STS Systems Defense logo
STS Systems DefensePosted 1 month ago

Cyber Data Engineer

$77,200–$96,500 year

On-siteSan Antonio, Texas, United States or Lackland Air Force Base, Texas, United States

Full TimeStartup

Job Summary

Automate system patching and configuration scripts to remediate identified vulnerabilities across Windows and Unix/Linux platforms. Develop and maintain Splunk, ELK, and other search/analytics tools to alert on malicious activity and fulfill compliance requirements. Create, install, and test vulnerability fixes while ensuring critical data feeds remain active. Conduct cybersecurity audits and perform systems security engineering to verify hardening and patching activities against STIGs and SRGs. Generate regular reports on patch management status, vulnerability assessments, and impact analysis for failed deployments. Provide operational reports to support leadership tasking and maintain currency on industry trends for developing tactics and procedures.

Required Qualifications

  • U.S. Citizen
  • Active TS/SCI
  • Graduates degree in Software Engineer
  • BA/BS or MA/MS
  • More than 3 years of relevant work experience
  • Proficient w/ Splunk Processing Language (SPL), ELK Lucene Query Syntax or other search/analytics tool
  • Proficient with programming/scripting fundamentals – including regex, C++, Python, RHEL, Unix Scripting, and Windows PowerShell
  • Linux+/Red Hat; RHEL 7
  • More than three (3) years of relevant work experience, including experience in responding to security problems in target‐rich environments, looking at security alerts, frontline analysis, and response
  • Understanding of SIEM "Search" Language & Lucene Query Syntax
  • Understanding of SIEM Dashboard, Reports, Lookup Tables, and Summary Indexes
  • Knowledge of knowing how to customize Dashboards via the XML source
  • Experience with SIEM Apps and ELK
  • Experience with Python Scripting
  • Programming experience in Python, C/C++, Java, or Go
  • Demonstrated expertise with malware analysis, including investigations of botnet and root‐kit behavior
  • Familiarity with information security concepts (OWASP Top 10, CVEs, IoCs, TTPs, Cryptography)
  • Network Security Devices (IDS/IPS, NGFW, WAF, NGAV)
  • OSSEC, Snort, Suricata Experience
  • Experience with at least one SIEM i.e Alienvault, Logrhythm, Splunk, Qradar , ELK and Firewalls such as Fortinet, Sonicwall, and Palo Alto
  • Scanning technologies, Log collection and analysis tools (SIEM)
  • Experience with Scripting/Programming Languages (BASH, Python, Java, etc)
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce