1

Siem Content Developer Jobs (NOW HIRING)

The Splunk Content Developer will install and maintain Splunk infrastructure, gatherrequirements ... SIEM) platforms * Extensive experience with advanced configuration of Splunk including Indexer ...

The Splunk Content Developer SME will install and maintain Splunk infrastructure, gather ... SIEM) platforms * Extensive experience with advanced configuration of Splunk including Indexer ...

SOC Content Developer-Atlanta, GA

Atlanta, GA · Remote

$118K - $123K/yr

Splunk Content Developer-Atlanta, GA Required Education: Bachelor's Degree in Information ... Ability to interact with end users to gather requirements, optimize existing SIEM processes and ...

The Splunk Content Developer SME will install and maintain Splunk infrastructure ... SIEM) platforms * Extensive experience with advanced configuration of Splunk including Indexer ...

SOC Content Developer-Atlanta, GA

Atlanta, GA · On-site

$118K - $123K/yr

Splunk Content Developer-Atlanta, GA Required Education: Bachelor's Degree in Information ... Ability to interact with end users to gather requirements, optimize existing SIEM processes and ...

Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports * Analyze security events and log data to identify suspicious activity, support ...

Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports * Analyze security events and log data to identify suspicious activity, support ...

Configure, maintain, and optimize SIEM content including correlation rules, alerts, dashboards, and reports * Analyze security events and log data to identify suspicious activity, support ...

Junior Content Developer

Huntsville, AL

$69K - $90K/yr

PeopleTec is currently seeking a Junior Content Developer to support our Huntsville, AL location ... Cybersecurity SIEM (Splunk, Elastic) * Microsoft Power Platform (PowerBI, Power App, Power Automate)

Junior Content Developer

Huntsville, AL · On-site

$69K - $90K/yr

Opportunity PeopleTec is currently seeking a Junior Content Developer to support our Huntsville, AL ... Cybersecurity SIEM (Splunk, Elastic) * Microsoft Power Platform (PowerBI, Power App, Power Automate)

Junior Content Developer

Huntsville, AL · On-site

$69K - $90K/yr

Opportunity PeopleTec is currently seeking a Junior Content Developer to support our Huntsville, AL ... Cybersecurity SIEM (Splunk, Elastic) * Microsoft Power Platform (PowerBI, Power App, Power Automate)

Splunk Content Developer

Ashburn, VA · On-site

$131K - $237K/yr

The Cyber Systems Engineer - Splunk Content Developer is responsible for designing, engineering ... Management (SIEM) platform using advanced Search Processing Language (SPL), data models, and ...

The Cyber Systems Engineer - Splunk Content Developer is responsible for designing, engineering ... Management (SIEM) platform using advanced Search Processing Language (SPL), data models, and ...

next page

Showing results 1-20

Siem Content Developer information

See salary details

$29.5K

$116.6K

$129K

How much do siem content developer jobs pay per year?

As of Jun 8, 2026, the average yearly pay for siem content developer in the United States is $116,615.00, according to ZipRecruiter salary data. Most workers in this role earn between $123,000.00 and $128,000.00 per year, depending on experience, location, and employer.

What are some common daily responsibilities of a Siem Content Developer?

Siem Content Developers typically spend their days creating and refining detection rules, correlation searches, and security alerts within SIEM platforms to identify suspicious activities. They work closely with security analysts to understand emerging threats, tune existing content for accuracy, and research new attack techniques to ensure early detection. Regular responsibilities also include analyzing security logs, testing and documenting new rules, and collaborating with IT or incident response teams to translate business risk into technical controls. This collaborative and analytical environment helps foster ongoing professional development and deeper expertise in threat detection.

What are the key skills and qualifications needed to thrive in the Siem Content Developer position, and why are they important?

A successful Siem Content Developer possesses strong cybersecurity expertise, experience with SIEM platforms (such as Splunk, IBM QRadar, or ArcSight), and the ability to write detection rules and correlation logic. Familiarity with scripting languages, threat intelligence sources, and relevant certifications like CISSP or CompTIA Security+ are highly valuable. Excellent problem-solving, collaboration, and communication skills help developers work effectively with security teams and stakeholders. These competencies ensure the development of accurate, actionable detection content, keeping organizations protected from evolving cyber threats.

What is a SIEM Content Developer job?

A SIEM Content Developer is responsible for designing, creating, and optimizing security information and event management (SIEM) content such as correlation rules, dashboards, alerts, and reports. Their role involves analyzing security events, identifying threats, and enhancing detection capabilities. They work closely with security analysts and engineers to fine-tune SIEM configurations, improve threat detection, and reduce false positives. This role requires expertise in log analysis, threat intelligence, and scripting to customize SIEM solutions for an organization's security needs.

What cities are hiring for Siem Content Developer jobs? Cities with the most Siem Content Developer job openings:
What are the most commonly searched types of Siem Content Developer jobs? The most popular types of Siem Content Developer jobs are:
Infographic showing various Siem Content Developer job openings in the United States as of May 2026, with employment types broken down into 1% Internship, 70% Full Time, 28% Part Time, and 1% Temporary. Highlights an 80% Physical, 5% Hybrid, and 15% Remote job distribution, with an average salary of $116,615 per year, or $56.1 per hour.

Splunk Content Developer

Kinzo Staffing

Owings Mills, MD

Full-time

Posted 11 days ago


Job description

Kinzo Staffing is seeking a Splunk Enterprise Security Engineer who can develop custom detection content (correlation rules) identify threat activity. This includes developing notable events, visualizations, forms, reports, alerts, as well as Splunk Apps, Technology Add-ons, and normalize data sources to the Common Information Model. The candidate will provide optimization of data flow using aggregation, filters, etc. The Splunk Engineer will provide overall engineering, and administration in supporting a very large distributed clustered Splunk environment consisting of search heads, indexers, deployers, deployment servers, heavy/universal forwarders and Splunk Enterprise Security app, spanning security, performance, and operational roles. The Engineer should be proficient with recognizing and onboarding new data sources into Splunk, analyzing the data for anomalies and trends, and building dashboards highlighting the key trends of the data. The Splunk engineer should be proficient within a Linux environment, editing and maintaining Splunk configuration files and apps.

What you will do:

  • Alert use case development
  • Upgrade Splunk apps required by Splunk ES upgrades.
  • Splunk Enterprise Security administration and management.
  • Configure notable event actions, action menus and Adaptive Responses.
  • Data onboarding and data ingestion normalization recommendations.
  • Strong knowledge of security risk procedures, security patterns, authentication technologies and security attack pathologies.
  • Develop, evaluate, and document, specific metrics for management purpose.
  • Write complex code to install and manage the Splunk enterprise development.
  • Performing maintenance and optimization of existing clustered Splunk deployments.
  • Create Dashboards to monitor the traffic volumes, response times, errors, and warnings across various data centers.
  • Monitor the web portals, log files and databases.
  • Provide debugging and monitoring capabilities.
  • Design and Develop Splunk for routine use.
  • Solve complex Integration challenges and debug complex configuration issues.
  • Consult with stakeholders to establish, maintain and refresh their strategic direction in cloud adoption.
  • Become knowledgeable on the CDM technical requirements for the federal government’s CDM program. Understand your role in CDM activities.
  • Involved in a wide range of security issues including architectures, firewalls, electronic data traffic, and network access.
  • Design, manage, and maintain enterprise SIEM infrastructure to improve data ingestion processes, including architectural work on data pipelines to ensure optimal flow of data.
  • Maintenance, configuration and implementing products, appliances and devices on the enterprise network.

Qualifications:Required Qualifications:

  • Bachelor’s degree and 8 years of experience, Master's degree and 6 years of experience. Additional years of relevant experience may be accepted in lieu of the degree.
  • At least 4 years’ experience using customer-focused Splunk Enterprise Security SIEM engineering background - SME knowledge of ES v4.7
  • At least 4 years’ experience in a senior Splunk role working in a Splunk clustered environment supporting SOC or NOC environments
  • At least 4 years of experience with:
    • In-depth knowledge of designing, upgrading, maintaining and implementing network devices on a large-scale enterprise
    • Direct experience with Splunk Engineering and data integration
    • Prior SIEM data modelling experience on similar platform at scale (>50 servers)
    • Scripting and development skills in Python/Perl with deep comprehension of regular expressions
    • Coordination and communication with other remotely deployed team members
    • Developing documentation with processes and procedures
    • Proposing, implementing automation features in a large enterprise environment
  • At least 3 years of experience with Linux and SQL/ODBC interfaces
  • At least 2 years of experience in app interface development, using REST API’s
  • Hold active Splunk Core Certifications of at least Splunk Architect
  • Minimum of 3 year of experience in developing and tailoring reporting from network security tools.
  • Must be able to obtain and maintain a US Public Trust clearance.

Preferred Qualifications:

  • Experience with Splunk Common Information Model (CIM) and Enterprise Analytic
  • Strong problem-solving abilities with an analytic and qualitative eye for reasoning under pressure.
  • Self-starter with the ability to independently prioritize and complete multiple tasks with little to no supervision
  • Knowledge of Cloud Services such as AWS, Azure, Office365
  • Ability to script in one more of the following computer languages Python, Bash, Visual Basic or Powershell
  • Experience in automating Splunk Deployments and orchestration with in a Cloud environment