> Markdown version of [/jobs/ext/1316126-cyber-threat-emulation-analyst](https://www.wearedevelopers.com/jobs/ext/1316126-cyber-threat-emulation-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Threat Emulation & Analyst - **Company:** STS SYSTEMS SUPPORT, LLC - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Bash Shell, Cyber Security, Linux, Emulators, Intrusion Detection and Prevention, Intrusion Detection Systems, Windows PowerShell, Security Information and Event Management, Scripting, Mitre Att&ck, Cyber Threat Analysis, Free and Open-Source Software, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/dfb17015-2abf-46e8-9da5-74d072682673 ## About the Role * DoDD 8570.01-M/8140.01 I AT Level III CND * Active TS/SCI * Five years' of penetration testing experience. BA/BS or MA/MS * Five (5) years of penetration testing experience. * Demonstrated advanced knowledge of cyber security operations with master of two or more of the following: attack surface management, Security Operations Center (SOC) operations, Intrusion Detection/Intrusion Prevention Systems (IDS/IPS), Security Information and Event Management (SIEM) use, threats (including Advanced Persistent Threat (APT), insider), vulnerabilities, and exploits; incident response, investigations and remediation. * Experience with PowerShell, BASH or Python scripting/programming language. * Must have a strong understanding of Linux Operating System. * Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects) ## Description STS Systems Support, LLC (SSS) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Cyber Threat Emulation & Analyst at Lackland AFB in San Antonio, TX. What You'll Do: * Conduct both automated and manual enterprise vulnerability assessments, including conducting regular patch & configuration vulnerability assessments as directed by operational flight leads. * Conduct Cyber Threat Emulation operations, and coordinate with security teams to strengthen the overall security posture of the AFNet and AFIN various tools and capabilities. * Test for real-time security vulnerabilities, conduct assessments, and assess vulnerability risk and impact. * Continuously develop and maintain safe and valid procedures to actively test Enterprise defensive measures. (CDRL A007 & A008) * Develop mitigations, policies, and procedures to coordinate with internal teams. (CDRL A007) * Work with incident response team to develop response policies and procedures. * Generate threat intelligence indicators during the course of Cyber Threat Emulation operations and provide reports back to operators. (CDRL A008) * Coordinate with internal and external intelligence teams in order to replicate threat actor (TA) Techniques, Tactics, and Procedures (TTPs). * Research & Evaluate threats and vulnerabilities to assist in the prioritization of remediation actions. * Utilize knowledge and understanding of the Cyber Threat Framework (ODNI) and production of Threat Emulation findings. * Utilize the MITRE ATT&CK framework to perform cyber security operations testing, and develop improvements based upon adversary behavior. * Formulate, lead and persuade individuals, large teams and communities on ideas, concepts, and opportunities. * Leverage research, frameworks, and best practices on the latest exploits and security trends and currency on industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002) * Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate. * Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009). * Provide information to operational leaderships tasking as required as it relates to CTE actions ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)