Quick Summary
Research and develop new threat detection use cases based on emerging threats, threat intelligence research, and Threat Detection Analyst feedback.
Experience: Five (5) years of relevant IT experience. Three (3) years of experience working with a SIEM in a content development or Incident Response role.
AGE Solutions is seeking an experienced SIEM Content Developer to support the development and enhancement of cybersecurity threat detection capabilities. This position researches emerging threats and threat intelligence to develop new detection use cases, identifies gaps in security protection and analytics capabilities, and develops custom scripts to enhance SIEM functionality.
The SIEM Content Developer works closely with stakeholders, cybersecurity tool SMEs, and Threat Detection Analysts to improve data feeds, establish alerting priorities, and create detection signatures tailored to critical systems, programs, and applications.
Responsibilities
~2 min read- →Research and develop new threat detection use cases based on emerging threats, threat intelligence research, and Threat Detection Analyst feedback.
- →Collaborate with stakeholders and cybersecurity tool Subject Matter Experts (SMEs) to identify gaps in security protection and analytics capabilities.
- →Develop custom scripts to enhance SIEM functionality and threat detection capabilities.
- →Review the quality of SIEM data feeds and recommend or implement improvements.
- →Collaborate with stakeholders to identify critical systems and application components.
- →Develop alerting priorities based on identified critical systems and application components.
- →Create signatures tailored to individual programs and applications.
- →Develop and maintain scripts using PowerShell, Python, SPL, or similar scripting capabilities identified for the role.
- →Apply knowledge of various log formats when developing and maintaining SIEM content.
- →Apply knowledge of the MITRE ATT&CK framework when developing threat detection use cases.
- →Apply knowledge of network architecture when developing security analytics and detection capabilities.
- →Apply an understanding of Defense-in-Depth when supporting security protection and analytics capabilities.
- →Independently assess material gaps in customer threat-detection coverage, compare alternative corrective approaches, and recommend priorities based on system criticality, security risk, and operational impact.
- →Advise customer cybersecurity leadership on changes to detection practices and monitoring priorities, explaining the alternatives, tradeoffs, and expected effects on protection of critical systems and applications.
Requirements
~1 min read- Experience:
- Five (5) years of relevant IT experience.
- Three (3) years of experience working with a SIEM in a content development or Incident Response role.
- Three (3) years of System and/or Network Administration experience.
- Clearance:
- Must possess a current DoD Top Secret Clearance with IT-I, T5 investigation.
- Certifications:
- Must have at least one IAT-II Certification:
- Cisco Certified Network Associate Security (CCNA Security)
- CompTIA Cybersecurity Analyst (CySA+)
- Global Industrial Cyber Security Professional (GICSP)
- GIAC Security Essentials (GSEC)
- CompTIA Security+ Continuing Education (Security+ CE)
- Systems Security Certified Practitioner (SSCP)
- Must have at least one CSSP IR / CSSP A certification from the list of the following:
- CSSP Analyst Certified Ethical Hacker (CEH)
- CyberSec First Responder (CFR)
- CompTIA Cybersecurity Analyst (CySA+)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Certified Incident Handler (GCIH)
- Global Industrial Cyber Security Professional (GICSP)
- Cisco Cybersecurity Specialist (SCYBER)
- GIAC Certified Forensic Analyst (GCFA)
- Must have at least one IAT-II Certification:
- Skills and Qualifications:
- Understanding of various log formats.
- Understanding of the MITRE ATT&CK framework.
- Strong understanding of network architecture.
- Experience developing and maintaining scripts, preferably using PowerShell, Python, or SPL.
- Understanding of Defense-in-Depth.
- Location:
- This role is full-time onsite at our customer’s location in Columbus, OH.
- Work is primarily performed in a professional office or technical environment.
- Requires prolonged periods of sitting and working at a computer workstation.
- Requires frequent use of computers, keyboards, monitors, and standard office equipment.
- Requires the ability to communicate effectively with team members and stakeholders in person, by telephone, and through virtual collaboration tools.
- May require occasional standing, walking, bending, and reaching during the normal course of work.
- Requires the ability to maintain concentration and attention to detail while reviewing security data, threat intelligence, log information, and SIEM content.
- Must be able to work effectively in a collaborative environment with stakeholders, cybersecurity tool SMEs, and Threat Detection Analysts.
The projected salary range for this position is $115,000+ annually. Final compensation will be determined based on factors including years of relevant experience, active security clearance level, certifications, technical skillset, contract requirements, and overall qualifications.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 60%
- Scored at
- September 29, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.