Network Security Analyst 0056A

Sistema Technologies Inc.

San Antonio (TX)

Hybrid

USD 90,000 - 140,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sistema Technologies Inc. in San Antonio, TX seeks a Network Security Analyst to lead advanced incident response across Windows and Linux. The role includes host-based forensics, incident command during events, and collaboration with statewide agencies.

You will map adversary activity to MITRE ATT&CK and produce timelines and executive summaries. Responsibilities cover alert validation, cross-agency coordination, and post-incident playbook updates, with a readiness for 24x7 on-call response.

Qualifications

  • 5+ years of advanced host-based forensics across Windows and Linux using telemetry tools.
  • Ability to correlate host, network, and intelligence data to build incident timelines.
  • Experience producing high-quality incident reports and executive summaries.
  • Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting.
  • Incident Commander experience in IR operations.
  • Experience supporting SLTT or critical infrastructure environments.

Responsibilities

  • Perform advanced incident response across Windows and Linux environments.
  • Conduct host-based forensics including log analysis, memory capture, and malware analysis.
  • Serve as Incident Commander during cybersecurity events with coordination and communication.
  • Analyze TTPs and map findings to MITRE ATT&CK.
  • Review and validate alerts from SIEM/EDR/IDS/IPS and network monitoring tools.
  • Produce incident reports, timelines, and executive summaries for stakeholders.
  • Support multi-agency response operations and cross-agency coordination.
  • Provide recommendations for detection improvements and hardening.
  • Participate in post-incident reviews and playbook updates.
  • Maintain readiness for 24x7 response via on-call rotation.

Skills

Incident response
Host-based forensics
Incident Commander
Threat hunting
Executive reporting
Security monitoring
Cross-agency coordination
TIMELINE construction

Tools

CrowdStrike
SentinelOne
Microsoft Sentinel
Corelight
NetWitness
Gravwell
CRIBL
Google SecOps

Job description

San Antonio, TX
Network Security Analyst - Solicitation# 37100056A
Texas Cyber Command (TXCC)

  • Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery.
  • Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis.
  • Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies.
  • Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK.
  • Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools.
  • Produce incident reports, timelines, and executive summaries for statewide stakeholders.
  • Support multi-agency response operations, including SLTT partners and critical infrastructure entities.
  • Provide recommendations for detection improvements, hardening, and long-term mitigation.
  • Participate in post-incident reviews, lessons learned, and playbook updates.
  • Maintain readiness for 24x7 response through on-call rotation or surge support.

Candidate must be a U.S. citizen, pass required background checks, complete required cybersecurity, privacy, and operational training before gaining system access, and comply with TXCC security and data-handling requirements. Occasional after-hours support may be required with TXCC approval. Work must be performed from within the United States unless TXCC grants prior written approval.

The working position is Hybrid - On Site and Telework.

Minimum Requirements
  • 5 Required Advanced host‑based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity.
  • 5 Required Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines.
  • 5 Required Experience producing high‑quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows.
  • 4 Required Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet‑level and log‑level data from but not limited to Corelight, NetWitness, and CRIBL pipelines.
  • 3 Required Incident Commander experience
  • 1 Required Experience supporting SLTT or critical infrastructure environments, including multi‑tenant IR operations and cross‑agency coordination.
  • 5 Preferred Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK.
  • 5 Preferred Hands‑on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems.
  • 4 Preferred Security Certifications Preferred (CISSP, CIH, Sec+)
I need Three References

Reference Name ( Required ): Title (Optional) Company Name ( Required ): Phone Number ( Required include area code): E-mail address (Optional): Professional Relationship (Optional):

Peer Co-Worker Supervisor

Customer End-User Subordinate

Reference Name ( Required ): Title (Optional) Company Name ( Required ): Phone Number ( Required include area code): E-mail address (Optional): Professional Relationship (Optional):

Peer Co-Worker Supervisor

Customer End-User Subordinate

Reference Name ( Required ): Title (Optional) Company Name ( Required ): Phone Number ( Required include area code): E-mail address (Optional): Professional Relationship (Optional):

Peer Co-Worker Supervisor

Customer End-User Subordinate

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Engineer 0057
Network Security Engineer 0057

Sistema Technologies Inc. • San Antonio (TX)

Hybrid
USD 90,000 - 140,000
Hybrid work
Network Security Analyst
Network Security Analyst

TechTalenthunt • Austin (TX)

On-site
USD 120,000 - 160,000
Cyber Incident Response Analyst at 3B Staffing LLC Austin, TX
Cyber Incident Response Analyst at 3B Staffing LLC Austin, TX

Fairweather, LLC • Austin (TX)

On-site
USD 110,000 - 150,000
DevOps Engineer 0049A
DevOps Engineer 0049A

Sistema Technologies Inc. • San Antonio (TX)

Hybrid
USD 100,000 - 140,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Cyber Threat Analyst II
Cyber Threat Analyst II

NewGen Technologies • Arlington (VA)

On-site
USD 90,000 - 120,000
Network Based Systems Analyst IV
Network Based Systems Analyst IV

Solutions³ LLC • Arlington (VA)

On-site
USD 140,000 - 180,000
Network Based Systems Analyst IV
Network Based Systems Analyst IV

Solutions³ LLC • Virginia (MN)

On-site
USD 110,000 - 170,000
Emerging Threats Analyst
Emerging Threats Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 85,000 - 110,000
Medical, dental and vision insurance
401(k) with company match
Paid holidays and time off
Network Forensics Cybersecurity Analyst
Network Forensics Cybersecurity Analyst

NewGen Technologies • Arlington (VA)

On-site
USD 120,000 - 160,000