Emerging Threats Analyst

STS Systems Support, LLC

San Antonio (TX)

On-site

USD 85,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental and vision insurance
401(k) with company match
Paid holidays and time off

Job summary

STS Systems Support, LLC (SSS) is looking for an Emerging Threats Analyst at Lackland Air Force Base in San Antonio, TX. The role involves analyzing network traffic and providing insights on cyber threats using various analytical tools.

Ideal candidates will possess an active TS/SCI clearance. Responsibilities include conducting research, producing reports, and collaborating with other teams to enhance cybersecurity measures.

Qualifications

  • Active TS/SCI clearance required.
  • Formal intelligence analysis training and prior experience in a government setting.
  • Understanding of Networking principles including OSI Model and TCP/IP.

Responsibilities

  • Analyze network traffic using various tools.
  • Determine if traffic requires further investigation.
  • Correlate data to discern anomalies and trends.
  • Conduct research on advanced threat actors.
  • Write analytical reports on cyber threats.

Skills

Active TS/SCI
Formal intelligence analysis training and government experience
Understanding of Networking
Previous experience with hunting tools and technologies
Experience with open source Malware Analysis platforms
Knowledge of MITRE ATT&CK framework

Education

BA/BS or MA/MS

Tools

ArcSight
Splunk
Wireshark
Fidelis
Cuckoo
Joe Sandbox

Job description

Lackland Air Force Base, San Antonio, TX, USA •

Job Description

Posted Wednesday, July 1, 2026 at 5:00 AM

STS Systems Support, LLC (SSS) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We areseeking an Emerging Threats Analyst to support our mission at Lackland AFB in San Antonio, TX.

What You'll Do:
  • Analyze current and historical traffic entering the Air Force network using ArcSight (SIEM technology), Centaur, Noesis, Splunk, ELK, Fidelis, Solera, Niksun, Wireshark and other available tools (commercial and government provided), including OSINT and other classified reporting databases.
  • Determine if the network traffic requires further investigation of the Air Force asset(s) in question.
  • Correlate various data points using historical network traffic, operational events, reporting patterns, and other data to discern anomalies, patterns, or trends.
  • Perform post intrusion correlation to ensure current incidents are contained and have not spread to other Air Force Bases, networks or enclaves.
  • Provide tipper information to other organizations when required.
  • Collect weekly and monthly metrics (or as required) and trend information for organizational reports (as required) and long‑term analysis.
  • Continuously review (24/7/365) NCTOC reports, Tippers, SIGACTS, emails and other self‑reported problems and events.
  • Conduct research and gather threat intelligence on advanced threat actors.
  • Conduct Data Analysis for mission discovery of cyber threats and conduct characterization and attribution of those threats.
  • Identify cyber threats, trends, and new developments on various cyber security topics by analyzing raw intelligence and data which includes geopolitical and transnational events.
  • Present results to analysts and operators and train them how to recognize changes in operational environment likely to cause mission success or failure.
  • Create visual displays conveying situational awareness and engagement effectiveness assessments to the operational crews. (CDRL A008)
  • Analyze current all‑source intelligence from applicable intelligence community sources concerning adversary telecommunication and computer network systems supporting adversary C4I processes. Provide analytical reports and state findings or integrate conclusions into overall squadron generated composite reports, briefings, and target profile folders.
  • Provide analytic tradecraft to gathered intelligence in a consistent manner.
  • Develop and refine cyber threat intelligence collection and analysis processes.
  • Assist crews and analysts to determine most efficient means of execution (course of action) against malware, adversary TTPs, threat actors and the MITRE attack framework with respect to AFCERT weapons.
  • Write technical operational reports associated with systems that extensively involve telecommunications and telecommunications interfaces, IT, computer network defense (CND), computer networking, and network security. (CDRL A002)
  • Make analytical predictions about cyber actors and their future activities based on available data. Recognize threats by performing relevant research and data analysis using both internal and external tools and resources.
  • Produce detailed intelligence analysis reports on cyber threats with a potential to impact AF networks, systems and enclaves. (CDRL A008)
  • Present relevant findings to both technical and non‑technical audiences.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
What You Bring:
Requirements:
  • Active TS/SCI
  • Formal intelligence analysis training and government experience.
  • BA/BS or MA/MS
  • Formal Intelligence Analysis training and government experience preferred.
  • Previous experience working with hunting tools and technologies.
  • Understanding of Networking (including the OSI Model, TCP/IP, DNS, HTTP, SMTP).
  • Experience with open source Malware Analysis platforms (Assemblyline, Cuckoo, Malboxes).
  • Experience with one or more commercial Malware Analysis platforms (Joe Sandbox, VirusTotal, etc.) knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community
What We Offer:

STS Systems Support, LLC (SSS) offers a competitive benefits package to include paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

SSS is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638

Lackland Air Force Base, San Antonio, TX, USA,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Emulation & Analyst
Cyber Threat Emulation & Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 80,000 - 110,000
Paid holidays
Paid time off
Medical insurance
+1
Signature Writer – Intermediate – Cyber Security
Signature Writer – Intermediate – Cyber Security

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 180,000
Paid holidays
401(k) with company match
Tuition reimbursement
Incident Response Officer (Intermediate)
Incident Response Officer (Intermediate)

Ssd Anc • San Antonio (TX)

On-site
USD 110,000 - 150,000
Health insurance
Paid time off
401(k) with company match
+1
Cyber Data Engineer
Cyber Data Engineer

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 160,000
Tuition reimbursement
Medical and vision insurance
Paid holidays and PTO
Cyber Threat Intelligence Analyst: Emerging Threats
Cyber Threat Intelligence Analyst: Emerging Threats

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 85,000 - 110,000
Medical, dental and vision insurance
401(k) with company match
Paid holidays and time off
Content Developer (SIEM Cyber Security)
Content Developer (SIEM Cyber Security)

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 90,000 - 120,000
Paid holidays
Medical, dental, and vision insurance
401(k) with company match
Cyber Threat Intelligence Analyst - Emerging Threats
Cyber Threat Intelligence Analyst - Emerging Threats

Bristol Bay Native Corporation • San Antonio (TX)

On-site
USD 80,000 - 100,000
Paid holidays
401(k) with company match
Tuition reimbursement
Emerging Threats Analyst (TS/SCI with Polygraph)
Emerging Threats Analyst (TS/SCI with Polygraph)

Red Alpha • Columbia (MD)

On-site
USD 150,000 - 225,000
Health insurance
401(k) with up to 10% match
Paid time off (up to 25 days)
+2
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
Network Security Analyst 0056A
Network Security Analyst 0056A

Sistema Technologies Inc. • San Antonio (TX)

Hybrid
USD 90,000 - 140,000