SIEM Content Developer

Y-Tech, LLC

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Five years of relevant IT experience
  • Three years with SIEM in content development or Incident Response role
  • Three years of System and/or Network Administration experience
  • Understanding of various log formats
  • Familiarity with the MITRE ATT&CK framework
  • Strong grasp of network architecture
  • Experience with scripting (Powershell, Python, or SPL)
  • Must have a current DOD Top Secret Clearance
  • Baseline Certification for IT-II and CNDSP/CSSP-IR required upon onboarding.

Responsibilities

  • Research and develop new threat detection use cases based on emerging threats
  • Collaborate with cybersecurity tool SMEs to identify security gaps
  • Develop custom scripts to enhance SIEM functionality
  • Review data feed quality and implement improvements
  • Collaborate with stakeholders to prioritize alerting for critical systems
  • Create signatures tailored to specific programs and applications.

Benefits

  • Work is performed on-site, promoting team collaboration
  • Opportunities to work with latest cybersecurity tools and technologies
  • Engagement in hands-on threat detection and incident response
  • Potential for career growth within cybersecurity roles
  • Access to continuing education and certifications within the field.
Full Job Description
Researches and develops new threat detection use cases based on emerging threats, threat intelligence

research and Threat Detection Analyst feedback. Works with stakeholders and cybersecurity tool SMEs

to identify gaps in security protection and analytics capabilities. Develops custom scripts to enhance

SIEM functionality. Reviews the quality of data feeds and recommend and/or implement improvements.

Collaborates with stakeholders to identify critical systems and application components to develop

alerting priorities and create signatures tailored to individual programs and applications.

Minimum Requirements:
  • Five (5) years of relevant IT experience
  • Three (3) years working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and/or Network Administration experience
  • Understanding of various log formats
  • Understanding of the MITRE ATT&CK framework
  • Strong understanding of network architecture
  • Experience developing and maintaining scripts (preferably using Powershell, Python or SPL)
  • Understanding of Defense-in-Depth
  • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission.
  • Must have Baseline Certification for IT-II and CNDSP/CSSP-IRwhen on boarding and must have one of the "Computer Network Defense" CE Certifications within six (6) months of on-boarding.

Work to be performed On-Site (Only). Work Locations: Columbus, OH; Battle Creek, MI; Ft. Belvoir, VA

Similar Jobs

More Jobs at Y-Tech, LLC

More Information Technology Jobs

Find similar SIEM Content Developer jobs: