SIEM Content Developer

DirectViz Solutions, LLC•Columbus, OH
•Onsite

About The Position

We are seeking an experienced SIEM Content Developer to research, develop, and enhance threat detection capabilities within a complex cybersecurity environment. This role focuses on creating new threat detection use cases based on emerging threats, threat intelligence, and feedback from security analysts. The SIEM Content Developer will work closely with cybersecurity stakeholders, security tool SMEs, incident response teams, and threat detection analysts to identify gaps in security monitoring and analytics. The position will develop custom scripts and SIEM content, evaluate the quality of security data feeds, and create alerts and signatures tailored to critical systems and applications.

Requirements

  • Five (5) years of relevant IT experience
  • Three (3) years working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and/or Network Administration experience
  • Understanding of various log formats
  • Understanding of the MITRE ATT&CK framework
  • Strong understanding of network architecture
  • Experience developing and maintaining scripts (preferably using Powershell, Python or SPL)
  • Understanding of Defense-in-Depth
  • Must possess a current DOD Top Secret Clearance and be eligible for an IT-I Critical Sensitive security clearance

Responsibilities

  • Research and develop new threat detection use cases based on emerging threats, threat intelligence research, and Threat Detection Analyst feedback.
  • Work with stakeholders and cybersecurity tool SMEs to identify gaps in security protection and analytics capabilities.
  • Develop custom scripts to enhance SIEM functionality and automate security monitoring activities.
  • Review the quality and effectiveness of SIEM data feeds and recommend or implement improvements.
  • Analyze log sources and ensure relevant security data is available for detection and investigation.
  • Collaborate with stakeholders to identify critical systems and application components and establish appropriate alerting priorities.
  • Develop and maintain detection signatures and alerts tailored to individual systems, programs, and applications.
  • Support continuous improvement of SIEM detection capabilities based on evolving threats and operational requirements.
  • Apply knowledge of network architecture, Defense-in-Depth, and the MITRE ATT&CK framework when developing detection content.

Benefits

  • Competitive compensation
  • Comprehensive medical benefits
  • 401(k) match
  • Generous PTO accrual
  • Professional development reimbursement
  • Corporate-funded technology certifications
  • Robust employee recognition and appreciation programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service