Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SIEM Content Developer

Base One Inc

Primary Responsibilities Experience with creating and implementing custom IOCs and IOAs in Crowdstrike Experience with triaging and investigating hosts using Crowdstrike Experienced with updating McAfee AV signatures Experience with creating and maintain custom Tanium packages for collecting artifacts for continuous monitoring Provide recommendations for tuning and/or triaging notable events Perform critical thinking and analysis to investigate cyber security alerts Analyze network traffic using enterprise tools (e.g. Full PCAP, Firewall, Proxy logs, IDS logs, etc) Collaborate with team members to analyze an alert or a threat Stay up to date with latest threats and familiar with APT and common TTPs Utilize OSINT to extrapolate data to pivot and identify malicious activity Have experience with dynamic malware analysis Have experience performing analysis of network traffic and correlating diverse security logs to perform recommendations for response Utilize the Cyber Kill Chain and synthesize the entire attack life cycle Review and provide feedback to junior analysts’ investigation participate in discussions to make recommendations on improving SOC visibility or process Contribute to SOP development and updating Provide expert guidance and mentorship to junior analysts Qualifications Basic requirements that the recruiter should use as a filter: All Tier 2 analyst candidates shall have a minimum a bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field PLUS eight (8) years of experience in incident detection and response, malware analysis, or cyber forensics. Of the eight (8) years of professional experience requirements above, SIEM Content Developer candidates shall have at least one (1) of the following specialized experience for their position: Monitoring and Detection Analyst: Candidates shall have a minimum of five (5) years of professional experience in security, information risk management, or information systems risk assessment, and must be knowledgeable in many areas such as Vulnerability Assessments, Intrusion Prevention and Detection, Access Control and Authorization, Policy Enforcement, Application Security, Protocol Analysis, Firewall Management, Incident Response, Data Loss Prevention (DLP), Encryption, Two-Factor Authentication, Web-filtering, and Advanced Threat Protection. Incident Response Analyst: Candidates shall have a minimum of five (5) years of professional experience responding to information system security incidents. Ability to use the DHS-furnished toolset to identify and determine root causes of incidents and provide any required documentation and possible evidence to security investigators. Candidates must have extensive experience working with various security methodologies and processes, advanced knowledge of TCP/IP protocols, experience configuring and implementing various technical security solutions, extensive experience providing analysis and trending of security log data from a large number of heterogeneous security devices, and must possess expert knowledge in two or more of the following areas related to cybersecurity: Vulnerability Assessment Intrusion Prevention and Detection Access Control and Authorization Policy Enforcement Application Security Protocol Analysis Firewall Management Incident Response Encryption Web-filtering Advanced Threat Protection Must have at least one of the following certifications: SANS GIAC:GCIA, GCIH, GCFA, GPEN, GWAPT, GCFE, GREM, GXPN, GMON, GISF, or GCIH EC Council:CEH, CHFI, LPT, ECSA

ISC2:CCFP, CCSP, CISSP CERT CSIH

Offensive Security:OSCP, OSCE, OSWP and OSEE Must have TS/SCI. In addition to specific security clearance requirements, all Department of Homeland Security SOC employees are required to obtain an Entry on Duty (EOD) clearance to support this program. The ideal candidate is a self-motivated individual in pursuit of a career in cyber security. Experienced with developing advanced correlation rules utilizing tstats and datamodels for cyber threat detection Experienced with creating and maintaining Splunk knowledge objects Experienced managing and maintaining Splunk data models Expertise in developing custom SPL using macros, lookups, etc and network security signatures such as SNORT and YARA Experience creating regex for pattern matching Implemented security methodologies and SOC processes Extensive knowledge about network ports and protocols (e.g. TCP/UDP, ICMP, DNS, SMTP, etc) Experienced with network topologies and network security devices (e.g. Firewall, IDS/IPS, Proxy, DNS, WAF, etc). Hands-on experience utilizing network security tools (e.g. Sourcefire, Suricata, Netwitness, o365, FireEye, etc) and SIEM Experience in a scripting language (e.g. Python, Powershell, etc) and automating SOC processes/workflow Experience training and mentoring junior analysts Extensive knowledge of common end user and web application attacks and countermeasures against attacks Experience developing custom workflows within Splunk to streamline SOC processes Experience creating SOPs and providing guidance to junior analysts Ability to analyze new attacks and provide guidance to watch floor analysts on detection and response Knowledgeable of the various Intel Frameworks (e.g. Cyber Kill Chain, Diamond Model, MITRE ATT&CK, etc) and able to utilize it in their analysis workflow Experience with cloud (e.g. o365, Azure, AWS, etc) security monitoring and familiar with cloud threat landscape Knowledgeable of APT capabilities and be able to implement appropriate countermeasures Preferred Qualifications Provide expert content development in Splunk Enterprise Security using tstats and datamodels Utilize knowledge of latest threats and attack vectors to develop Splunk correlation rules for continuous monitoring Review logs to determine if relevant data is present to accelerate against datamodels to work with existing use cases Capture use cases from subscribers or other team members and develop correlation rules Requirement Certifications CCFP – Certified Cyber Forensics Professional CHFI – Computer Hacking Forensic Investigator CISSP – Certified Information Systems Security CIRC ECSA – EC-Council Certified Security Analyst EnCE FIWE GCFA – Forensic Analyst GCFE – Forensic Examiner GCIH – Incident Handler GISF – Security Fundamentals GREM – Reverse Engineering Malware GXPN – Exploit Researcher and Advanced Penetration Tester LPT – Licensed Penetration Tester OSCE (Certified Expert) OSCP (Certified Professional) OSEE (Exploitation Expert) OSWP (Wireless Professional)

WFE-E-CI

FTK-WFE-FTK

GCTI – Cyber Threat Intelligence GOSI – Open Source Intelligence CTIA – Certified Threat Intelligence Analyst #J-18808-Ljbffr Base One Inc

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the SIEM Content Developer in Washington DC vacancy
  • $140k - $180k

     ...engineering degree. The position offers a salary ranging from $140,000 to $180,000 depending on experience. Experience with AWS, VMWare, and SIEM products is preferred, along with strong teamwork and problem-solving skills. #J-18808-Ljbffr Edgewater Federal Solutions, Inc.
    Suggested

    Edgewater Federal Solutions, Inc.

    Bethesda, MD
    2 days ago
  • $77.6k - $176k

     ...Job Number: R0237536 SIEM Platform Engineer The Opportunity : Work with clients and peers to build a high-performing system using Elastic to aggregate logs from many systems into a single common schema.Use Elastic Common Schema (ECS) formatted fields, create... 
    Suggested
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    1 day ago
  •  ...Senior Engineer - SIEM Platform Engineering & Operations Denver, Colorado;Washington...  ...being an inclusive workplace, attracting and developing exceptional talent, supporting our...  ...relevant data sources. Oversee the Anvilogic content management platform including rule... 
    Suggested
    Work at office
    Shift work
    Day shift

    Bank of America

    Washington DC
    3 days ago
  •  ...oversee security operations. The ideal candidate will have extensive experience in cybersecurity, including expertise in Splunk and SIEM/SOAR operations, and will mentor junior cybersecurity personnel. This position may require occasional travel and includes comprehensive... 
    Suggested

    ARETUM Holdings LLC

    Bethesda, MD
    1 day ago
  • $77.6k - $176k

    A leading consulting firm in Virginia is seeking a skilled SIEM Platform Engineer. The role involves building systems with Elastic for log aggregation, creating visualizations and alerts to enhance security monitoring, and maintaining infrastructure for proactive issue... 
    Suggested
    Remote job

    Booz Allen Hamilton

    Alexandria, VA
    1 day ago
  • Dexian DISYS is seeking an experienced Coralogix SIEM Engineer to serve as the hands-on technical owner in Washington, DC. This role requires strong Coralogix platform administration skills and the ability to manage multi-tenant setups effectively. The ideal candidate... 

    Dexian DISYS

    Washington DC
    2 days ago
  • $77.6k - $176k

    SIEM Platform Engineer page is loaded## SIEM Platform Engineerlocations: Arlington, VAtime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 9, 2026 (30+ days left to apply)job requisition id: R0237536SIEM Platform Engineer**The Opportunity****:*... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Arlington, VA
    21 hours ago
  •  ...skilled individual to build high-performing systems using Elastic for log aggregation. The ideal candidate has extensive experience with SIEM platforms and data pipeline architectures. Responsibilities include creating visualizations for threat hunting and ensuring... 

    Phase2 Technology

    Arlington, VA
    4 days ago
  •  ...Position Summary August Schell is seeking a Senior  Splunk  / SIEM Engineer with advanced hands-on experience in designing,...  ...maintain complex Splunk clusters across varied hardware platforms Develop and optimize advanced Splunk dashboards and queries to support mission... 
    Work at office
    Remote work
    Home office
    2 days per week
    3 days per week

    August Schell

    Alexandria, VA
    22 days ago
  •  ...self-directed and experienced individual to fill the role of a SIEM Administrator/Security Monitoring Engineer for our existing government...  ..., normalization, enrichment, and throughput optimization. Develop and tune detection logic, correlation rules, and alerting... 
    Full time
    Part time
    For contractors
    Interim role
    Remote work

    Akima

    Alexandria, VA
    3 days ago
  • $107.9k - $195.05k

    Job Overview Leidos has an immediate need for a Splunk Content Developer for a new customer on a highly‑visible, strategic Cybersecurity Task...  ...with other Security Information and Event Management (SIEM) platforms. Extensive experience with advanced configuration... 
    Immediate start

    Leidos Inc

    Arlington, VA
    2 days ago
  • KellyMitchell Group is seeking a Senior Security Engineer in Bethesda, Maryland, focused on enterprise IT security and hybrid infrastructures. You will design, maintain security systems, and implement cybersecurity tools while collaborating with diverse teams. The ideal...

    KellyMitchell Group

    Bethesda, MD
    2 days ago
  •  ...and cloud environments • Deploy and configure security tools including EDR, SIEM, and identity management solutions • Provide technical support and troubleshooting for client environments • Develop automation scripts and tools to improve operational efficiency • Create... 
    Remote work

    Districttechgroup

    Washington DC
    4 days ago
  •  ...of security products and a minimum of 5 years experience in the information security space, with a preference for familiarity with SIEM technologies such as MS Sentinel or Splunk. This role also requires excellent communication skills and the ability to present complex... 

    Exabeam

    Washington DC
    1 day ago
  •  ...Security Incident and Event Management/Elastic Specialist in Washington, DC. The role requires a clear understanding of Elastic and SIEM processes. Candidates must be US citizens with a Secret Clearance and have at least three years of experience using Elastic/Splunk query... 

    Diligent Consulting Inc

    Washington DC
    3 days ago
  • $30 - $35 per hour

     ...Replies within 24 hours TITLE: IT Trainer/Content Developer LOCATION: Georgia/ Hybrid MINIMUM EDUCATION: Bachelor's degree in IT, related field, or equivalent experience. REQUIRED EXPERIENCE: + years INTERVIEWS: Either Web Cam or In Person... 
    Hourly pay
    Long term contract
    Permanent employment
    Contract work
    For contractors
    Work experience placement
    Work at office
    Remote work
    Work from home
    Flexible hours

    AHU Technologies, Inc.

    Washington DC
    4 days ago
  • COMFORT SYSTEMS is seeking a Splunk Content Developer in Arlington, Virginia to support a strategic cybersecurity task order. The ideal candidate must have extensive experience in system administration and Splunk, managing installations in both on-premise and cloud environments... 

    Comfort Systems USA

    Arlington, VA
    4 days ago
  •  ...POSITION OVERVIEW Reporting to the Program Manager, the Web Developer Embeds security across the SDLC for mission-critical web apps,...  ...WAF and FIM deploy/tune; Security testing tools (Wireshark, SIEM, IDS/IPS, NDR, EDR); risk assessment; DevSecOps CI/CD security... 
    Work from home
    Flexible hours

    Basecamp Consulting & Solutions LLC

    Washington DC
    1 day ago
  • $100k - $145k

     ...management, incident response, and drafting documentation. The ideal candidate will have over 4 years of cybersecurity experience, 2+ years with SIEM tools, and a Bachelor's degree. Salary is estimated between $100,000 and $145,000 based on experience. #J-18808-Ljbffr... 

