Shuvel is hiring a
Cybersecurity Detection Content Developer in United States

Logo of Shuvel
Cybersecurity Detection Content Developer
🏢 Shuvel
💵 ~$90k-$107k
📍United States
📅 Posted on Jun 30, 2024

Summary

The job is for a Cyber Security Content Developer in Vienna, VA with hybrid work arrangements. The role involves creating high-confidence security monitoring content, conducting log analysis, developing technical documents, and improving processes. Requires 7+ years of experience in cybersecurity operations and SIEM technologies.

Requirements

  • 7+ years of experience within cyber security operations and SIEM technologies serving in a senior analyst or supervisory role
  • Advanced knowledge of content creation concepts, content development management, content testing, implementation, the revision cycle, and cybersecurity threat analysis of complex events
  • Advanced skills in monitoring and analyzing logs and alerts from a variety of different technologies and sources, to include but not limited to IDS/IPS, firewall, proxies, network/host, anti-virus, OS events, application/database, EDR, NDR, Cloud (IaaS, PaaS, SaaS)
  • Advanced skill in developing complex detection content using various data sources and query languages - e.g., custom SPL(macros, lookups, regex) SNORT, YARA, KQL
  • Experience in analyzing security systems, and how changes in conditions, operations, or the environment will affect deployed monitoring content
  • Experience in applying cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
  • Advanced knowledge of security architectures, devices, proxies, firewalls, and system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return-oriented attacks, malicious code)
  • Advanced understanding of blue team/red team processes and technologies and their applicability to custom content development
  • Advanced verbal and written skill presenting complex findings, conclusions, alternatives, and information clearly and concisely to all levels of management, supervisors, stakeholders and vendor through advanced research, analytical, and problem solving skills

Responsibilities

  • Create high-confidence security monitoring content consisting of dashboards and alerts within SIEM and other network security tools (Hybrid/Cloud) to detect threats, suspicious activities, potential incidents, and aid in analytical-investigations
  • Continuously evaluate and optimize custom and OOTB detection content monitoring various on-prem and cloud service provider environments in support to SOC operations
  • Serve as lead cyber security content SME for collaboration with various teams for purposes including, but not limited to threat intelligence, hunt operations, red team engagements, identity management, security architecture review, security event logging issues, and detection content management for identifying gaps and enhancing NFCU cyber security monitoring posture
  • Troubleshoot issues in production and other test and development environments, applying debugging and problem-solving methodologies (e.g., log analysis, non-invasive tests)
  • Conduct independent critical thinking to diagnose and analyze threat intelligence data, latest threats and attack vectors, tactics, techniques, and procedures (TTPs) to make decisions on the most effective response and remediation strategies through content development
  • Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats and vulnerabilities impacting the NFCU organization

Preferred Qualifications

  • Splunk Power User
  • CySA+, CASP+, CISSP or other related Information Security certifications
  • Bachelor degree in cybersecurity or related discipline
  • Advanced knowledge of IT security standards and frameworks (e.g., MITRE ATT&CK )
Help us out by mentioning to Shuvel that you discovered this job opportunity on JobsCollider. Your support is greatly appreciated. Thank you 🙏
Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Jobs