Leidos is seeking an experienced Content Developer to join our team on a highly visible cyber security single-award IDIQ vehicle. Duties include proactively searching for threats. Inspect traffic for anomalies and new malware patterns. Investigate and analyze logs. Develop custom content within the Splunk SIEM using advanced SPL language and data models) or other network security tools to detect threats and attacks against the department. SIEM Content Developers participate in briefings to provide expert guidance on new threats and will act as an escalation point for analysts. The analyst may also be required to author reports and/or interface with customers for ad-hoc requests. In addition, the threat detection engineer may be asked to participate in discussions to make recommendations on improving SOC visibility or process. Primary Responsibilities Capture use cases from subscribers or other team members and develop correlation rules Utilize knowledge of latest threats and attack vectors to develop Splunk correlation rules for continuous monitoring Develop, manage, and maintain Splunk data models Review logs to determine if relevant data is present to accelerate against data models to work with existing use cases Develop custom regex to create custom knowledge objects Developing custom SPL using macros, lookups, etc., and network security signatures such as SNORT and YARA Develop custom dashboards and reports for customer stakeholders Train and mentor junior staff
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level