> Markdown version of [/jobs/ext/1828406-cyber-content-developer-siem-engineer-33-nws](https://www.wearedevelopers.com/jobs/ext/1828406-cyber-content-developer-siem-engineer-33-nws). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Content Developer/SIEM Engineer (33 NWS) - **Company:** Ipsecure, Inc. - **Location:** San Antonio, TX, United States - **Contract:** Permanent contract - **Skills:** Cyber Security, Intrusion Detection Systems, Python (Programming Language), Machine Learning, Network Forensics, Windows PowerShell, ArcSight SIEM Tool, Security Information and Event Management, Scripting, Mitre Att&ck, Information Technology, Free and Open-Source Software, Splunk - **Published:** July 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9031813/cyber-content-developersiem-engineer-33-nws ## About the Role * Ability to obtain the GIAC Machine Learning Engineer (GMLE) Certification within 120-days of hire date OR have a BS in Computer Science or MS in Computer Science/Cyber Security. * 2+ years of SIEM technology (ex: Arcsight, Splunk, Devo and/or ELK). * Experience with log handling, reports, filters, and rule creation. * Extensive knowledge with IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (ex: Air Force, Navy, Army, DC3, DISA). * 3+ years of experience with Network Traffic Analysis; ports and protocols. SANS GCDA or equivalent certification(s). * Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (ex: Open Source projects). * 1+ year of experience with Security, Orchestration, Automation, and Response (SOAR) platforms such as Phantom and/or Demisto. * Proficient in Python and PowerShell. ## Description The Cyber Content Developer/SIEM Engineer implements use cases based on mission requirements that provide analysts with a manageable SIEM view of security incidents, complete with workflow and reporting. Additionally, provide proactive housekeeping of associated content (use cases) with consideration for revisions and/or decommissioning. Will be in close collaboration with DO and DM leadership to ensure tasks align with squadron requirements, priorities, and future initiatives. * Analyze DCO events. * Apply current industry SIEM best-practices. * Use security alerts correlated with log enrichment data to enhance the operator's ability to identify real attacks. * Establish security control effectiveness and monitor for unauthorized outbound connections * Create detections by analyzing log data across the enterprise. * Develop dashboards and visualizations to identify adversarial activity. * Use log data to establish and implement virtual tripwires for early detection. * Analyze and ingest security logs into the SIEM in order to optimize for performance of the SIEM. * Conduct designing, implementing, and testing of various SIEM solutions. * Create and support the creation of SIEM Use Cases and understand what alerts and log enrichment is necessary to meet the required acceptable false positive rate. * Create, test, and validate filters and rules. * Build and implement event correlation rules, logic, and content in the SIEM. * Tune SIEM event correlation rules and logic to filter out security events associated with known and well-established network behavior, known false positives and/or known errors. * Analyze malware threats to develop behavior-based detections that alert and/or prevent malicious activity. * Automate tasks in the SIEM using a common programming or scripting language. * Create scheduled and ad-hoc reporting with SEIM tools. * Create and maintain SIEM documentation. * Develop and execute a process to review and maintain SIEM resources such as rules, filters, lists, trends and reports. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)