SIEM Content Engineer

Tyto Athene

$110K — $120K *
US-AnywhereRemote in United States
Technical Services
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree required
  • 8 years of general work experience, 6 years in IT/Cyber with 2 years using SIEM tools like Splunk
  • Direct SIEM content development experience in a Tier 1 SOC
  • Strong verbal and written communication skills for both technical and non-technical audiences
  • Ability to manage and present complex data clearly to various stakeholders
  • Familiarity with the MITRE ATT&CK Framework
  • Experience developing Splunk dashboards, reports, and alerts

Responsibilities

  • Evaluate SIEM content for removal or updates to enhance fidelity
  • Utilize the MITRE ATT&CK framework to identify content development opportunities
  • Support onboarding of new data sources with relevant SIEM content
  • Develop and review SIEM detection use cases with stakeholders
  • Collaborate with security engineers to enhance logging and correct misconfigurations
  • Coordinate with SOC analysts to create triage and response playbooks
  • Maintain a SIEM content catalog aligned with the MITRE ATT&CK framework
  • Design and monitor dashboards and reports on content coverage and fidelity

Benefits

  • Health/Dental/Vision insurance
  • 401(k) matching
  • Paid Time Off
  • Short-term/Long-term Disability and Life Insurance
  • Referral bonuses
  • Professional development reimbursement
  • Parental leave
Full Job Description
Description

Tyto Athene is searching for a forward-thinking and self-motivated SIEM Content Engineer to focus on enhancing a government client’s detection content for their Security Operations Center (SOC). This exciting role requires curiosity, creativity, and critical thinking skills, as well as superior attention to detail, great organizational skills, and the ability to work in a highly collaborative work environment.

 

Responsibilities:

  • Evaluate existing SIEM content to determine which content should be removed or updated to improve fidelity
  • Leverage the MITRE ATT&CK framework, monitor the threat landscape and evaluate existing data sources to identify opportunities for new SIEM content development
  • Support the onboarding of new data sources by developing relevant SIEM content
  • Develop SIEM detection uses cases and review them with relevant stakeholders, such as security engineers, SIEM engineers, SOC analysts, and incident responders
  • Collaborate with security engineers to improve logging from various appliances and correct misconfigurations
  • Coordinate closely with SOC analysts and incident responders to develop playbooks for triaging and responding to events created by the SIEM tool
  • Develop and maintain a SIEM content catalog, including mapping to the MITRE ATT&CK framework, to improve the efficiency of deploying the security stack to new environments
  • Design, develop, and monitor various dashboards and reports that provide information on content coverage, alerting, and fidelity
Qualifications

Required:

  • Bachelor’s degree required
  • Eight (8) years of general work experience (with at least six (6) years of IT/Cyber experience) and two (2) years of experience using Splunk (or a similar SIEM tool) in a cybersecurity context (e.g., as a content developer, administrator, or SOC analyst, etc.…)
  • Direct experience developing SIEM content in collaboration with a Tier 1 security operations center
  • Effective verbal and written communication skills that include the ability to describe highly technical concepts in non-technical terms
  • Ability to manage, analyze, and report complex data in an easy-to-understand format for a variety of stakeholders
  • Familiarity with the MITRE ATT&CK Framework
  • Experience with Splunk and development
  • Experience developing Splunk dashboards, reports, and alerts

Desired:

  • Experience with Splunk Enterprise Security is a plus

Clearance:

  • Secret Clearance required

Location:

  • Remote
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $110,000-$120,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

Similar Jobs

More Jobs at Tyto Athene

  • PBX Technician
    $93K — $104K *
    Mt. Pleasant, SC 29464 (Charleston County)
    Telecommunications & Hardware
    In-Person
  • Senior Audit Lead
    $150K — $170K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • Program Manager Level II
    $80K — $90K *
    Warner Robins, GA 31088 (Houston County)
    Aerospace & Defense
    In-Person
  • Senior Proposal Manager
    $170K — $180K *
    Remote
    Business Services
    Remote in United States
  • Defensive Cyber Analyst
    $100K — $115K *
    Colorado Springs, CO 80918 (El Paso County)
    Aerospace & Defense
    In-Person

More Technical Services Jobs

Find similar SIEM Content Engineer jobs: