Bachelor's degree in a technical discipline from an accredited university.
5 years of IT experience in cybersecurity, systems administration, or network operations.
3 years of experience with SIEM platforms in content development or incident response.
Experience in system/network administration, including configuration and security of enterprise IT environments.
Understanding of log formats and experience analyzing log data for security events.
Familiarity with the MITRE ATT&CK framework for threat detection and analysis.
Proficiency in scripting and automation, preferably with PowerShell, Python, or SPL.
Knowledge of Defense-in-Depth principles for enterprise protection.
Responsibilities
Research and develop new threat detection use cases based on emerging threats and intelligence.
Collaborate with stakeholders and SMEs to identify security gaps in monitoring and detection.
Develop and maintain custom scripts to enhance SIEM functionality.
Review and improve the quality and reliability of cybersecurity data feeds.
Establish alerting priorities and develop tailored detection signatures for critical systems.
Benefits
On-site work location in Columbus, OH.
Opportunity to support a Defense Logistics Agency program.
Engagement in a proposal effort contingent on award and customer approval.
Potential for evolving responsibilities aligned with team and organizational goals.
Full Job Description
OCH Technologies is actively looking for a SIEM Content Developer supporting a Defense Logistics Agency program.
This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.
Location
On-site: Columbus, OH
Core Responsibilities & Duties
Researches and develops new threat detection use cases based on emerging threats, threat intelligence, cybersecurity research, and feedback from Threat Detection Analysts.
Collaborates with stakeholders and cybersecurity tool Subject Matter Experts (SMEs) to identify gaps in security protection, monitoring, detection, and analytics capabilities.
Develops and maintains custom scripts and automation to enhance Security Information and Event Management (SIEM) functionality and threat detection capabilities.
Reviews the quality, completeness, and reliability of cybersecurity data feeds and recommends and/or implements improvements to enhance data integrity and detection effectiveness.
Collaborates with stakeholders to identify critical systems, applications, and infrastructure components to establish alerting priorities and develop detection signatures tailored to specific programs, systems, and applications.
Responsibilities may evolve over time to support team and organizational goals, but will remain consistent with the overall scope of the role.
Requirements
Minimum Qualifications
Education
Bachelor's degree (BS or BA) in a technical discipline from an accredited university
Experience
Five (5) years of relevant Information Technology (IT) experience supporting cybersecurity, systems administration, network operations, or related technical functions.
Three (3) years of experience working with Security Information and Event Management (SIEM) platforms in a content development, security operations, or incident response role.
Three (3) years of experience performing system and/or network administration, including configuration, maintenance, troubleshooting, and security of enterprise IT environments.
Demonstrated understanding of various log formats and experience analyzing log data to identify security events, anomalies, and potential indicators of compromise.
Working knowledge of the MITRE ATT&CK framework and its application to threat detection, analysis, content development, and incident response.
Strong understanding of network architecture, including network infrastructure, protocols, traffic flows, and security controls.
Experience developing, maintaining, and enhancing scripts and automation to support cybersecurity operations, preferably using PowerShell, Python, and/or SPL.
Working knowledge of Defense-in-Depth principles and their application to protecting enterprise systems, networks, and data.
Security Clearance Requirement
Must possess an active DoD Top Secret security clearance and be eligible for an IT-I (Critical-Sensitive) security designation or Tier 5 (T5) investigation at the time of proposal submission.