Demo

CTA Security Content Engineer

Expedient Staffing Solutions
York, NY Full Time
POSTED ON 5/22/2026
AVAILABLE BEFORE 6/22/2026

Job Description:

The cyber-attack surface has significantly expanded with continuous threats by sophisticated actors, threats from new and emerging technologies, and the expansion of CityNet the last few years into virtual private and public cloud providers, into third-party hosted applications and services, and coupled with the rapid shift to telework by the City’s workforce and remote learning initiatives due to the pandemic. Counter Threat Automation (CTA) team supports the increase in security alerts and incidents associated with these initiatives. Increased alerts drive the need to build a comprehensive, innovative, intelligence driven, and a risk informed cyber defense and response strategy.

The resource function is essential to defend systems from cyber threats including direct support of life-safety, revenue generating, and COVID response operations. The CTA Security Content Engineer will support key Threat Management teams (Counter Threat Automation, Security Operations Center, Computer Emergency Response Team, Counter Threat Intelligence) by proactively deploying security-driven content. Specifically, improve the quality of alerts and detection through fine-tuning of policies/rule-setting using log management and security incident platforms; collaborate with TM teams during investigations, and develop a comprehensive threat detection library.

Scope of Services:

The cyber threat landscape has further expanded across networks and services since the pandemic response: threats have increased the volume of alerts, detections, and investigations. The company requires a high energy and experienced CTA Security Content Engineer to perform many critical functions within the Threat Management discipline to improve the City’s cybersecurity posture, and uplift the company’s ability to respond to cyber-attack. The Engineer will collaborate with the company’s Counter Threat Automation, Security Operations Center, Computer Emergency Response Team, and Counter Threat Intelligence teams to proactively develop and deploy security-driven content that improves the quality of alerts and detections. Specifically, build new--and fine-tune existing--security rules and policies using log management and NextGen SIEM platforms, and develop/push customized scripts that aid in threat detection and alerting. The Engineer will also develop ad-hoc content to assist teams with incident response operations; develop and manage a comprehensive threat content library of adversarial behavioral rules and policies mapped to the MITRE ATT&CK framework.

Tasks:

  • Develop correlation searches, dashboards, reports and alerts within the SIEM.
  • Develop User Entity Behavioral Analytic (UEBA) policies and rules within the NextGen SIEM platform and tune alerts for accuracy.
  • Map use cases and subsequent rules and policies to the MITRE ATT&CK framework.
  • Integrate innovative and custom technology to improve accuracy of alerts and notifications received by teams within Threat Management.
  • Create well documented and clearly articulated code, process and services documentation.
  • Understand REST and GraphQL API usage and implement solutions utilizing APIs from utilized solutions that enhance detection and response capabilities.
  • Collaborate with CTA, SOC, CERT and CTI teams to build robust, high fidelity detections and automated alerting workflows. 
  • Demonstrate a deep understanding of the SIEM and SOAR tools used to detect and respond to security threats along with other security products and data that will be used for the goal of threat detection.
  • Proactively build new threat detection content in alignment with cyber threat intelligence and in accordance with the cyber operations security strategy.
  • Establish, update, and maintain the content and development for the SIEM and SOAR platforms in order to achieve the goals of the cyber security operations program.

Mandatory Skills/ Experience:

  • Minimum 4 years of experience developing security rules, detections, and policies within Log Management platforms, NextGen SIEM’s (including UEBA) platforms
  • Proficient in Python, and/or GoLang
  • Experience building security driven content on key infrastructures such as log management platforms (Elastic, or Splunk or similar platforms), NextGen SIEM’s and UEBA platforms (Exabeam, Securonix)
  • Experience using NextGen SIEM’s such as Splunk, Elastic to create rules and alerts
  • Thorough knowledge of the MITRE ATT&CK framework, and working knowledge mapping security rules and policies for detection to the MITRE ATT&CK framework
  • Experience building correlation rules and alerts on log management platforms
  • Experience building policies and rules on email and network platforms
  • Proficient in git version control and git lifecycle development
  • Excellent verbal and written communication skills

Desirable Skills/Experience:

  • Bachelor’s degree
  • Basic understanding of Agile development model
  • Basic understanding of malware analysis and building rules for to identify malware families and threat actor TTPs that can be applied to platforms where applicable
  • Comprehensive understanding of building rules and alerts on multiple security-driven platforms, and understanding the end-to-end lifecycle of created rules and their corresponding alerts
  • Experience in technologies and platforms such as: Splunk, Elastic, Humio, Securonix, Google Cloud

Salary.com Estimation for CTA Security Content Engineer in York, NY
$116,807 to $147,825
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a CTA Security Content Engineer?

Sign up to receive alerts about other jobs on the CTA Security Content Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Expedient Staffing Solutions

  • Expedient Staffing Solutions York, NY
  • TEAM OVERSIGHT: Ensure that the mainframe team works together as a team and also within the enterprise to ensure that the systems remain available accordin... more
  • 13 Days Ago

  • Expedient Staffing Solutions Brooklyn, NY
  • Job Type: Hybrid or Full Remote *MUST RESIDE IN EST TIME ZONE* MANDATORY SKILLS/EXPERIENCE: Minimum 8 years of software development experience in an Agile ... more
  • 13 Days Ago

  • Expedient Staffing Solutions Brooklyn, NY
  • DESCRIPTION: The Subject Matter Expert (SME) is needed to continue the project work on the upgrade of the emergency call system. This resource is required ... more
  • 16 Days Ago

  • Expedient Staffing Solutions Brooklyn, NY
  • Job Type: Hybrid (minimum 2 days on-site) MANDATORY SKILLS/EXPERIENCE: At least 8 years of an experience as a QA analyst. Extensive experience with Seleniu... more
  • 16 Days Ago


Not the job you're looking for? Here are some other CTA Security Content Engineer jobs in the York, NY area that may be a better fit.

  • Tenex York, NY
  • The Role Content Engineering is to modern marketing what DevOps was to software. A new discipline that makes scale, governance, and speed possible without ... more
  • 7 Days Ago

  • Prime Content® Brooklyn, NY
  • About Prime Content Prime Content is a creative agency specializing in beauty, luxury, and lifestyle storytelling across photo, video, design, and digital ... more
  • 11 Days Ago

AI Assistant is available now!

Feel free to start your new journey!