
Network Security Analyst 0056A
Sistema TechnologiesSan Antonio, Texas
Automate your job search with Sonara.
Submit 10x as many applications with less effort than one manual application.1
Reclaim your time by letting our AI handle the grunt work of job searching.
We continuously scan millions of openings to find your top matches.

Overview
Schedule
Alternate-schedule
Full-time
Career level
Senior-level
Remote
Hybrid remote
Job Description
San Antonio, TXNetwork Security Analyst - Solicitation# 37100056ATexas Cyber Command (TXCC)
I need Three References
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Peer Co-Worker Supervisor * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Customer End-User Subordinate
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Peer Co-Worker Supervisor * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Customer End-User Subordinate
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Peer Co-Worker Supervisor * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * Customer End-User Subordinate
- Perform advanced incident response across Windows and Linux environments, including triage, containment, eradication, and recovery.
- Conduct host-based forensics, including log analysis, memory capture, file system review, and malware behavior analysis.
- Serve as Incident Commander during cybersecurity events, coordinating actions, documenting decisions, and communicating with leadership and affected agencies.
- Analyze adversary Tactics, Techniques, and Procedures (TTPs) and map findings to MITRE ATT&CK.
- Review and validate alerts from SIEM, IDS/IPS, EDR, and network monitoring tools.
- Produce incident reports, timelines, and executive summaries for statewide stakeholders.
- Support multi-agency response operations, including SLTT partners and critical infrastructure entities.
- Provide recommendations for detection improvements, hardening, and long-term mitigation.
- Participate in post-incident reviews, lessons learned, and playbook updates.
- Maintain readiness for 24x7 response through on-call rotation or surge support.
| Minimum Requirements: Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity. | |||
| Actual Years Experience | Years Experience Needed | Required/ Preferred | Skills/Experience |
| 5 | Advanced host‑based forensics across Windows and Linux, including memory, disk, and malware analysis, using telemetry from NetWitness, Gravwell, Google SecOps, and Corelight to validate findings and reconstruct attacker activity. | ||
| 5 | Ability to correlate host, network, and intelligence data from CrowdStrike, SentinelOne, Microsoft Sentinel, Corelight, and NetWitness to build complete incident timelines. | ||
| 5 | Experience producing high‑quality incident reports and executive summaries using evidence collected from Gravwell, NetWitness, Corelight, and case management workflows. | ||
| 4 | Strong understanding of adversary TTPs, intrusion kill chains, and threat hunting methodologies using packet‑level and log‑level data from but not limited to Corelight, NetWitness, and CRIBL pipelines. | ||
| 3 | Incident Commander experience | ||
| 1 | Experience supporting SLTT or critical infrastructure environments, including multi‑tenant IR operations and cross‑agency coordination. | ||
| 5 | Preferred | Proficiency with threat intelligence platforms, including Recorded Future, ThreatMon, GreyNoise, Google Threat Intelligence, VirusTotal, and Mandiant, to enrich investigations, validate indicators, and map activity to MITRE ATT&CK. | |
| 5 | Preferred | Hands‑on experience using Cyware CSAP for incident orchestration, automated enrichment, case creation, and workflow execution across SIEM, IPS, EDR, and ticketing systems. | |
| 4 | Preferred | Security Certifications Preferred (CISSP, CIH, Sec+) | |
| Reference Name (): |
| Title (Optional) |
| Company Name (): |
| Phone Number (include area code): |
| E-mail address (Optional): |
| Professional Relationship (Optional): |
| Reference Name (): |
| Title (Optional) |
| Company Name (): |
| Phone Number (include area code): |
| E-mail address (Optional): |
| Professional Relationship (Optional): |
| Reference Name (): |
| Title (Optional) |
| Company Name (): |
| Phone Number (include area code): |
| E-mail address (Optional): |
| Professional Relationship (Optional): |
Automate your job search with Sonara.
Submit 10x as many applications with less effort than one manual application.

FAQs About Network Security Analyst 0056A Jobs at Sistema Technologies
What is the work location for this position at Sistema Technologies?
This job at Sistema Technologies is located in San Antonio, Texas, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Sistema Technologies?
Employer has not shared pay details for this role.
What employment applies to this position at Sistema Technologies?
Sistema Technologies lists this position under the following employment categories:
- Alternate-schedule
- Full-time
What experience level is required for this role at Sistema Technologies?
Sistema Technologies is looking for a candidate with "Senior-level" experience level.
What is the process to apply for this position at Sistema Technologies?
You can apply for this role at Sistema Technologies either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.