SIEM Content Developer

Cb•Columbus, OH
•Onsite

About The Position

SarelaTech is seeking an experienced SIEM Content Developer to support a Department of War (DoW) cybersecurity mission in Columbus, Ohio. This position will research and develop new threat detection use cases based on emerging threats, threat intelligence research, and feedback from Threat Detection Analysts. The SIEM Content Developer will work with stakeholders and cybersecurity tool subject matter experts to identify gaps in security protection and analytics capabilities. The position will develop custom scripts to enhance SIEM functionality, review the quality of data feeds, and recommend or implement improvements. The SIEM Content Developer will also collaborate with stakeholders to identify critical systems and application components, establish alerting priorities, and create signatures tailored to individual programs and applications.

Requirements

  • Five (5) years of relevant information technology experience.
  • Three (3) years of experience working with a SIEM in a content development or Incident Response role.
  • Three (3) years of System and/or Network Administration experience.
  • Understanding of various log formats.
  • Understanding of the MITRE ATT&CK framework.
  • Strong understanding of network architecture.
  • Experience developing and maintaining scripts, preferably using PowerShell, Python, or SPL.
  • Understanding of Defense-in-Depth.
  • CompTIA Security+ certification.
  • At least one current certification meeting DoD 8570/8140 Cybersecurity Service Provider Incident Responder (CSSP-IR) requirements (e.g., CEH, CFR, Cisco Certified CyberOps Associate, CHFI, CySA+, PenTest+, GCFA, GCIH, SSCP).
  • Active DoD Top Secret (TS) security clearance.

Responsibilities

  • Research and develop new threat detection use cases based on emerging threats, threat intelligence research, and feedback from Threat Detection Analysts.
  • Work with stakeholders and cybersecurity tool subject matter experts to identify gaps in security protection and analytics capabilities.
  • Develop custom scripts to enhance SIEM functionality.
  • Review the quality of data feeds and recommend or implement improvements.
  • Collaborate with stakeholders to identify critical systems and application components.
  • Establish alerting priorities.
  • Create signatures tailored to individual programs and applications.

Benefits

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Paid time off
  • Profit sharing
  • Training & development
  • Tuition assistance
  • Vision insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service