> Markdown version of [/jobs/ext/3412457-security-data-engineer-senior](https://www.wearedevelopers.com/jobs/ext/3412457-security-data-engineer-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Data Engineer - Senior - **Company:** Modern Technology Solutions, Inc. - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $155,000.0 - $195,000.0 - **Contract:** Permanent contract - **Skills:** Secure Shell (SSH), Application Programming Interfaces (APIs), Business Analytics Applications, Data Analysis, Cloud Computing, Cyber Security, Computer Networks, Data Centers, Data Discovery, Data Normalization, Dynamic Host Configuration Protocol, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), JSON, Python (Programming Language), Network Security, Pcap, Simple Mail Transfer Protocols, NetFlow, Network Monitoring, Routing, Network Segmentation, Packet Analyzer, Network Protocols, Parsing, Queueing Systems, Security Information and Event Management, SQL Databases, Data Streaming, Syslog, TCP/IP, Wireshark, Virtual Local Area Networks, Extensible Markup Language (XML), Scripting, Transport Layer Security, Cloud Platform System, Data Ingestion, Mitre Att&ck, HybridCloud, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Data Lakes, Information Technology, Low Latency, Cybercrime, Purple Team (Cyber Security), Cyber Warfare, Data Pipelines - **Published:** September 28, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88482009/1 ## About the Role * Strong understanding of; network security monitoring and security telemetry. MITRE ATT&CK framework, adversary behaviors, TCP/IP, DNS, HTTP/HTTPS, TLS, SMTP, DHCP, SSH, SMB, and common network protocols. * Experience in; translating detection requirements into specific data and telemetry requirements. * Understanding of; packet capture, network flows, network metadata, and session-level telemetry. * Experience with technologies such as NetFlow/IPFIX, Zeek, Wireshark, IDS/IPS, firewalls, proxies, or network detection platforms, network segmentation, routing, VLANs, VPNs, cloud networking, and encrypted traffic. * Experience designing or maintaining security data ingestion pipelines. Understanding of APIs, syslog, message queues, streaming data, and event-based architectures. * Experience working with JSON, XML, CSV, CEF, LEEF, ECS, or other security-data formats. Strong understanding of data normalization, parsing, enrichment, transformation, and schema management. * Experience with at least one scripting language such as Python. * Ability to conduct data-source and detection-gap assessments. * Experience working with threat hunting or purple-team activities. Understanding of adversary emulation and controlled security testing. Desired: * Hands-on experience building security telemetry pipelines and supporting SIEM, data lake, or analytics platforms. * Experience writing or tuning detections using SQL, Sigma, YARA-L, Python, or similar. * Familiarity with MITRE ATT&CK, detection engineering, and Purple Team validation. * Ability to work with network, infrastructure, and cyber operations teams to enable and validate telemetry sources. * Strong written and verbal communication skills for technical analysis and stakeholder engagement. * Prior experience supporting federal, DoD, or USSF cyber environments is highly desirable., * Bachelor's degree in cybersecurity, computer science, security engineering, data science, network security, or a related field and 18 years of relevant professional experience; or Master's degree in one of the same fields and 10 years of relevant professional experience, * Must possess a Top Secret with SCI eligibility. SAR/SAP experience is highly desirable. ## Description Modern Technology Solutions, Inc. (MTSI) is searching for a Senior Security Data Engineer in support of United States Space Force (USSF) Space Systems Command (SSC) and Combat Forces Command (CFC) Defensive Cyber Operations. We are seeking a Security Data Engineer to own our security telemetry pipeline end-to-end. You will be responsible for ensuring that the organization collects, ingests, normalizes, and maintains the security telemetry required to support network traffic monitoring, threat hunting, custom detection engineering, and adversary detection. The candidate will ensure the organization has the telemetry necessary to detect the adversary behaviors necessary to identify, protect, and defend our mission and customers. The candidate will be responsible for developing the processes and procedures for identifying, onboarding, and optimizing network and application traffic data sources (e.g., NetFlow, PCAP, proxy logs, VPC flow logs, DNS, etc.) to feed centralized and deployed detection solutions. Additionally, you will partner with organizational personnel to write, tune, and maintain custom threat detections based on high-quality traffic ingestion. The engineer will determine what data is required to detect specific adversary behaviors, where that data originates, how it should be collected, and whether the resulting telemetry provides sufficient visibility to support reliable detections. The engineer is responsible for understanding the detection objective and working backward to ensure the organization has the appropriate data sources, telemetry fields, collection methods, retention, normalization, and data quality necessary to achieve that objective. Role and Responsibilities: The candidate will architect, build, and maintain data pipelines ingesting network traffic, VPC flow logs, firewall/proxy logs, DNS records etc. into the organization's centralized systems. The candidate will; ensure ingested data is structured, normalized (e.g., OCSF or CIM standard), and continuously parsed correctly for immediate querying and correlation. * Design, write, and deploy high-fidelity detection rules using SQL, Sigma, YARA-L, or Python targeting network-based attack techniques (e.g., C2 beaconing, data exfiltration, and lateral movement). * Continuously tune network detections to reduce false-positive rates while maintaining a high signal-to-noise ratio. * Identify telemetry required to support network monitoring, threat hunting, incident response, and custom detection engineering. * Map detection requirements to underlying data sources and identify visibility gaps across hybrid cloud and on-premises environments * Design and maintain pipelines that ingest security telemetry from network, endpoint, identity, cloud, application, OT, and security infrastructure. * Ensure telemetry is delivered reliably to SIEM, data lake, analytics, and detection platforms; troubleshoot ingestion, parsing, latency, and data-quality issues. * Evaluate whether packet, flow, session, DNS, proxy, authentication, endpoint, and application telemetry is sufficient for specific detection requirements. * Support custom detection development through data discovery, enrichment, normalization, and validation. * Identify opportunities to move detections from low-level indicators toward higher-level behavioral and tradecraft-based detection using the Detection Stack. * Work with network engineering teams to evaluate technologies such as network sensors, NetFlow/IPFIX, DNS telemetry, proxy telemetry, firewall logs, IDS/IPS, packet capture, Zeek/network metadata, and NDR platforms. * Establish telemetry health metrics, dashboards, and automated checks for missing, delayed, or malformed data. * Assess network visibility across data centers, cloud environments, remote networks, and segmented environments. * Optimize telemetry architectures and ingestion pipelines for performance, scalability, reliability, and cost ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [JSON and Beyond](https://www.wearedevelopers.com/videos/968-json-and-beyond) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)