Washington, DC, US
4 days ago
SIEM Content Engineer
Returning Candidate? Log back in! SIEM Content Engineer Location US-DC-Washington ID 2026-1644 Category Information Technology Position Type Full-Time Description

Tyto Athene is searching for a forward-thinking and self-motivated SIEM Content Engineer to focus on enhancing a government client’s detection content for their Security Operations Center (SOC). This exciting role requires curiosity, creativity, and critical thinking skills, as well as superior attention to detail, great organizational skills, and the ability to work in a highly collaborative work environment.

 

Responsibilities:

Evaluate existing SIEM content to determine which content should be removed or updated to improve fidelityLeverage the MITRE ATT&CK framework, monitor the threat landscape and evaluate existing data sources to identify opportunities for new SIEM content developmentSupport the onboarding of new data sources by developing relevant SIEM contentDevelop SIEM detection uses cases and review them with relevant stakeholders, such as security engineers, SIEM engineers, SOC analysts, and incident respondersCollaborate with security engineers to improve logging from various appliances and correct misconfigurationsCoordinate closely with SOC analysts and incident responders to develop playbooks for triaging and responding to events created by the SIEM toolDevelop and maintain a SIEM content catalog, including mapping to the MITRE ATT&CK framework, to improve the efficiency of deploying the security stack to new environmentsDesign, develop, and monitor various dashboards and reports that provide information on content coverage, alerting, and fidelity Qualifications

Required:

Bachelor’s degree requiredEight (8) years of general work experience (with at least six (6) years of IT/Cyber experience) and two (2) years of experience using Splunk (or a similar SIEM tool) in a cybersecurity context (e.g., as a content developer, administrator, or SOC analyst, etc.…)Direct experience developing SIEM content in collaboration with a Tier 1 security operations centerEffective verbal and written communication skills that include the ability to describe highly technical concepts in non-technical termsAbility to manage, analyze, and report complex data in an easy-to-understand format for a variety of stakeholdersFamiliarity with the MITRE ATT&CK FrameworkExperience with Splunk and developmentExperience developing Splunk dashboards, reports, and alerts

Desired:

Experience with Splunk Enterprise Security is a plus

Clearance:

Secret Clearance required

Location:

Remote About Tyto Athene

Compensation:

Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $150,000-$160,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains—Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT—empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide.  At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto?  Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law. Options ApplyApplySubmit a ReferralRefer Sorry the Share function is not working properly at this moment. Please refresh the page and try again later. Application FAQs

Software Powered by iCIMS
www.icims.com

Confirm your E-mail: Send Email