Hiring.Camp

Security Data Engineer - Senior

Modern Technology Solutions Inc

·

Today

Location
Colorado Springs, CO,US, US
Workplace
Hybrid
Type
Full-time
Department
Engineering
Seniority
Senior
Source
Eightfold

Description

Modern Technology Solutions, Inc. (MTSI) is searching for a Senior Security Data Engineer in support of United States Space Force (USSF) Space Systems Command (SSC) and Combat Forces Command (CFC) Defensive Cyber Operations. We are seeking a Security Data Engineer to own our security telemetry pipeline end-to-end. You will be responsible for ensuring that the organization collects, ingests, normalizes, and maintains the security telemetry required to support network traffic monitoring, threat hunting, custom detection engineering, and adversary detection. The candidate will ensure the organization has the telemetry necessary to detect the adversary behaviors necessary to identify, protect, and defend our mission and customers. The candidate will be responsible for developing the processes and procedures for identifying, onboarding, and optimizing network and application traffic data sources (e.g., NetFlow, PCAP, proxy logs, VPC flow logs, DNS, etc.) to feed centralized and deployed detection solutions. Additionally, you will partner with organizational personnel to write, tune, and maintain custom threat detections based on high-quality traffic ingestion. The engineer will determine what data is required to detect specific adversary behaviors, where that data originates, how it should be collected, and whether the resulting telemetry provides sufficient visibility to support reliable detections. The engineer is responsible for understanding the detection objective and working backward to ensure the organization has the appropriate data sources, telemetry fields, collection methods, retention, normalization, and data quality necessary to achieve that objective. Role and Responsibilities: The candidate will architect, build, and maintain data pipelines ingesting network traffic, VPC flow logs, firewall/proxy logs, DNS records etc. into the organization’s centralized systems. The candidate will; ensure ingested data is structured, normalized (e.g., OCSF or CIM standard), and continuously parsed correctly for immediate querying and correlation. Design, write, and deploy high-fidelity detection rules using SQL, Sigma, YARA-L, or Python targeting network-based attack techniques (e.g., C2 beaconing, data exfiltration, and lateral movement). Continuously tune network detections to reduce false-positive rates while maintaining a high signal-to-noise ratio. Identify telemetry required to support network monitoring, threat hunting, incident response, and custom detection engineering. Map detection requirements to underlying data sources and identify visibility gaps across hybrid cloud and on-premises environments Design and maintain pipelines that ingest security telemetry from network, endpoint, identity, cloud, application, OT, and security infrastructure. Ensure telemetry is delivered reliably to SIEM, data lake, analytics, and detection platforms; troubleshoot ingestion, parsing, latency, and data-quality issues. Evaluate whether packet, flow, session, DNS, proxy, authentication, endpoint, and application telemetry is sufficient for specific detection requirements. Support custom detection development through data discovery, enrichment, normalization, and validation. Identify opportunities to move detections from low-level indicators toward higher-level behavioral and tradecraft-based detection using the Detection Stack. Work with network engineering teams to evaluate technologies such as network sensors, NetFlow/IPFIX, DNS telemetry, proxy telemetry, firewall logs, IDS/IPS, packet capture, Zeek/network metadata, and NDR platforms. Establish telemetry health metrics, dashboards, and automated checks for missing, delayed, or malformed data. Assess network visibility across data centers, cloud environments, remote networks, and segmented environments. Optimize telemetry architectures and ingestion pipelines for performance, scalability, reliability, and cost Required: Strong understanding of; network security monitoring and security telemetry. MITRE ATT&CK framework, adversary behaviors, TCP/IP, DNS, HTTP/HTTPS, TLS, SMTP, DHCP, SSH, SMB, and common network protocols. Experience in; translating detection requirements into specific data and telemetry requirements. Understanding of; packet capture, network flows, network metadata, and session-level telemetry. Experience with technologies such as NetFlow/IPFIX, Zeek, Wireshark, IDS/IPS, firewalls, proxies, or network detection platforms, network segmentation, routing, VLANs, VPNs, cloud networking, and encrypted traffic. Experience designing or maintaining security data ingestion pipelines. Understanding of APIs, syslog, message queues, streaming data, and event-based architectures. Experience working with JSON, XML, CSV, CEF, LEEF, ECS, or other security-data formats. Strong understanding of data normalization, parsing, enrichment, transformation, and schema management. Experience with at least one scripting language such as Python. Ability to conduct data-source and detection-gap assessments. Experience working with threat hunting or purple-team activities. Understanding of adversary emulation and controlled security testing.  Desired: Hands-on experience building security telemetry pipelines and supporting SIEM, data lake, or analytics platforms. Experience writing or tuning detections using SQL, Sigma, YARA-L, Python, or similar. Familiarity with MITRE ATT&CK, detection engineering, and Purple Team validation. Ability to work with network, infrastructure, and cyber operations teams to enable and validate telemetry sources. Strong written and verbal communication skills for technical analysis and stakeholder engagement. Prior experience supporting federal, DoD, or USSF cyber environments is highly desirable. Education Requirements: Bachelor’s degree in cybersecurity, computer science, security engineering, data science, network security, or a related field and 18 years of relevant professional experience; or Master’s degree in one of the same fields and 10 years of relevant professional experience Clearance Requirements: Must possess a Top Secret with SCI eligibility. SAR/SAP experience is highly desirable. Location/Travel Requirements : Place of work is Colorado Springs; remote work opportunity is limited. You may be required to travel periodically, less than 20%. The pay range for this position in Colorado is $155,000/year to $195,000/year; however, base pay offered may vary depending on established government contract ranges, job-related knowledge, skills, and experience, and other factors. MTSI also offers a full range of medical, financial, and other benefits, dependent on the position offered. Base pay information is based on market location. Applications will be accepted on an ongoing basis. This posting will be renewed periodically until the position is filled. #LI-MW2 #MTSI

