Cyber Data Engineer

STS Systems Defense, LLC
San Antonio, TX, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Microsoft Windows Bash Shell Botnet Unix C++ (Programming Language) Apache Lucene Cyber Security Computer Programming Databases Software Debugging Linux
+26 more
Networking Hardware Intrusion Detection Systems Python (Programming Language) Network Security Lookup Table Open Web Application Security Windows PowerShell Red Hat Enterprise Linux Regular Expressions Security Information and Event Management Extensible Markup Language (XML) Snort (Software) Scripting Mitre Att&ck QRadar Sonicwall Malware Firewalls (Computer Science) Palo Alto Networks Data Analytics Patch Management Free and Open-Source Software Fortinet Splunk Vulnerability Analysis Programming Languages

Job description

STS Systems Defense, LLC (SSD) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. SSS is seeking a Cyber Data Engineer to support our ongoing mission at Lackland AFB in San Antonio, TX.

What You’ll Do:

  • Write and develop scripts to automate the system installation of required patches and configurations to remediated identified system vulnerabilities.
  • Perform coding and development as required to augment default SIEM functionality and facilitate the intercommunications of various security controls. (CDRL A007)
  • Develops basic new cybersecurity capabilities. (CDRL A007)
  • Develop new and maintain existing Splunk, ELK or other search/analytics tool’s knowledge objects (Saved searches, reports, dashboards, data models, event types, field aliases, field extractions, macros, lookups, tags) to alert on potentially malicious activity or fulfill compliance/policy requirements. (CDRL A007)
  • Ensure critical data feeds and hosts are sending data.
  • Develop, debug and maintain scripting languages.
  • Create, install and test vulnerability fixes to Windows and Unix/Linux platforms.
  • Assist/lead in conducting cybersecurity audits to ensure appropriate implementation and compliance of the security posture.
  • Perform systems security engineering and test efforts associated with implementing security controls on networking devices, databases, operating systems, hardware, and software components.
  • Develop vulnerability reports and investigation impact, resolution and verification of security vulnerabilities and patches; as well as, performing deep-dive and impact analysis into failed patch deployments. (CDRL A008)
  • Develop and provide regular reports on patch management program and overall status of patch compliance. (CDRL A008)
  • Perform and provide vulnerability assessment results and recommendations to the ESM Lead, and DO as necessary.
  • Assess known systems vulnerabilities and verify system hardening and patching activities to ensure compliance with the most current applicable Security Technical Implementation Guides (STIGs)/Security Requirements Guides (SRGs) and related checklists with no more than a 5% error rate.
  • Document, implement and prioritize patching requirements across the AFIN/AFNet enterprise. (CDRL A008)
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).
  • Support operational leaderships tasking as it relates to Systems Security Engineer functions and responsibilities

Requirements

  • Graduates degree in Software Engineer
  • More than 3 years of relevant work experience. BA/BS or MA/MS
  • Proficient w/ Splunk Processing Language (SPL), ELK Lucene Query Syntax or other search/analytics tool.
  • Proficient with programming/scripting fundamentals - including regex, C++, Python, RHEL, Unix Scripting, and Windows PowerShell is required.
  • Linux+/Red Hat; RHEL 7.
  • More than three (3) years of relevant work experience, including experience in responding to security problems in target-rich environments, looking at security alerts, frontline analysis, and response.
  • Understanding of SIEM “Search” Language & Lucene Query Syntax. Understanding of SIEM Dashboard, Reports, Lookup Tables, and Summary Indexes.
  • Knowledge of knowing how to customize Dashboards via the XML source.
  • Experience with SIEM Apps and ELK.
  • Experience with Python Scripting. Programming experience in Python, C/C++, Java, or Go.
  • Demonstrated expertise with malware analysis, including investigations of botnet and root-kit behavior.
  • Familiarity with information security concepts (OWASP Top 10, CVEs, IoCs, TTPs, Cryptography). Network Security Devices (IDS/IPS, NGFW, WAF, NGAV). OSSEC, Snort, Suricata Experience.
  • Experience with at least one SIEM i.e Alienvault, Logrhythm, Splunk, Qradar , ELK and Firewalls such as Fortinet, Sonicwall, and Palo Alto.
  • Scanning technologies, Log collection and analysis tools (SIEM).
  • Experience with Scripting/Programming Languages (BASH, Python, Java, etc).
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects).

Benefits & conditions

SSD offers a competitive benefits package to include: paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

2:39 min

Experiencing core Linux capabilities for DevOps administration

Michael Cade · LIVE

2:04 min

Defining timestamps and the international standard format

Denny Biasiolli Denny Biasiolli · Europe 2026 Virtual

Videos

See all

Related articles

See all