What are the responsibilities and job description for the Cyber Threat Detection Specialist position at Leidos?
Job Summary:
Leidos is seeking an experienced Cyber Threat Detection Specialist to join our team in a highly visible cyber security role. The ideal candidate will have a strong background in threat detection and incident response, with expertise in developing advanced correlation rules utilizing tstats and data models for cyber threat detection.
Responsibilities:
Leidos is seeking an experienced Cyber Threat Detection Specialist to join our team in a highly visible cyber security role. The ideal candidate will have a strong background in threat detection and incident response, with expertise in developing advanced correlation rules utilizing tstats and data models for cyber threat detection.
Responsibilities:
- Capture use cases from subscribers or other team members and develop correlation rules
- Utilize knowledge of latest threats and attack vectors to develop Splunk correlation rules for continuous monitoring
- Develop, manage, and maintain Splunk data models
- Review logs to determine if relevant data is present to accelerate against data models to work with existing use cases
- Develop custom regex to create custom knowledge objects
- Developing custom SPL using macros, lookups, etc., and network security signatures such as SNORT and YARA
- Develop custom dashboards and reports for customer stakeholders
- Train and mentor junior staff