SIEM Content Developer
Base One Inc
Primary Responsibilities Experience with creating and implementing custom IOCs and IOAs in Crowdstrike Experience with triaging and investigating hosts using Crowdstrike Experienced with updating McAfee AV signatures Experience with creating and maintain custom Tanium packages for collecting artifacts for continuous monitoring Provide recommendations for tuning and/or triaging notable events Perform critical thinking and analysis to investigate cyber security alerts Analyze network traffic using enterprise tools (e.g. Full PCAP, Firewall, Proxy logs, IDS logs, etc) Collaborate with team members to analyze an alert or a threat Stay up to date with latest threats and familiar with APT and common TTPs Utilize OSINT to extrapolate data to pivot and identify malicious activity Have experience with dynamic malware analysis Have experience performing analysis of network traffic and correlating diverse security logs to perform recommendations for response Utilize the Cyber Kill Chain and synthesize the entire attack life cycle Review and provide feedback to junior analysts’ investigation participate in discussions to make recommendations on improving SOC visibility or process Contribute to SOP development and updating Provide expert guidance and mentorship to junior analysts Qualifications Basic requirements that the recruiter should use as a filter: All Tier 2 analyst candidates shall have a minimum a bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS eight (8) years of experience in incident detection and response, malware analysis, or cyber forensics. Of the eight (8) years of professional experience requirements above, SIEM Content Developer candidates shall have at least one (1) of the following specialized experience for their position: Monitoring and Detection Analyst: Candidates shall have a minimum of five (5) years of professional experience in security, information risk management, or information systems risk assessment, and must be knowledgeable in many areas such as Vulnerability Assessments, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web-filtering, and Advanced Threat Protection. Incident Response Analyst: Candidates shall have a minimum of five (5) years of professional experience responding to information system security incidents. Ability to use the DHS-furnished toolset to identify and determine root causes of incidents and provide any required documentation and possible evidence to security investigators. Candidates must have extensive experience working with various security methodologies and processes, advanced knowledge of TCP/IP protocols, experience configuring and implementing various technical security solutions, extensive experience providing analysis and trending of security log data from a large number of heterogeneous security devices, and must possess expert knowledge in two or more of the following areas related to cybersecurity: Vulnerability Assessment Intrusion Prevention and Detection Access Control and Authorization Policy Enforcement Application Security Protocol Analysis Firewall Management Incident Response Encryption Web-filtering Advanced Threat Protection Must have at least one of the following certifications: SANS GIAC:GCIA, GCIH, GCFA, GPEN, GWAPT, GCFE, GREM, GXPN, GMON, GISF, or GCIH EC Council:CEH, CHFI, LPT, ECSA
ISC2:CCFP, CCSP, CISSP CERT CSIH
Offensive Security:OSCP, OSCE, OSWP and OSEE Must have TS/SCI. In addition to specific security clearance requirements, all Department of Homeland Security SOC employees are required to obtain an Entry on Duty (EOD) clearance to support this program. The ideal candidate is a self-motivated individual in pursuit of a career in cyber security. Experienced with developing advanced correlation rules utilizing tstats and datamodels for cyber threat detection Experienced with creating and maintaining Splunk knowledge objects Experienced managing and maintaining Splunk data models Expertise in developing custom SPL using macros, lookups, etc and network security signatures such as SNORT and YARA Experience creating regex for pattern matching Implemented security methodologies and SOC processes Extensive knowledge about network ports and protocols (e.g. TCP/UDP, ICMP, DNS, SMTP, etc) Experienced with network topologies and network security devices (e.g. Firewall, IDS/IPS, Proxy, DNS, WAF, etc). Hands-on experience utilizing network security tools (e.g. Sourcefire, Suricata, Netwitness, o365, FireEye, etc) and SIEM Experience in a scripting language (e.g. Python, Powershell, etc) and automating SOC processes/workflow Experience training and mentoring junior analysts Extensive knowledge of common end user and web application attacks and countermeasures against attacks Experience developing custom workflows within Splunk to streamline SOC processes Experience creating SOPs and providing guidance to junior analysts Ability to analyze new attacks and provide guidance to watch floor analysts on detection and response Knowledgeable of the various Intel Frameworks (e.g. Cyber Kill Chain, Diamond Model, MITRE ATT&CK, etc) and able to utilize it in their analysis workflow Experience with cloud (e.g. o365, Azure, AWS, etc) security monitoring and familiar with cloud threat landscape Knowledgeable of APT capabilities and be able to implement appropriate countermeasures Preferred Qualifications