×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

SIEM Content Engineer

Job in Washington, District of Columbia, 20022, USA
Listing for: Tyto Athene, LLC
Full Time position
Listed on 2026-08-04
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

Tyto Athene is searching for a forward-thinking and self-motivated SIEM Content Engineer to focus on enhancing a government client’s detection content for their Security Operations Center (SOC). This exciting role requires curiosity, creativity, and critical thinking skills, as well as superior attention to detail, great organizational skills, and the ability to work in a highly collaborative work environment.

Responsibilities:
  • Evaluate existing SIEM content to determine which content should be removed or updated to improve fidelity
  • Leverage the MITRE ATT&CK framework, monitor the threat landscape and evaluate existing data sources to identify opportunities for new SIEM content development
  • Support the onboarding of new data sources by developing relevant SIEM content
  • Develop SIEM detection uses cases and review them with relevant stakeholders, such as security engineers, SIEM engineers, SOC analysts, and incident responders
  • Collaborate with security engineers to improve logging from various appliances and correct misconfigurations
  • Coordinate closely with SOC analysts and incident responders to develop playbooks for triaging and responding to events created by the SIEM tool
  • Develop and maintain a SIEM content catalog, including mapping to the MITRE ATT&CK framework, to improve the efficiency of deploying the security stack to new environments
  • Design, develop, and monitor various dashboards and reports that provide information on content coverage, alerting, and fidelity
Required:
  • Eight (8) years of general work experience (with at least six (6) years of IT/Cyber experience) and two (2) years of experience using Splunk (or a similar SIEM tool) in a cybersecurity context (e.g., as a content developer, administrator, or SOC analyst, etc.…)
  • Direct experience developing SIEM content in collaboration with a Tier 1 security operations center
  • Effective verbal and written communication skills that include the ability to describe highly technical concepts in non-technical terms
  • Ability to manage, analyze, and report complex data in an easy-to-understand format for a variety of stakeholders
  • Familiarity with the MITRE ATT&CK Framework
  • Experience with Splunk and development
  • Experience developing Splunk dashboards, reports, and alerts
  • Experience with Splunk Enterprise Security is a plus
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary