Content Developer (SIEM Cyber Security)

BRS
San Antonio, TX Full Time
POSTED ON 5/29/2024
STS Systems Support, LLC. (SSS) is seeking a Content Developer (SIEM Cyber Security)

Requirements:
  • DoDD 8570.01‐M/8140.01 I AT Level III CND
  • Active TS/SCI
  • More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK.
  • More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS
  • More than five (5) years of SIEM technology such as Arcsight, Splunk and/or ELK. Including, but not limited to, log handling, reports, filters, rule creation.
  • Extensive knowledge with IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (i.e., Air Force, Navy, Army, DC3, DISA).
  • More than three (3) years of experience with Network Traffic Analysis; ports and protocols. SANS GCDA or equivalent certification(s).
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)
Desired:
  • Additionally, more than one (1) year of experience with Security, Orchestration, Automation, and Response (SOAR) platforms such as Phantom and/or Demisto. Proficient in Python and PowerShell.
Duties:
  • Analyze DCO events.
  • Apply current industry SIEM best‐practices.
  • Use security alerts correlated with log enrichment data to enhance the operator’s ability to identify real attacks.
  • Establish security control effectiveness and monitor for unauthorized outbound connections
  • Create detections by analyzing log data across the enterprise. (CDRL A007)
  • Develop dashboards and visualizations to identify adversarial activity. (CDRL A007)
  • Use log data to establish and implement virtual tripwires for early detection.
  • Analyze and ingest security logs into the SIEM in order to optimize for performance of the SIEM.
  • Conduct designing, implementing, and testing of various SIEM solutions. (CDRL A007)
  • Create and support the creation of SIEM Use Cases and understand what alerts and log enrichment is necessary to meet the required acceptable false positive rate. (CDRL A008)
  • Create, test, and validate filters and rules. (CDRL A007)
  • Build and implement event correlation rules, logic, and content in the SIEM. (CDRL A007)
  • Tune SIEM event correlation rules and logic to filter out security events associated with known and well established network behavior, known false positives and/or known errors.
  • Analyze malware threats to develop behavior based detections that alert and/or prevent malicious activity.
  • Automate tasks in the SIEM using a common programming or scripting language.
  • Create scheduled and ad‐hoc reporting with SEIM tools. (CDRL A007 and A008)
  • Create and maintain SIEM documentation. (CDRL A008)
  • Develop and execute a process to review and maintain SIEM resources such as rules, filters, lists, trends and reports.
  • Utilize SIEM to develop metrics collection, analysis, and create reports upon request.
  • Provide training to government personnel as requested.
  • Provide knowledge transfer of tools, processes and procedures to government personnel as requested.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).
Support operational leaderships tasking as it relates to Content Development functions and responsibilities

Locations: Lackland AFB, TX, Offut AFB, NE, and Maxwell AFB, AL

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs that are on the Content Developer (SIEM Cyber Security) career path.

Click the checkbox next to the jobs that you are interested in.

Income Estimation: 
$48,966 - $55,825
Income Estimation: 
$51,979 - $66,515
Income Estimation: 
$66,579 - $82,510
Income Estimation: 
$108,560 - $136,938
Income Estimation: 
$126,730 - $161,221
Income Estimation: 
$137,605 - $179,497
Income Estimation: 
$101,036 - $135,845
Income Estimation: 
$147,172 - $193,721
Income Estimation: 
$68,487 - $86,782
Income Estimation: 
$86,561 - $112,265
Income Estimation: 
$87,839 - $116,019
Income Estimation: 
$89,378 - $119,179
Income Estimation: 
$90,046 - $116,334

Sign up to receive alerts about other jobs with skills like those required for the Content Developer (SIEM Cyber Security).

Click the checkbox next to the jobs that you are interested in.

  • BI Analytics/Reporting Tools Skill

    • Income Estimation: $59,051 - $74,965
    • Income Estimation: $60,302 - $76,641
  • Change Data Capture Skill

    • Income Estimation: $66,610 - $83,710
    • Income Estimation: $71,766 - $95,486
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at BRS

BRS
Hired Organization Address Anchorage, AK Full Time
Eagle Health Analytics has an Administrative Assistant position in support of CDC’s “Arctic Investigations Program. The ...
BRS
Hired Organization Address Dugway, UT Full Time
GC&E Federal is seeking a HELP DESK TECHNICIAN– Dugway Proving Grounds, UT. The candidate for this position will work wi...
BRS
Hired Organization Address Little Rock, AR Full Time
SES is currently seeking a full-time federal construction superintendent. Potential candidates must be experienced, tech...
BRS
Hired Organization Address Huntsville, AL Full Time
Bristol Bay Shared Services (BBSS), LLC is a shared service organization of Bristol Bay Native Corporation (BBNC) and is...

Not the job you're looking for? Here are some other Content Developer (SIEM Cyber Security) jobs in the San Antonio, TX area that may be a better fit.

Content Developer (SIEM Cyber Security)

Bristol Bay Construction Holdings LLC, San Antonio, TX

Content Developer (SIEM Cyber Security)

SSSCANDIDATEPORTAL, San Antonio, TX