Provide expert content development in Splunk Enterprise Security using tstats and datamodels Utilize knowledge of latest threats and attack vectors to develop Splunk correlation rules for continuous monitoring Review logs to determine if relevant data is present to accelerate against datamodels to work with existing use cases Capture use cases from subscribers or other team members and develop correlation rules Requirement Certifications CCFP – Certified Cyber Forensics Professional CHFI – Computer Hacking Forensic Investigator CISSP – Certified Information Systems Security CIRC ECSA – EC-Council Certified Security Analyst EnCE FIWE GCFA – Forensic Analyst GCFE – Forensic Examiner GCIH – Incident Handler GISF – Security Fundamentals GREM – Reverse Engineering Malware GXPN – Exploit Researcher and Advanced Penetration Tester LPT – Licensed Penetration Tester OSCE (Certified Expert) OSCP (Certified Professional) OSEE (Exploitation Expert) OSWP (Wireless Professional)WFE-E-CI
FTK-WFE-FTK
GCTI – Cyber Threat Intelligence GOSI – Open Source Intelligence CTIA – Certified Threat Intelligence Analyst #J-18808-Ljbffr Base One Inc$140k - $180k
...engineering degree. The position offers a salary ranging from $140,000 to $180,000 depending on experience. Experience with AWS, VMWare, and SIEM products is preferred, along with strong teamwork and problem-solving skills. #J-18808-Ljbffr Edgewater Federal Solutions, Inc.Suggested$77.6k - $176k
...Job Number: R0237536 SIEM Platform Engineer The Opportunity : Work with clients and peers to build a high-performing system using Elastic to aggregate logs from many systems into a single common schema.Use Elastic Common Schema (ECS) formatted fields, create...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- ...Senior Engineer - SIEM Platform Engineering & Operations Denver, Colorado;Washington... ...being an inclusive workplace, attracting and developing exceptional talent, supporting our... ...relevant data sources. Oversee the Anvilogic content management platform including rule...SuggestedWork at officeShift workDay shift
- ...oversee security operations. The ideal candidate will have extensive experience in cybersecurity, including expertise in Splunk and SIEM/SOAR operations, and will mentor junior cybersecurity personnel. This position may require occasional travel and includes comprehensive...Suggested
$77.6k - $176k
A leading consulting firm in Virginia is seeking a skilled SIEM Platform Engineer. The role involves building systems with Elastic for log aggregation, creating visualizations and alerts to enhance security monitoring, and maintaining infrastructure for proactive issue...SuggestedRemote job- Dexian DISYS is seeking an experienced Coralogix SIEM Engineer to serve as the hands-on technical owner in Washington, DC. This role requires strong Coralogix platform administration skills and the ability to manage multi-tenant setups effectively. The ideal candidate...
$77.6k - $176k
SIEM Platform Engineer page is loaded## SIEM Platform Engineerlocations: Arlington, VAtime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 9, 2026 (30+ days left to apply)job requisition id: R0237536SIEM Platform Engineer**The Opportunity****:*...Full timeContract workPart timeWork at officeLocal areaRemote work- ...skilled individual to build high-performing systems using Elastic for log aggregation. The ideal candidate has extensive experience with SIEM platforms and data pipeline architectures. Responsibilities include creating visualizations for threat hunting and ensuring...
- ...Position Summary August Schell is seeking a Senior Splunk / SIEM Engineer with advanced hands-on experience in designing,... ...maintain complex Splunk clusters across varied hardware platforms Develop and optimize advanced Splunk dashboards and queries to support mission...Work at officeRemote workHome office2 days per week3 days per week
- ...self-directed and experienced individual to fill the role of a SIEM Administrator/Security Monitoring Engineer for our existing government... ..., normalization, enrichment, and throughput optimization. Develop and tune detection logic, correlation rules, and alerting...Full timePart timeFor contractorsInterim roleRemote work
$107.9k - $195.05k
Job Overview Leidos has an immediate need for a Splunk Content Developer for a new customer on a highly‑visible, strategic Cybersecurity Task... ...with other Security Information and Event Management (SIEM) platforms. Extensive experience with advanced configuration...Immediate start- KellyMitchell Group is seeking a Senior Security Engineer in Bethesda, Maryland, focused on enterprise IT security and hybrid infrastructures. You will design, maintain security systems, and implement cybersecurity tools while collaborating with diverse teams. The ideal...
- ...and cloud environments • Deploy and configure security tools including EDR, SIEM, and identity management solutions • Provide technical support and troubleshooting for client environments • Develop automation scripts and tools to improve operational efficiency • Create...Remote work
- ...of security products and a minimum of 5 years experience in the information security space, with a preference for familiarity with SIEM technologies such as MS Sentinel or Splunk. This role also requires excellent communication skills and the ability to present complex...
