Network Security Analyst 0056A

Sistema Technologies
  • San Antonio, Texas
    30+ days ago

    Job Description

    San Antonio, TX
    Network Security Analyst - Solicitation# 37100056A
    Texas Cyber Command (TXCC)
     
    • Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery.
    • Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis.
    • Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies.
    • Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK.
    • Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools.
    • Produce incident reports, timelines, and executive summaries for statewide stakeholders.
    • Support multi-agency response operations, including SLTT partners and critical infrastructure entities.
    • Provide recommendations for detection improvements, hardening, and long-term mitigation.
    • Participate in post-incident reviews, lessons learned, and playbook updates.
    • Maintain readiness for 24x7 response through on-call rotation or surge support.
    Candidate must be a U.S. citizen, pass required background checks, complete required cybersecurity, privacy, and operational training before gaining system access, and comply with TXCC security and data-handling requirements. Occasional after-hours support may be required with TXCC approval. Work must be performed from within the United States unless TXCC grants prior written approval.
    The working position is Hybrid - On Site and Telework.
     
    Minimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
    Actual
    Years
    Experience
    Years
    Experience
    Needed
    Required/
    Preferred
    Skills/Experience
     5Advanced host‑based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity.
     5Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines.
     5Experience producing high‑quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows.
     4Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet‑level and log‑level data from but not limited to Corelight, NetWitness, and CRIBL pipelines.
     3Incident Commander experience
     1Experience supporting SLTT or critical infrastructure environments, including multi‑tenant IR operations and cross‑agency coordination.
     5PreferredProficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK.
     5PreferredHands‑on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems.
     4PreferredSecurity Certifications Preferred (CISSP, CIH, Sec+)



    I need Three References

     
    Reference Name (): 
    Title (Optional) 
    Company Name (): 
    Phone Number (include area code): 
    E-mail address (Optional): 
    Professional Relationship (Optional): 
         
    Peer                                                                      Co-Worker                                                                  Supervisor
       

      Customer                                                             End-User                                                                     Subordinate
     
    Reference Name (): 
    Title (Optional) 
    Company Name (): 
    Phone Number (include area code): 
    E-mail address (Optional): 
    Professional Relationship (Optional): 
         
    Peer                                                                      Co-Worker                                                                  Supervisor
       

      Customer                                                             End-User                                                                     Subordinate
     
    Reference Name (): 
    Title (Optional) 
    Company Name (): 
    Phone Number (include area code): 
    E-mail address (Optional): 
    Professional Relationship (Optional): 
         
    Peer                                                                      Co-Worker                                                                  Supervisor
       

      Customer                                                             End-User                                                                     Subordinate

     

    Numbers & Facts

    LocationSan Antonio, Texas

    Skills

    • Analysis Skillsunmatched
    • Background Investigationunmatched
    • Case Managementunmatched
    • Documentationunmatched
    • File Systemsunmatched
    • Forensic Scienceunmatched
    • Huntingunmatched
    • IR (Infrared)unmatched
    • Incident Managementunmatched
    • Incident Responseunmatched
    • Internet Securityunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Leadershipunmatched
    • Linux Operating Systemunmatched
    • Malware Analysisunmatched
    • Memory Hardwareunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Monitoringunmatched
    • Network Performance/Analysisunmatched
    • Network Securityunmatched
    • On Callunmatched
    • Reporting Skillsunmatched
    • Security Analysisunmatched
    • Security Complianceunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Telemetryunmatched
    • United States Citizenunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder