About this role
Electrosoft Services, LLC is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, Zero Trust, digital engineering and transformation, and enterprise AI and intelligent automation. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel – and the knowledge that outstanding effort is recognized and rewarded. The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more. If we’ve described you and your dream workplace, please apply and share in the many benefits and opportunities we offer.
SIEM Content Developer
Researches and develops new threat detection use cases based on emerging threats, threat intelligence research and Threat Detection Analyst feedback. Works with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities. Develops custom scripts to enhance SIEM functionality. Reviews the quality of data feeds and recommend and/or implement improvements. Collaborates with stakeholders to identify critical systems and application components to develop alerting priorities and create signatures tailored to individual programs and applications.
Minimum Requirements:
- Five (5) years of relevant IT experience
- Three (3) years working with a SIEM in a content development or Incident Response role.
- Three (3) years of System and/or Network Administration experience
- Understanding of various log formats
- Understanding of the MITRE ATT&CK framework
- Strong understanding of network architecture
- Experience developing and maintaining scripts (preferably using Powershell, Python or SPL)
- Understanding of Defense-in-Depth
- Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance or Tier 5 (T5) at time of proposal submission.