Search jobs > San Antonio, TX > Cyber security

Signature Writer - Intermediate - Cyber Security

Bristol Bay Shared Services
San Antonio, TX
Full-time

STS Systems Support, LLC (SSS) is seeking a Signature Writer - Intermediate - Cyber Security

Requirements :

  • DoDD 8570.01-M / 8140.01 I AT Level III CND
  • Active TS / SCI
  • More than 3 years' experience implementing signatures on HIPS devices.
  • 3+ years' experience using Regular Expressions, YARA, and Snort-equivalent to create custom IPS / IDS signatures. BA / BS or MA / MS
  • More than three (3) years of experience implementing signatures on Host based Intrusion Protection System (HIPS) devices.
  • Proficient in PowerShell with more than one (1) year of experience.
  • Extensive knowledge of Windows internals.
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects).
  • More than three years of experience using Regular Expressions, YARA, and Snortequivalent to create custom IPS / IDS signatures

Desired :

  • More than five (5) years of experience implementing behavior-based (heuristic and anomaly-based) signatures on IDS / IPS / Host based Intrusion Protection System (HIPS) devices on AF approved devices as well as DISA's Joint Regional Security Stacks (JRSS).
  • Proficient in Python and PowerShell. SANS GCFA or equivalent certification.

Duties :

  • Analyze, interpret, and utilize Regular Expressions, YARA, and Snort-like capabilities in the creation of custom signature sets.
  • Develop and document IPS / IDS SOPs. (CDRL A008)
  • Investigate intrusion events, host files, network files, and memory, to dissect and extrapolate information necessary for the development of custom signatures.
  • Analyze deployed signatures to reduce false positive rate and perform signature maintenance.
  • Create, modify, and manage, Security Orchestration and Automation workflows for operational use and execution.
  • Automate tasks using a common programming or scripting language.
  • Utilize Linux systems, UNIX / Linux shell scripting (bash), Python, PowerShell.
  • Develop, Test, Deploy, and Manage signatures, rules and filters for capabilities such as; IDS, IPS, firewall, web application firewall, proxy and SIEM systems. (CDRL A007)
  • Migrate, tune, and document existing and future AF signatures / detections to new tools and systems as they become available. (CDRL A007)
  • Provide support to external units and work centers as approved by AFCERT leadership. (CDRL A007)
  • Automate processes and procedures using scripts and SQL / database administration (CDRL A007)
  • Provide training and knowledge transfer to government personnel as requested.
  • Provide OJT to other contractor employees, military, and / or civilian personnel, and ensure continuity folders / working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Maintain currency on latest industry trends and provide operational reports / assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Create, document, and report metrics for analysis to improve weapon system processes and mission execution. (CDRL A009).
  • Locations : Lackland AFB, TX, Offut AFB, NE, and Maxwell AFB, AL
  • 9 days ago
Related jobs
Bristol Bay Native
San Antonio, Texas

STS Systems Support, LLC (SSS) is seeking a Signature WriterIntermediateCyber Security. Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (. More than five (5) years of experience implementing behavior‐based (heuristic and anomaly‐based) signatures ...

OSAAVA Services
San Antonio, Texas

OSAAVA Services is seeking a IS and Cyber Security Professional – Intermediate to join our Air Force / Space team at Langley /Peterson/ Lackland AFB. Cyber Security company, specializing in specific cyber defense activities and IT services. Cyber Security company, specializing in specific cybe...

Promoted
Gainwell Technologies LLC
TX, US
Remote

Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities.Working at Gainwell carries its rewards.You’ll have an incredible opportunity to grow your career in a company that values work fl...

Promoted
Guidehouse
San Antonio, Texas

Financial Crimes Compliance Analyst. Opportunities available for Analysts and Senior Analysts. Guidehouse is seeking experienced personnel to support oversight of the quality of service delivery for projects in which Guidehouse conducts financial crime and regulatory compliance related reviews and i...

Promoted
CHRISTUS Health
San Antonio, Texas

The Armed Security Officer is responsible for responding to all emergency codes, internal/external disaster events as needed and/or requested, conducting preliminary investigations of reported incidents, and performing other security related tasks as directed by a security supervisor/and or Manager....

Promoted
Outcome Logix ( A Tech 50 Finalist company 2022, by Pittsburgh Technology Council )
San Antonio, Texas
Remote

Identify security risks, analyze complex security issues, and perform remediation efforts. Create and own security standards, provide security requirements, and make informed decisions. The ideal candidate will possess strong security and technology knowledge, with an emphasis on risk management in ...

Promoted
State of Maine
San Antonio, Texas
Remote

Five years of information security experience, with a focus on Endpoint Security, Incident Response, and Security Engineering within an enterprise environment. Security Operation Center Analyst (Remote Role). The Information Security Office (ISO), Security Operations Center (SOC) is at the forefront...

Promoted
JAB Recruitment
TX, United States

A JAB client is seeking a Business Data Analyst in Houston, TX location. Experience with different methods for dealing with large, multi-dimensional data sets, including relational databases, SQL, and ETL. Understand system relationships for the Aftermarket/Manufacturing and related processes, utili...

Promoted
Security Service Federal Credit Union
TX, United States

All employees should demonstrate our SSFCU core values -- Caring, Innovative, Honest, Fair and Dedicated -- while providing enthusiastic, professional, and courteous service to SSFCU members and employees.Responsible for the support and operations of data protection, availability, backup and recover...

Promoted
KPMG
San Antonio, Texas

KPMG is currently seeking a Cyber Operations, Cyber Threat Analyst to join our Enterprise Security Services organization. Minimum five years of recent experience in cyber threat intelligence and/or cyber threat hunting; experience in security monitoring, security operations, and incident response a...