{"schemaVersion":"jobsearcher.job.v1","id":"a7acad7fcede4140d0f52e2b","url":"https://jobsearcher.com/jobs/a7acad7fcede4140d0f52e2b","canonicalUrl":"https://jobsearcher.com/jobs/a7acad7fcede4140d0f52e2b","title":"Cyber Security Signature Developer","description":"Cyber Security Signature Developer/Scripter – TS/SCI Required – Lackland AFB, San Antonio, TX\nJob Description\nThe Cyber Security Signature Developer/Scripter’s primary responsibility is for Developing, Testing, Deploying, and Managing the development of commercial, and custom Host Based and Network based IDS/IPS SIEM, SOAR signatures, rules, workflows, and dashboards.\nAt IPSecure, you’ll shape the future of Cybersecurity by building the technology to tackle the toughest challenges and stay ahead of the latest threats. If you want to join an agile and growing company that makes a direct impact in the cyber fight against cyber criminals, IPSecure is the place for you. Driven by passionate people who are dedicated to making the world safer, it’s no wonder we’ve been named a Top Place to Work in San Antonio.\nResponsibilities\nDevelopment of all signatures, with the intent to develop custom signatures related to the Tough and Challenging levels within DCO tool sets.\nAnalyze, interpret, and utilize Regular Expressions, YARA, and Snort‐like capabilities in the creation of custom signature sets.\nDevelop and document IPS/IDS SOPs.\nInvestigate intrusion events, host files, network files, and memory, to dissect and extrapolate information necessary for the development of custom signatures.\nAnalyze deployed signatures to reduce false positive rate and perform signature maintenance.\nCreate, modify, and manage Security Orchestration and Automation workflows for operational use and execution.\nAutomate tasks using a common programming or scripting language.\nUtilize Linux systems, UNIX/Linux shell scripting (bash), Python, PowerShell.\nDevelop, Test, Deploy, and Manage signatures, rules and filters for capabilities such as; IDS, IPS, firewall, web application firewall, proxy and SIEM systems.\nMigrate, tune, and document existing and future AF signatures/detections to new tools and systems as they become available.\nProvide support to external units and work centers as approved by AFCERT leadership.\nProvide training and knowledge transfer to government personnel as requested.\nProvide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.\nMaintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures.\nCreate, document, and report metrics for analysis to improve weapon system processes and mission execution.\nBasic Qualifications\nAn active TS/SCI clearance is required to start.\nAbility to gain the CSSP Incident Responder Certification (GCFA) Certification requirement within 120-day of hire date.\nPreferred Qualifications\nExtensive knowledge with one or more of the IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (ex: AF, Navy, Army, DC3, DISA) or Federal Government.\nExperience with IP addressing and domain name service; network components; Transmission Control Protocol (TCP)/User Datagram Protocol (UDP), File Transfer Protocol (FTP), Simple Mail Transfer Protocol (SMTP), and Hypertext Transfer Protocol (HTTP).\nUnderstand the network Open Systems Interconnection (OSI) model.\nAutomate processes and procedures using scripts and SQL/database administration.\nIn-depth Knowledge of DoD or Air Force cyber operations policies and guides.\nExtensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community.\nBenefits\nMedical, Dental, Vision (company paid for employee and dependents), Paid Time Off, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid legal plan and ID protection plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.\nEEOC Statement\nIPSecure is an Affirmative Action Employer and does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.","company":"Ipsecure","rawCompany":"ipsecure","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-04-12T21:04:35.825Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"928110","title":"National Security","slug":"national-security"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cyber Security Signature Developer","description":"Cyber Security Signature Developer/Scripter – TS/SCI Required – Lackland AFB, San Antonio, TX\nJob Description\nThe Cyber Security Signature Developer/Scripter’s primary responsibility is for Developing, Testing, Deploying, and Managing the development of commercial, and custom Host Based and Network based IDS/IPS SIEM, SOAR signatures, rules, workflows, and dashboards.\nAt IPSecure, you’ll shape the future of Cybersecurity by building the technology to tackle the toughest challenges and stay ahead of the latest threats. If you want to join an agile and growing company that makes a direct impact in the cyber fight against cyber criminals, IPSecure is the place for you. Driven by passionate people who are dedicated to making the world safer, it’s no wonder we’ve been named a Top Place to Work in San Antonio.\nResponsibilities\nDevelopment of all signatures, with the intent to develop custom signatures related to the Tough and Challenging levels within DCO tool sets.\nAnalyze, interpret, and utilize Regular Expressions, YARA, and Snort‐like capabilities in the creation of custom signature sets.\nDevelop and document IPS/IDS SOPs.\nInvestigate intrusion events, host files, network files, and memory, to dissect and extrapolate information necessary for the development of custom signatures.\nAnalyze deployed signatures to reduce false positive rate and perform signature maintenance.\nCreate, modify, and manage Security Orchestration and Automation workflows for operational use and execution.\nAutomate tasks using a common programming or scripting language.\nUtilize Linux systems, UNIX/Linux shell scripting (bash), Python, PowerShell.\nDevelop, Test, Deploy, and Manage signatures, rules and filters for capabilities such as; IDS, IPS, firewall, web application firewall, proxy and SIEM systems.\nMigrate, tune, and document existing and future AF signatures/detections to new tools and systems as they become available.\nProvide support to external units and work centers as approved by AFCERT leadership.\nProvide training and knowledge transfer to government personnel as requested.\nProvide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.\nMaintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures.\nCreate, document, and report metrics for analysis to improve weapon system processes and mission execution.\nBasic Qualifications\nAn active TS/SCI clearance is required to start.\nAbility to gain the CSSP Incident Responder Certification (GCFA) Certification requirement within 120-day of hire date.\nPreferred Qualifications\nExtensive knowledge with one or more of the IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (ex: AF, Navy, Army, DC3, DISA) or Federal Government.\nExperience with IP addressing and domain name service; network components; Transmission Control Protocol (TCP)/User Datagram Protocol (UDP), File Transfer Protocol (FTP), Simple Mail Transfer Protocol (SMTP), and Hypertext Transfer Protocol (HTTP).\nUnderstand the network Open Systems Interconnection (OSI) model.\nAutomate processes and procedures using scripts and SQL/database administration.\nIn-depth Knowledge of DoD or Air Force cyber operations policies and guides.\nExtensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community.\nBenefits\nMedical, Dental, Vision (company paid for employee and dependents), Paid Time Off, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid legal plan and ID protection plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.\nEEOC Statement\nIPSecure is an Affirmative Action Employer and does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.","datePosted":"2026-04-12T21:04:35.825Z","dateModified":"2026-04-12T21:04:35.825Z","hiringOrganization":{"@type":"Organization","name":"Ipsecure","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a7acad7fcede4140d0f52e2b"},"url":"https://jobsearcher.com/jobs/a7acad7fcede4140d0f52e2b"}}