SIEM Content Developer

ESM

• $95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of relevant IT experience
  • 3+ years in SIEM content development or Incident Response
  • 3+ years in System and/or Network Administration
  • CSSP Analyst certification or equivalent (CEH, CFR, GCIA, GCISP)
  • SIEM certification required
  • Strong understanding of log formats and network architecture
  • Familiarity with the MITRE ATT&CK framework

Responsibilities

  • Research and develop threat detection use cases based on emerging threats
  • Collaborate with stakeholders to identify gaps in security controls
  • Develop custom scripts to enhance SIEM capabilities
  • Improve data feeds for effective detection
  • Identify critical systems to establish alerting priorities
  • Develop tailored detection signatures

Benefits

  • Opportunity to work in a federal environment
  • Engagement with cutting-edge cybersecurity tools
  • Collaboration with a diverse team of experts
  • Potential for professional growth and development
  • Supportive work culture that values proactive problem-solving
Full Job Description
We are hiring a SIEM Content Developer to support an enterprise-level program within a federal environment.

Job Description and Responsibilities

Research and develop threat detection use cases based on emerging threats, threat intelligence, and analyst feedback. Collaborates with stakeholders and cybersecurity tool SMEs to identify gaps in security controls, analytics, and data quality. Develops custom scripts to enhance SIEM capabilities and improves data feeds to support effective detection. Identifies critical systems and application components to establish alerting priorities and develop tailored detection signatures.

Required Knowledge, Skills and Abilities (KSA)
  • Skill collecting and interpreting qualitative and quantitative data from multiple sources
  • Knowledge of log formats and network architecture.
  • Knowledge of the MITRE ATT&CK framework
  • Skill developing and maintaining scripts with Python, Powershell or SPL
  • Ability to understand Defense in Depth


Desired KSA
  • Be a positive, self-motivated, and proactive person with the ability to adapt to change and tolerate stressful situations
  • Candidate must communicate effectively with team members, team lead, management, and government customers
  • Must have the ability and desire to research and develop creative solutions to unique problems with minimal supervision


Minimum Training, Education, and Certifications
  • Five (5) years of relevant IT experience
  • Three (3) years working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and/or Network Administration experience
  • Must maintain CSSP Analyst certification by having one of the following or equivalent - (CEH, CFR, GCIA, GCISP)
  • SIEM certification


Minimum Clearance
  • Top Secret


Physical Requirements
  • Required to stand, walk and sit; communicate verbally both in person and by telephone; use hands to finger, handle or feel objects or controls; reach with hands and arms. Regularly required to stoop, kneel, bend, crouch and lift up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, depth perception, color vision and the ability to adjust focus.
  • Physical demands associated with this position include extensive walking (including stairs) throughout offices and between buildings. May require use of public transportation, personal or Government vehicle to drive to local and/or remote office locations.


Additional Requirements
  • Other duties as assigned


Similar Jobs

More Jobs at ESM

More Information Technology Jobs

Find similar SIEM Content Developer jobs: