SIEM Content Developer
Core
Research emerging threats and develop new SIEM threat-detection use cases, detection signatures, and alerting priorities for critical systems.
Role type
Senior IC SIEM Content Developer
Builds
Custom detection signatures, alerting rules, and tailored SIEM content
Domain
Cybersecurity / Threat Intelligence / Security Analytics
Required skills
SIEM content development, threat intelligence research, PowerShell scripting, Python scripting, SPL scripting, log format analysis, MITRE ATT&CK framework knowledge, network architecture understanding, Defense-in-Depth principles, incident response, systems administration, network administration
Preferred skills
Stakeholder collaboration, cybersecurity tool SME expertise
Responsibilities
Research emerging threats and threat intelligence to develop new SIEM threat-detection use cases; Create detection signatures, alerting priorities, and tailored SIEM content; Assess threat-detection coverage gaps and advise cybersecurity leadership on detection practices; Develop and maintain custom scripts using PowerShell, Python, or SPL; Collaborate with stakeholders, cybersecurity tool SMEs, and Threat Detection Analysts to identify analytics gaps and improve data feeds
Seniority
Senior, hands-on IC