System One • Vienna, VA 22185
Job #2818350971
Cybersecurity Detection Content Developer
Location: Hybrid based o ut of Vienna, VA, Winchester, VA or Pensacola, FL or Remote.
Pay Rate: Open to Both C2C and W2 options
Position Type: Multiyear Contract
Job Description:
Create high-confidence security monitoring content consisting of dashboards and alerts within SIEM and other network security tools (Hybrid/Cloud) to detect threats, suspicious activities, potential incidents, and aid in analytical-investigations.
Continuously evaluate and optimize custom and OOTB (out of the box) detection content monitoring various on-prem and cloud service provider environments in support to SOC operations.
Serve as lead cyber security content SME for collaboration with various teams for purposes including, but not limited to threat intelligence, hunt operations, red team engagements, identity management, security architecture review, security event logging issues, and detection content management for identifying gaps and enhancing The organization's cyber security monitoring posture.
Log Analysis:
Troubleshoot issues in production and other test and development environments, applying debugging and problem-solving methodologies (e.g., log analysis, non-invasive tests).
Conduct independent critical thinking to diagnose and analyze threat intelligence data, latest threats and attack vectors, tactics, techniques, and procedures (TTPs) to make decisions on the most effective response and remediation strategies through content development.
Perform analysis of log files from a variety of sources (e.g., individual host logs, network traffic logs, firewall logs, and intrusion detection system [IDS] logs) to identify possible threats and vulnerabilities impacting the organization.
Documentation and Process Improvement:
Develop technical documents including, but not limited to content creation, content/rule review process, language-specific querying for disparate log sources, network/security visibility issues, detection gaps, SOPs, and monitoring strategies.
Continuously executes timely and effective communication across team and management channels regarding tasks completed, roadblocks experienced, and process improvement opportunities identified.
7+ years of experience within cyber security operations and SIEM technologies serving in a senior analyst or supervisory role.
Advanced knowledge of content creation concepts, content development management, content testing, implementation, the revision cycle, and cybersecurity threat analysis of complex events.
Advanced skills in monitoring and analyzing logs and alerts from a variety of different technologies and sources, to include but not limited to IDS/IPS, firewall, proxies, network/host, anti-virus, OS events, application/database, EDR, NDR, Cloud (IaaS, PaaS, SaaS).
Advanced skill in developing complex detection content using various data sources and query languages - e.g., custom SPL(macros, lookups, regex) SNORT, YARA, KQL
Experience in analyzing security systems, and how changes in conditions, operations, or the environment will affect deployed monitoring content.
Experience in applying cybersecurity and privacy principles to organizational requirements
(relevant to confidentiality, integrity, availability, authentication, non-repudiation).
application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting,
Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert
channel, replay, return-oriented attacks, malicious code).
applicability to custom content development
information clearly and concisely to all levels of management, supervisors, stakeholders and vendors
through advanced research, analytical, and problem solving skills
Forensic Analysis, Malware analysis, SIEM, Cloud, and the content development lifecycle
development of cyber defense detections
certifications
Desired: Bachelor degree in cybersecurity or related discipline
Desired: Advanced knowledge of IT security standards and frameworks (e.g., MITRE ATT&CK )
System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
System One • Reston, VA 20190 • Yesterday
System One • Reston, VA 20190 • 2 Days Ago
System One • Vienna, VA 22184 • 2 Days Ago
System One • Herndon, VA 22095 • Yesterday
System One • Vienna, VA 22184 • Yesterday
Symplicity • Arlington, VA 22201 • 8 Days Ago
Leidos • Arlington, VA 22201 • 8 Days Ago
Audacia Strategies • Arlington, VA 22205 • Yesterday