Signature Writer – Intermediate – Cyber Security

Ssd Anc

San Antonio (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Paid holidays
401(k) with company match
Tuition reimbursement

Job summary

STS Systems Defense, LLC seeks a Signature Writer – Intermediate – Cyber Security to support Lackland AFB in San Antonio, TX. The role focuses on SIEM analysis, detections, dashboards, and automation to protect government networks.

You will work with ArcSight, Splunk, and ELK, develop use cases, and provide training to government personnel. A TS/SCI clearance and DoD cyber experience are essential for this on-site position at Lackland AFB.

Qualifications

  • Active TS/SCI clearance required.
  • GCFA or GMLE or GIAC equivalent certification is required.
  • 5+ years SIEM experience (ArcSight, Splunk, ELK).
  • 3+ years with network traffic analysis; BA/BS or MA/MS.
  • 5+ years with DoD-grade IDS/IPS and MITRE ATT&CK framework usage.
  • 1+ year with SOAR platforms; Python and PowerShell proficiency.

Responsibilities

  • Analyze DCO events and apply SIEM best practices.
  • Create detections by analyzing log data across the enterprise.
  • Develop dashboards and visualizations to identify adversarial activity.
  • Tune SIEM rules to reduce false positives and improve detections.
  • Automate SIEM tasks with scripting languages.
  • Provide training and knowledge transfer to government personnel.

Skills

Python
PowerShell
SOAR platforms
MITRE ATT&CK
Network traffic analysis
SIEM concepts

Education

BA/BS or MA/MS

Tools

ArcSight
Splunk
ELK
Phantom
Demisto

Job description

Signature Writer – Intermediate – Cyber Security

San Antonio, TX, USA •

Lackland Air Force Base, San Antonio, TX, USA

Job Description

Posted Wednesday, July 1, 2026 at 5:00 AM

STS Systems Defense, LLC (SSD) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Content Developer (SIEM Cyber Security) at Lackland AFB in San Antonio, TX.

What You'll Do:

  • Analyze DCO events.
  • Apply current industry SIEM best‐practices.
  • Use security alerts correlated with log enrichment data to enhance the operator’s ability to identify real attacks.
  • Establish security control effectiveness and monitor for unauthorized outbound connections
  • Create detections by analyzing log data across the enterprise. (CDRL A007)
  • Develop dashboards and visualizations to identify adversarial activity. (CDRL A007)
  • Use log data to establish and implement virtual tripwires for early detection.
  • Analyze and ingest security logs into the SIEM in order to optimize for performance of the SIEM.
  • Conduct designing, implementing, and testing of various SIEM solutions. (CDRL A007)
  • Create and support the creation of SIEM Use Cases and understand what alerts and log enrichment is necessary to meet the required acceptable false positive rate. (CDRL A008)
  • Create, test, and validate filters and rules. (CDRL A007)
  • Build and implement event correlation rules, logic, and content in the SIEM. (CDRL A007)
  • Tune SIEM event correlation rules and logic to filter out security events associated with known and well established network behavior, known false positives and/or known errors.
  • Analyze malware threats to develop behavior based detections that alert and/or prevent malicious activity.
  • Automate tasks in the SIEM using a common programming or scripting language.
  • Create scheduled and ad'hoc reporting with SEIM tools. (CDRL A007 and A008)
  • Create and maintain SIEM documentation. (CDRL A008)
  • Develop and execute a process to review and maintain SIEM resources such as rules, filters, lists, trends and reports.
  • Utilize SIEM to develop metrics collection, analysis, and create reports upon request.
  • Provide training to government personnel as requested.
  • Provide knowledge transfer of tools, processes and procedures to government personnel as requested.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).
  • Support operational leaderships tasking as it relates to Content Development functions and responsibilities

What You Bring:

Requirements:

  • Active TS/SCI
  • GCFA or GMLE (GIAC Machine Learning Engineer or GIAC Certified Forensic Analyst)
  • More than 5 years of SIEM technology such as ArcSight, Splunk, and/or ELK.
  • More than 3 years with network traffic analysis, ports, and protocols. BA/BS or MA/MS
  • More than five (5) years of SIEM technology such as Arcsight, Splunk and/or ELK. Including, but not limited to, log handling, reports, filters, rule creation.
  • Extensive knowledge with IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (i.e., Air Force, Navy, Army, DC3, DISA).
  • More than three (3) years of experience with Network Traffic Analysis; ports and protocols. SANS GCDA or equivalent certification(s).
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)
  • Additionally, more than one (1) year of experience with Security, Orchestration, Automation, and Response (SOAR) platforms such as Phantom and/or Demisto. Proficient in Python and PowerShell.

What We Offer:

STS Systems Defense, LLC offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

SSD is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638.

Lackland Air Force Base, San Antonio, TX, USA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Content Developer (SIEM Cyber Security)
Content Developer (SIEM Cyber Security)

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 90,000 - 120,000
Paid holidays
Medical, dental, and vision insurance
401(k) with company match
Cyber Data Engineer
Cyber Data Engineer

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 160,000
Tuition reimbursement
Medical and vision insurance
Paid holidays and PTO
Emerging Threats Analyst
Emerging Threats Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 85,000 - 110,000
Medical, dental and vision insurance
401(k) with company match
Paid holidays and time off
Incident Response Officer (Intermediate)
Incident Response Officer (Intermediate)

Ssd Anc • San Antonio (TX)

On-site
USD 110,000 - 150,000
Health insurance
Paid time off
401(k) with company match
+1
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
SIEM Content Developer – Intermediate Cyber Security
SIEM Content Developer – Intermediate Cyber Security

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 180,000
Paid holidays
401(k) with company match
Tuition reimbursement
Cyber Threat Emulation & Analyst
Cyber Threat Emulation & Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 80,000 - 110,000
Paid holidays
Paid time off
Medical insurance
+1
Advanced Cyber Security Analytics Engineer New St. Louis, MO
Advanced Cyber Security Analytics Engineer New St. Louis, MO

D2 Consulting • St. Louis (MO), Northern (KY)

Hybrid
USD 90,000 - 100,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
CYBERSECURITY ENGINEER
CYBERSECURITY ENGINEER

Y-Tech, LLC. • Fort Belvoir (VA)

On-site
USD 90,000 - 130,000
Linux SIEM System Engineer New Springfield, VA
Linux SIEM System Engineer New Springfield, VA

D2 Consulting • Springfield (VA), Northern (KY)

Hybrid
USD 135,000 - 145,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3