Talent.com
Wits Solutions Inc
SIEM Content DeveloperWits Solutions Inc • Columbus, OH, United States
Search for other jobs
SIEM Content Developer

SIEM Content Developer

Wits Solutions Inc • Columbus, OH, United States
2 days ago
Job type
  • Full-time
  • Quick Apply
Job description

Wits Solutions Inc. (WITS) is a SBA certified Small Disadvantaged Business with headquarters in the metropolitan Washington D.C. area. WITS has been providing best-in-class solutions in professional IT and administrative consulting to various Federal, State, Local and commercial customers. At WITS, we believe in working not for our clients but with them. This is why right from the beginning; our analysts and solution-builders work closely with our clients to ensure that the project outcomes continue to deliver value long into the future.

Job Description:

Security Clearance:

  • Current DoD Top Secret; eligible for IT-I Critical Sensitive / Tier 5 (T5)

Education/ Certification Mandatory:

  • No separate degree minimum is stated in the task-order PWS. DoDM 8140.03-aligned certifications required. Candidate must meet the applicable JETS 2.0 IDIQ labor-category education requirements and applicable DoDM 8140.03 / DLA certification requirements.

Work Experience Mandatory:

  • Minimum 5 years relevant IT experience; 3 years working with a SIEM in content development or Incident Response; 3 years System and/or Network Administration; understanding of various log formats; MITRE ATT&CK; strong network architecture knowledge; experience developing and maintaining scripts, preferably PowerShell, Python or SPL; understanding of Defense-in-Depth.

Education/Certifications Nice To Have:

  • Splunk certifications, CISSP, Security+, GIAC detection/incident-response certifications, or other SIEM/content-engineering and DoDM 8140.03-aligned credentials.

Work Experience Nice To Have:

  • DoD/DLA CSSP or CERT detection engineering; Splunk Enterprise Security; custom correlation searches and detections; log onboarding/data quality; IDS/IPS signatures; firewall countermeasures; detection-as-code; automation and threat-intelligence-driven use cases.

Roles And Responsibilities:

  • Research and develop new threat-detection use cases based on emerging threats, CTI and analyst feedback.
  • Work with cybersecurity tool SMEs and stakeholders to identify security protection and analytics gaps.
  • Develop and maintain custom scripts that enhance SIEM functionality, preferably PowerShell, Python and SPL.
  • Review SIEM data-feed quality and recommend or implement improvements.
  • Identify critical systems/application components and establish alerting priorities.
  • Develop signatures and detections tailored to programs and applications.
  • Apply MITRE ATT&CK, network-architecture knowledge and Defense-in-Depth principles to SIEM content development.
  • Support detection tuning, testing and operational deployment in coordination with DLA cybersecurity stakeholders.
Create a job alert for this search

SIEM Content Developer • Columbus, OH, United States