Network Security Engineer 0057

Sistema Technologies Inc.

San Antonio (TX)

Hybrid

USD 90,000 - 140,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work

Job summary

Sistema Technologies Inc. is the employer historically associated with Federal/State security work, and the Texas Cyber Command hosts the Network Security Analyst position in San Antonio, TX.

You will engineer, tune, and operate SIEM and IDS/IPS platforms, integrate EDR telemetry, and convert threat intel into actionable detection logic. Responsibilities include pcap analysis, network traffic assessment, and developing orchestration playbooks within Cyware to support statewide monitoring and

Qualifications

  • 5+ years of SOC operations experience.
  • Hands-on experience with IDS/IPS platforms and tuning.
  • Advanced packet capture and network analysis skills.
  • Experience maintaining and tuning EDR platforms with SIEM integration.
  • Threat intel application expertise and detection logic development.

Responsibilities

  • Engineer, maintain, and tune SIEM platforms (Google SecOps, Gravwell), including correlation rules and dashboards.
  • Configure, tune, and optimize IDS/IPS technologies (Corelight, TippingPoint, Cisco Firepower).
  • Perform pcap analysis to validate alerts using NetWitness or Corelight.
  • Conduct network traffic analysis to detect anomalies and lateral movement.
  • Collaborate on network security architecture with distributed sensors and log pipelines.
  • Operationalize threat intel feeds within SOC platforms, converting indicators to detection logic.
  • Continuously tune detection content based on intelligence and minimize false positives.
  • Develop orchestration playbooks within Cyware to integrate SIEM, EDR, TI, and ticketing.
  • Support SOC operations with detection engineering and data normalization.
  • Maintain network security monitoring infrastructure and log pipelines.
  • Collaborate with Incident Responders for network-level evidence and validation.
  • Produce engineering reports, tuning docs, and platform health assessments.
  • Align detection logic with MITRE ATT&CK and emerging adversary behaviors.
  • Produce coverage maps using data from Firepower, TippingPoint, Corelight, NetWitness, MS Sentinel, and Google SecOps.

Skills

SOC operations
IDS/IPS tuning
EDR integration
Threat intel apps
Detection logic

Tools

Corelight
NetWitness
CRIBL
Google SecOps
Gravwell
TippingPoint
Cisco Firepower
Cyware
CrowdStrike Falcon
SentinelOne

Job description

San Antonio, TX
Network Security Analyst - Solicitation# 37100057
Texas Cyber Command (TXCC)

  • Engineer, maintain, and tune SIEM platforms (Google SecOps, Gravwell), including correlation rules, dashboards, enrichment logic, and detection content.
  • Configure, tune, and optimize IDS/IPS technologies (Corelight, Tipping Point, Cisco Firepower), including signature development and false-positive reduction.
  • Perform packet capture (pcap) analysis to validate alerts, identify malicious traffic, and support investigations using Netwitness or Corelight.
  • Conduct network traffic analysis to detect anomalies, lateral movement, and command‑and‑control activity.
  • Strong understanding of network security architecture, including distributed sensors (Corelight), packet capture systems (NetWitness), and log pipelines (CRIBL, Gravwell, Google SecOps).
  • Operationalize threat intelligence feeds within SOC platforms and customers, converting indicators into detection logic, correlation rules, and automated enrichment workflows.
  • Continuously tune detection content based on intelligence‑driven insights, improving alert fidelity and reducing false positives across statewide monitoring.
  • Develop and maintain orchestration playbooks within Cyware, integrating SIEM, EDR, threat intelligence, and ticketing systems to support statewide monitoring expansion and rapid incident handling.
  • Support SOC operations by providing detection engineering, log onboarding, and data normalization.
  • Develop and maintain network security monitoring infrastructure, including sensors, collectors, and log pipelines.
  • Collaborate with Incident Responders to provide network‑level evidence, context, and threat validation.
  • Produce engineering reports, tuning documentation, and platform health assessments.
  • Implement detection logic aligned with MITRE ATT&CK, threat intelligence, and emerging adversary behaviors.
  • Produce engineering documentation, tuning reports, platform health assessments, and detection coverage maps using data from Firepower, TippingPoint, Corelight, NetWitness, Microsoft Sentinel, and Google SecOps

Candidate must be a U.S. citizen, pass required background checks, complete required cybersecurity, privacy, and operational training before gaining system access, and comply with TXCC security and data-handling requirements. Occasional after-hours support may be required with TXCC approval. Work must be performed from within the United States unless TXCC grants prior written approval.
The working position is Hybrid - On Site and Telework.
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. Actual
Years
Experience Years
Experience
Needed Required/
Preferred Skills/Experience 5 Required SOC operations experience 5 Required Hands‑on experience with IDS/IPS platforms, specifically Cisco Firepower and TippingPoint, including signature tuning, false‑positive reduction, and threat‑driven detection improvements. 5 Required Advanced packet capture (pcap) and network analysis skills using Corelight, NetWitness, and CRIBL pipelines to identify anomalies, malicious traffic, and lateral movement. 5 Required Experience maintaining and tuning EDR platforms, including CrowdStrike Falcon and SentinelOne, and integrating EDR telemetry into SIEM and orchestration workflows. 5 Required Threat intelligence application expertise 5 Required Develop detection logic aligned with adversary TTPs 6 Preferred Experience operationalizing threat intelligence by converting indicators and TTPs from Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant into SIEM rules, IPS signatures, and automated enrichment logic. 5 Preferred Experience operationalizing threat intelligence by converting indicators and TTPs from Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant into SIEM rules, IPS signatures, and automated enrichment logic. 5 Preferred Perform packet-level analysis to validate alerts and identify malicious activity 5 Preferred Serves as an escalation SOC analysts to support other SOC analyst and incident responders with enriched network‑level intelligence 5 Preferred Proficiency with Google SecOps and Cyware (SOAR) orchestration, including building automated workflows that integrate SIEM, IDS/IPS, EDR (CrowdStrike, SentinelOne), threat intelligence, and Jira ticketing for SOC automation 4 Preferred Security Certifications Preferred (CISSP, CEH, GISF, GSEC, CySA+, Sec+)
I need Three References

Reference Name ( Required ): Title (Optional) Company Name ( Required ): Phone Number ( Required include area code): E-mail address (Optional): Professional Relationship (Optional):
Peer Co-Worker Supervisor
Customer End-User Subordinate
Reference Name ( Required ): Title (Optional) Company Name ( Required): Phone Number ( Required include area code): E-mail address (Optional): Professional Relationship (Optional):
Peer Co-Worker Supervisor
Customer End-User Subordinate
Reference Name ( Required ): Title (Optional) Company Name ( Required ): Phone Number ( Required include area code): E-mail address (Optional): Professional Relationship (Optional):
Peer Co-Worker Supervisor
Customer End-User Subordinate
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Network Security Analyst 0056A
Network Security Analyst 0056A

Sistema Technologies Inc. • San Antonio (TX)

Hybrid
USD 90,000 - 140,000
DevOps Engineer 0049A
DevOps Engineer 0049A

Sistema Technologies Inc. • San Antonio (TX)

Hybrid
USD 100,000 - 140,000
Senior Cybersecurity Ops Analyst
Senior Cybersecurity Ops Analyst

Jobtailor • Santa Ana (CA)

On-site
USD 75,000 - 120,000
Senior Detection & Response Analyst
Senior Detection & Response Analyst

Remote Jobs • United States

On-site
USD 110,000 - 190,000
Engineer II – Cyber Incident Response
Engineer II – Cyber Incident Response

Jobtailor • Pennsylvania

On-site
USD 70,000 - 100,000
SOC Analyst 2
SOC Analyst 2

Mbi Llc • Harrisburg

On-site
USD 60,000 - 90,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Associate Director, Threat Management Center
Associate Director, Threat Management Center

Jobtailor • Town of Florida (NY)

On-site
USD 150,000 - 190,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Cyber Hunt Analyst
Cyber Hunt Analyst

Synergy ECP • Columbia (MD)

On-site
USD 90,000 - 130,000