Job Description
Description Leidos is seeking an experienced Content Developer to join our team on a highly visible cyber security single-award IDIQ vehicle. Duties include proactively searching for threats. Inspect traffic for anomalies and new malware patterns. Investigate and analyze logs. Develop custom content within the Splunk SIEM using advanced SPL language and data models) or other network security tools to detect threats and attacks against the department. SIEM Content Developers participate in briefings to provide expert guidance on new threats and will act as an escalation point for analysts. The analyst may also be required to author reports and/or interface with customers for ad-hoc requests. In addition, the threat detection engineer may be asked to participate in discussions to make recommendations on improving SOC visibility or process. Primary Responsibilities Capture use cases from subscribers or other team members and develop correlation rules Utilize knowledge of latest threats and attack vectors to develop Splunk correlation rules for continuous monitoring Develop, manage, and maintain Splunk data models Review logs to determine if relevant data is present to accelerate against data models to work with existing use cases Develop custom regex to create custom knowledge objects Developing custom SPL using macros, lookups, etc., and network security signatures such as SNORT and YARA Develop custom dashboards and reports for customer stakeholders Train and mentor junior staff Basic Qualifications Bachelor's Degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field and 12+ years of experience or MS Degree and 10 years of experience In addition, at least eight (8) years of experience in incident detection and response