    Dark Wolf

    Washington DC
    11 hours ago
  • A financial services firm in Arlington, Virginia is seeking an IT Security Engineer to enhance security posture and maintain data integrity. The role involves working with the IT Security team to define and implement security strategies. Candidates should have a bachelor...
    Flexible hours

    IntraFi

    Arlington, VA
    2 days ago
  • $40 per hour

     ...A tech company specializing in AI training is seeking a Content Developer - Math to assist in training AI models. The role involves evaluating the logic and quality of AI chatbots' outputs and providing writing and editing tasks. Candidates should have a strong command... 
    Hourly pay
    Remote work
    Flexible hours

    DataAnnotation

    Washington DC
    4 days ago
  • $40 per hour

     ...We are looking for a Content Developer - Math to join our team to train AI models. You will measure the progress of these AI chatbots, evaluate their logic, and solve problems to improve the quality of each model. In this role you will need to hold an expert level of writing... 
    Hourly pay
    Full time
    Contract work
    Part time
    Remote work

    DataAnnotation

    Washington DC
    21 hours ago
  • $90 - $130 per hour

     ...Summary: Our client is seeking a Security Infrastructure Support - SIEM & Data Pipeline Technical Lead / SME to join their team! This...  ...log management solutions across enterprise environments Develop, implement, and maintain secure and efficient data pipelines to... 
    Local area

    KellyMitchell Group

    Bethesda, MD
    4 days ago
  • $17 - $17.95 per hour

     ...creating positive, irreversible change for children, and the future we all share. The Role As the Fall 2026 Finance Learning Content Developer Intern, you’ll be integral to our work in helping vulnerable children achieve a brighter future. You will partner with the... 
    Work experience placement
    Internship
    Flexible hours

    Save the Children

    Washington DC
    21 hours ago
  •  ...resolution steps, to support Root Cause analysis and process improvement initiatives. Collaborate with stakeholders to develop and enhance the SIEM platform and overall detection program. Possess familiarity with container technologies such as Kubernetes and... 

    Samprasoft

    Washington DC
    2 days ago
  • $138k - $162k

     ...Focus) , you'll design, deploy, and sustain secure database environments that support enterprise security platforms, analytics, and SIEM capabilities in classified, mission-critical systems. This role partners with cybersecurity, SIEM, and infrastructure teams to support... 
    Full time
    Work experience placement
    Local area
    Flexible hours

    MetroStar Corporation

    Washington DC
    1 day ago
  •  ...Eagle Harbor Solutions, LLC a Koniag Government Services company, is seeking an experienced Front End Web Developer with a Secret security clearance to support EHS and our government customer in Washington, DC. This position is for a Future New Business Opportunity.... 
    Work experience placement
    Local area
    Flexible hours

    Koniag Government Services

    Washington DC
    5 days ago
  • Koitecc Solutions is seeking a Splunk Engineer SME to handle a strategic Cybersecurity Task Order. The ideal candidate will have 12-15 years of experience in system administration, cybersecurity, and will excel in building and maintaining Splunk infrastructure on both on...

    Koitecc Solutions

    Arlington, VA
    4 days ago
  • Marmic Fire & Safety Co. is seeking a Cybersecurity Training Content Developer to support our client in Washington, DC. This remote role focuses on designing and implementing advanced cybersecurity training programs. We aim to bridge the gap between technical operations... 
    Remote job

    Marmic Fire & Safety Co.

    Washington DC
    3 days ago
  • Description The Training & Content Developer is responsible for designing, developing, and maintaining training materials and digital learning content for the USDA National Organic Program. This role supports the Organic Integrity Learning Center (OILC) by creating engaging... 
    Worldwide

    TLN Worldwide Enterprises, Inc

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SIEM Content Developer. Be the first to apply!