- ...Security Incident and Event Management/Elastic Specialist in Washington, DC. The role requires a clear understanding of Elastic and SIEM processes. Candidates must be US citizens with a Secret Clearance and have at least three years of experience using Elastic/Splunk query...
$30 - $35 per hour
...Replies within 24 hours TITLE: IT Trainer/Content Developer LOCATION: Georgia/ Hybrid MINIMUM EDUCATION: Bachelor's degree in IT, related field, or equivalent experience. REQUIRED EXPERIENCE: + years INTERVIEWS: Either Web Cam or In Person...Hourly payLong term contractPermanent employmentContract workFor contractorsWork experience placementWork at officeRemote workWork from homeFlexible hours- COMFORT SYSTEMS is seeking a Splunk Content Developer in Arlington, Virginia to support a strategic cybersecurity task order. The ideal candidate must have extensive experience in system administration and Splunk, managing installations in both on-premise and cloud environments...
- ...POSITION OVERVIEW Reporting to the Program Manager, the Web Developer Embeds security across the SDLC for mission-critical web apps,... ...WAF and FIM deploy/tune; Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR); risk assessment; DevSecOps CI/CD security...Work from homeFlexible hours
$100k - $145k
...management, incident response, and drafting documentation. The ideal candidate will have over 4 years of cybersecurity experience, 2+ years with SIEM tools, and a Bachelor's degree. Salary is estimated between $100,000 and $145,000 based on experience. #J-18808-Ljbffr...- A financial services firm in Arlington, Virginia is seeking an IT Security Engineer to enhance security posture and maintain data integrity. The role involves working with the IT Security team to define and implement security strategies. Candidates should have a bachelor...Flexible hours
$40 per hour
...A tech company specializing in AI training is seeking a Content Developer - Math to assist in training AI models. The role involves evaluating the logic and quality of AI chatbots' outputs and providing writing and editing tasks. Candidates should have a strong command...Hourly payRemote workFlexible hours$40 per hour
...We are looking for a Content Developer - Math to join our team to train AI models. You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of each model. In this role you will need to hold an expert level of writing...Hourly payFull timeContract workPart timeRemote work$90 - $130 per hour
...Summary: Our client is seeking a Security Infrastructure Support - SIEM & Data Pipeline Technical Lead / SME to join their team! This... ...log management solutions across enterprise environments Develop, implement, and maintain secure and efficient data pipelines to...Local area$17 - $17.95 per hour
...creating positive, irreversible change for children, and the future we all share. The Role As the Fall 2026 Finance Learning Content Developer Intern, you’ll be integral to our work in helping vulnerable children achieve a brighter future. You will partner with the...Work experience placementInternshipFlexible hours- ...resolution steps, to support Root Cause analysis and process improvement initiatives. Collaborate with stakeholders to develop and enhance the SIEM platform and overall detection program. Possess familiarity with container technologies such as Kubernetes and...
$138k - $162k
...Focus) , you'll design, deploy, and sustain secure database environments that support enterprise security platforms, analytics, and SIEM capabilities in classified, mission-critical systems. This role partners with cybersecurity, SIEM, and infrastructure teams to support...Full timeWork experience placementLocal areaFlexible hours- ...Eagle Harbor Solutions, LLC a Koniag Government Services company, is seeking an experienced Front End Web Developer with a Secret security clearance to support EHS and our government customer in Washington, DC. This position is for a Future New Business Opportunity....Work experience placementLocal areaFlexible hours
- Koitecc Solutions is seeking a Splunk Engineer SME to handle a strategic Cybersecurity Task Order. The ideal candidate will have 12-15 years of experience in system administration, cybersecurity, and will excel in building and maintaining Splunk infrastructure on both on...
- Marmic Fire & Safety Co. is seeking a Cybersecurity Training Content Developer to support our client in Washington, DC. This remote role focuses on designing and implementing advanced cybersecurity training programs. We aim to bridge the gap between technical operations...Remote job
- Description The Training & Content Developer is responsible for designing, developing, and maintaining training materials and digital learning content for the USDA National Organic Program. This role supports the Organic Integrity Learning Center (OILC) by creating engaging...Worldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to SIEM Content Developer. Be the first to apply!
- virtual web developer Washington DC
- web associate Washington DC
- remote web developer apprenticeship Washington DC
- junior web developer Washington DC
- web programmer Washington DC
- ecommerce web developer Washington DC
- remote contract web developer Washington DC
- amazon web services engineer Washington DC
- website content developer Washington DC
- junior web developer internship Washington DC


