders, security tool SMEs, incident response teams, and threat detection analysts to identify gaps in security monitoring and analytics. The position will develop custom scripts and SIEM content, evaluate the quality of security data feeds, and create alerts and signatures tailored to critical systems and applications.
Key Responsibilities- Research and develop new threat detection use cases based on emerging threats, threat intelligence research, and Threat Detection Analyst feedback.
- Work with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities.
- Develop custom scripts to enhance SIEM functionality and automate security monitoring activities.
- Review the quality and effectiveness of SIEM data feeds and recommend or implement improvements.
- Analyze log sources and ensure relevant security data is available for detection and investigation.
- Collaborate with stakeholders to identify critical systems and application components and establish appropriate alerting priorities.
- Develop and maintain detection signatures and alerts tailored to individual systems, programs, and applications.
- Support continuous improvement of SIEM detection capabilities based on evolving threats and operational requirements.
- Apply knowledge of network architecture, Defense-in-Depth, and the MITRE ATT&CK framework when developing detection content.
Minimum Requirements- Five (5) years of relevant IT experience • Three (3) years working with a SIEM in a content development or Incident Response role. • Three (3) years of System and/or Network Administration experience • Understanding of various log formats • Understanding of the MITRE ATT&CK framework • Strong understanding of network architecture • Experience developing and maintaining scripts (preferably using Powershell, Python or SPL) • Understanding of Defense-in-Depth • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance
If you thrive on solving complex problems and building meaningful connections, we'd love to hear from you. Join our team and make an impact today!
Physical and Mental Qualifications:- Maintain focus and awareness throughout scheduled working hours.
- Perform tasks requiring prolonged periods of sitting or standing at a desk, utilizing a computer, mouse, and keyboard.
- Lift and move objects weighing up to 15 pounds as needed.
- Exhibit excellent verbal and written communication skills, with a strong command of the English language.
- Demonstrate the ability to work independently while also collaborating effectively as part of a team.
- Quickly learn and retain routine tasks and processes.
- Possess strong organizational skills, attention to detail, business correspondence proficiency, and self-management capabilities.
- Perform the essential functions of the role satisfactorily; reasonable accommodation will be provided for employees with disabilities upon request.
- Accept and adapt to additional responsibilities or changes to assigned duties as determined by DirectViz Solutions (DVS).