Skills

PythonSQLData ScienceSAPCybersecuritySIEMTCP/IP

Similar Jobs

30

Data Security Engineer

Leidos·3309 Army Research Laboratory Adelphi MD, US·Hybrid, Onsite

1mo ago

Data Security Engineer

General Intuition & Medal·New York City·Onsite

3mo ago

Data Security Engineer

Gnw·Richmond, Virginia +1

3mo ago

Data Security Engineer

Pwc·Athens - Kifisias Av. 65, Greece

3mo ago

Data Security Engineer

Booz Allen Hamilton·Fayetteville, NC·Hybrid

3mo ago

Data Security Engineer

Skechers·USA: 225 Sepulveda, US·Hybrid

4mo ago

Data Security Engineer

General Intuition & Medal·New York City·Onsite

8mo ago

Principal Engineer - Security & Controls (Data Centers)

AECOM·Bogota, COLOMBIA

Today

Security Infrastructure Support and Data Pipeline Engineer

Booz Allen Hamilton·Bethesda, MD·Hybrid

1d ago

SIEM & Security Data Staff Engineer

Usaa·San Antonio Home Office I, US +3·Remote, Hybrid

1d ago

Data Privacy Security Engineer

Bjakcareer·Global·Remote

1d ago

Colo Physical Security Engineer [Architect], Data Center Engineering, Colocation Regional Engineering

Amazon

1d ago

Senior Customer Success Engineer - Data & AI Security

Veeamsoftware·Remote, US·Hybrid, Remote

1d ago

Security Operations Data Loss Prevention Engineer

Purestorage·Lehi, Utah +2

1d ago

Staff Security Data Engineer

Adobe·San Jose, US +1

2d ago

Junior Data Security Engineer

Verizon Communications·GA Home Working, GA

2d ago

Physical Security Engineer (Design) , Data Center Engineering

Amazon

4d ago

Distinguished AI and Data Security Engineer

Verizon Communications·5055 North Point Pkwy, GA +1

5d ago

Senior Customer Success Engineer - Data & AI Security

Veeamsoftware·Remote, US·Hybrid, Remote

5d ago

EDAT- Senior Data Security Engineer - Tampa, FL

Barbaricum·Tampa, FL·Onsite

5d ago

Sr. Security Data Engineer & Developer, Security Data Platform

Mufgub·BCIT Bengaluru Office, India

6d ago

Principal Specialist Sales Engineer, Data Security - Majors

Zscaler·Remote - USA·Remote

1w ago

Staff SW Systems Engineer 10531 – DPDK/VPP Data Plane Developer (SD-WAN Security)

Extremenetworks·Bangalore·Hybrid

1w ago

Sr. Staff Integration Engineer (Security Platform and Data Pipelines)

Zscaler·Remote - India +1·Remote

1w ago

Managing Engineer, Data Security Engineering

Allstate·Belfast 10 Mays Meadow, UK +1·Hybrid

2w ago

Managing Engineer - Data Security Engineering

Allstate·USA - IL, US·Remote

2w ago

AI Data & Security Governance Engineer (MAD-BS-OR)

HiNext·NCP, US·Hybrid

2w ago

Data Engineer - Security & Intelligence

Envitia

2w ago

[L6-1] Security Data Platform Engineer (Detection Engineering)

Coupang Internal·Seoul, South Korea

2w ago

AVP, Data Engineer (Information Security & Digital Risk Management)

Ocbc·SGP-Head Office, Singapore·Hybrid

3w ago