About this role
Modern Technology Solutions, Inc. (MTSI) is searching for a Senior Security Data Engineer in support of United States Space Force (USSF) Space Systems Command (SSC) and Combat Forces Command (CFC) Defensive Cyber Operations. We are seeking a Security Data Engineer to own our security telemetry pipeline end-to-end. You will be responsible for ensuring that the organization collects, ingests, normalizes, and maintains the security telemetry required to support network traffic monitoring, threat hunting, custom detection engineering, and adversary detection. The candidate will ensure the organization has the telemetry necessary to detect the adversary behaviors necessary to identify, protect, and defend our mission and customers. The candidate will be responsible for developing the processes and procedures for identifying, onboarding, and optimizing network and application traffic data sources (e.g., NetFlow, PCAP, proxy logs, VPC flow logs, DNS, etc.) to feed centralized and deployed detection solutions. Additionally, you will partner with organizational personnel to write, tune, and maintain custom threat detections based on high-quality traffic ingestion. The engineer will determine what data is required to detect specific adversary behaviors, where that data originates, how it should be collected, and whether the resulting telemetry provides sufficient visibility to support reliable detections. The engineer is responsible for understanding the detection objective and working backward to ensure the organization has the appropriate data sources, telemetry fields, collection methods, retention, normalization, and data quality necessary to achieve that objective. Role and Responsibilities: The candidate will architect, build, and maintain data pipelines ingesting network traffic, VPC flow logs, firewall/proxy logs, DNS records etc. into the organization’s centralized systems. The candidate will; ensure ingested data is structured, normalized (e.g., OCSF or CIM standard), and continuously parsed correctly for immediate querying and correlation.
- Design, write, and deploy high-fidelity detection rules using SQL, Sigma, YARA-L, or Python targeting network-based attack techniques (e.g., C2 beaconing, data exfiltration, and lateral movement).
- Continuously tune network detections to reduce false-positive rates while maintaining a high signal-to-noise ratio.
- Identify telemetry required to support network monitoring, threat hunting, incident response, and custom detection engineering.
- Map detection requirements to underlying data sources and identify visibility gaps across hybrid cloud and on-premises environments
- Design and maintain pipelines that ingest security telemetry from network, endpoint, identity, cloud, application, OT, and security infrastructure.
- Ensure telemetry is delivered reliably to SIEM, data lake, analytics, and detection platforms; troubleshoot ingestion, parsing, latency, and data-quality issues.
- Evaluate whether packet, flow, session, DNS, proxy, authentication, endpoint, and application telemetry is sufficient for specific detection requirements.
- Support custom detection development through data discovery, enrichment, normalization, and validation.
- Identify opportunities to move detections from low-level indicators toward higher-level behavioral and tradecraft-based detection using the Detection Stack.
- Work with network engineering teams to evaluate technologies such as network sensors, NetFlow/IPFIX, DNS telemetry, proxy telemetry, firewall logs, IDS/IPS, packet capture, Zeek/network metadata, and NDR platforms.
- Establish telemetry health metrics, dashboards, and automated checks for missing, delayed, or malformed data.
- Assess network visibility across data centers, cloud environments, remote networks, and segmented environments.
- Optimize telemetry architectures and ingestion pipelines for performance, scalability, reliability, and cost
Required:
- Strong understanding of; network security monitoring and security telemetry. MITRE ATT&CK framework, adversary behaviors, TCP/IP, DNS, HTTP/HTTPS, TLS, SMTP, DHCP, SSH, SMB, and common network protocols.
- Experience in; translating detection requirements into specific data and telemetry requirements.
- Understanding of; packet capture, network flows, network metadata, and session-level telemetry.
- Experience with technologies such as NetFlow/IPFIX, Zeek, Wireshark, IDS/IPS, firewalls, proxies, or network detection platforms, network segmentation, routing, VLANs, VPNs, cloud networking, and encrypted traffic.
- Experience designing or maintaining security data ingestion pipelines. Understanding of APIs, syslog, message queues, streaming data, and event-based architectures.
- Experience working with JSON, XML, CSV, CEF, LEEF, ECS, or other security-data formats. Strong understanding of data normalization, parsing, enrichment, transformation, and schema management.
- Experience with at least one scripting language such as Python.
- Ability to conduct data-source and detection-gap assessments.
- Experience working with threat hunting or purple-team activities. Understanding of adversary emulation and controlled security testing.
Desired:
- Hands-on experience building security telemetry pipelines and supporting SIEM, data lake, or analytics platforms.
- Experience writing or tuning detections using SQL, Sigma, YARA-L, Python, or similar.
- Familiarity with MITRE ATT&CK, detection engineering, and Purple Team validation.
- Ability to work with network, infrastructure, and cyber operations teams to enable and validate telemetry sources.
- Strong written and verbal communication skills for technical analysis and stakeholder engagement.
- Prior experience supporting federal, DoD, or USSF cyber environments is highly desirable.
Education Requirements:
- Bachelor’s degree in cybersecurity, computer science, security engineering, data science, network security, or a related field and 18 years of relevant professional experience; or Master’s degree in one of the same fields and 10 years of relevant professional experience
Clearance Requirements:
- Must possess a Top Secret with SCI eligibility. SAR/SAP experience is highly desirable.
Location/Travel Requirements :
- Place of work is Colorado Springs; remote work opportunity is limited. You may be required to travel periodically, less than 20%.
The pay range for this position in Colorado is $155,000/year to $195,000/year; however, base pay offered may vary depending on established government contract ranges, job-related knowledge, skills, and experience, and other factors. MTSI also offers a full range of medical, financial, and other benefits, dependent on the position offered. Base pay information is based on market location. Applications will be accepted on an ongoing basis. This posting will be renewed periodically until the position is filled.
#LI-MW2 #MTSI