JULIO MARTINEZ
Network Detection & Response Engineer // NSM · Threat Detection · Security Observability
15+ yrs cybersecurity
25+ yrs IT / networking
TS/SCI (DoD)
DoD · Federal · Enterprise · Health · Finance
SUMMARY Profile
Principal Cybersecurity Engineer with 15+ years securing large-scale enterprise and
federal networks, with deep hands-on focus on Network Detection & Response (NDR) and
Network Security Monitoring (NSM). Designs sensor-to-dashboard detection pipelines that turn raw
PCAP and NetFlow into high-fidelity, MITRE ATT&CK-aligned detections — from packet
capture and protocol analysis through enrichment, alerting, and executive-ready visibility.
Production NSM/NDR experience deploying Security Onion (Zeek + Suricata) sensors and
Gigamon network taps across multi-classification environments — plus Corelight for
enterprise-grade network evidence and Grafana, Prometheus, and InfluxDB for time-series
telemetry and custom operational dashboards. Pairs that network depth with a
decade of SIEM/UEBA detection engineering (Splunk ES, XSIAM, Elastic) and SOAR automation, so
network findings flow seamlessly into SOC triage and response. Strong Python/API tooling for
ingestion pipelines, integrations, and dashboards across cloud and on-prem.
12 TB/day
Telemetry ingest scale
150k+ EPS
Peak event throughput
98%
Network device visibility
● LIVE LAB Network Detection & Response Lab
Self-architected, full-stack NDR lab that extends my production NSM / Security Onion background
onto a modern open stack — the discipline of capturing, parsing, and detecting on live network evidence. Sensors tap a
mirrored/SPAN segment; PCAP and NetFlow are captured, parsed by Zeek, scored by
Suricata, and rendered into custom dashboards over a time-series observability backend.
CorelightZeekSuricata
PCAPNetFlow / IPFIX
GrafanaPrometheusInfluxDB
- Packet & flow capture: tap/SPAN ingestion of full PCAP plus NetFlow/IPFIX records for retrospective hunting and forensics.
- Zeek / Corelight evidence: protocol logs (conn, dns, http, ssl/tls, files, x509) as the structured backbone for detection.
- Suricata detection: signature + flow-based alerting, EVE JSON output, and custom rule tuning to cut false positives.
- Time-series backend: Prometheus + InfluxDB storing sensor health, flow volumes, and detection metrics.
- Custom Grafana dashboards: top talkers, protocol mix, beaconing/JA3 anomalies, alert trends, and sensor SLOs.
- Detection engineering: MITRE ATT&CK-mapped network detections with Git-versioned rules and CI validation.
CAPABILITIES Core Qualifications
Network Detection & Response (NDR)
Stand up and operate NDR sensors (Zeek/Corelight, Suricata, Security Onion, Cisco Stealthwatch) across mirrored and segmented networks; tune detections for east-west traffic, lateral movement, C2 beaconing, and exfiltration.
Packet & Flow Telemetry
Engineer Gigamon TAP/packet-broker visibility and pipelines for full PCAP and NetFlow/IPFIX — including cross-domain (CDS) NetFlow delivery; protocol analysis (DNS, TLS/JA3, HTTP, SMB); retention, indexing, and replay for hunting and forensics.
Security Observability Stack
Operational dashboards and metrics with Grafana, Prometheus, and InfluxDB — sensor health, flow baselines, detection KPIs, and SLOs — plus Kibana and Power BI for executive reporting.
Detection Engineering & Content Lifecycle
Detection-as-code with Git + CI/CD: authoring, testing, promotion, and rollback of Suricata rules, Zeek scripts, Sigma, YARA, and SIEM correlation content mapped to MITRE ATT&CK.
SIEM / UEBA Integration
Feed normalized network evidence into Splunk ES, XSIAM, and Elastic for cross-source correlation, risk-based alerting, and behavioral analytics — bridging the network and SOC views.
Automation, APIs & Tooling
Python/Flask/FastAPI services, REST APIs, and webhooks for ingestion, enrichment, and SOAR (Cortex XSOAR) orchestration; Ansible for sensor/node builds and configuration drift control.
Zero Trust & Network Security
Micro-segmentation, NAC (ForeScout), VPN/SD-WAN, secure web gateways, and cloud firewalls; integrate posture and flow data into continuous monitoring and compliance.
Platform Reliability & IaC
Highly available monitoring pipelines via automated patching, upgrade runbooks, health checks, and rollback strategies that protect mission-critical capture and logging paths.
EXPERIENCE Professional Experience
Principal Cybersecurity Engineer / Co-Founder
· Xbitium Technologies
Feb 2025 – Present · Tampa, FL
- Architect and operate NDR + NSM environments — Zeek/Corelight, Suricata, and flow sensors — capturing PCAP and NetFlow and converting them into MITRE ATT&CK-aligned network detections.
- Build custom Grafana dashboards over Prometheus and InfluxDB for sensor health, flow baselines, protocol anomalies, and detection KPIs across client environments.
- Engineer Python microservices and REST APIs (FastAPI/Flask) for telemetry ingestion pipelines, real-time KPI dashboards, webhook integrations, and automated reporting.
- Author and tune Suricata rules, Zeek scripts, Sigma, and YARA under a detection-as-code workflow with GitHub Actions — automated testing, versioning, promotion, and rollback.
- Integrate network evidence into Cortex XSIAM/XDR and Splunk ES, then automate triage, enrichment, and containment via Cortex XSOAR playbooks for zero manual handoff.
- Design incident lifecycle workflows from ingestion and deduplication through escalation, remediation, and post-incident reporting with full audit trail.
Sr. Cybersecurity Consultant & Solutions Architect
· Palo Alto Networks | RedMatter Solutions
Oct 2023 – Feb 2025 · Tampa, FL / Arlington, VA (Remote)
- Architected and deployed Splunk Enterprise Security for FHFA — data models, correlation searches, adaptive response, and risk-based alerting (RBA) aligned to MITRE ATT&CK.
- Onboarded and normalized IDS/IPS, firewall, NetFlow, and network telemetry into the platform (CIM), giving analysts unified network + host visibility for hunting.
- Built and tuned Cortex XSOAR playbooks (Python) to automate notable-event response — threat-intel enrichment, VirusTotal, identity APIs, auto-ticketing, and containment.
- Optimized detection performance at scale — SPL refactoring, summary indexing, search-head clustering, and data-model acceleration — to reduce runtime and licensing pressure.
- Integrated STIX/TAXII/MISP threat-intel feeds for automated IoC enrichment, scoring, and network-aware hunting across ingested telemetry.
- Delivered SPL/detection training and runbook documentation enabling SOC analysts to independently build searches, dashboards, and investigations.
Lead Cybersecurity Engineer & Architect
· GDIT / Crystal Clear Technologies — U.S. CENTCOM HQ
May 2017 – Sep 2023 · MacDill AFB, Tampa, FL
- Architected and operated enterprise security monitoring processing 12 TB/day at 150k EPS across multi-domain DoD networks — indexer clusters, search-head clusters, and heavy forwarders.
- Deployed and managed Gigamon network TAPs / packet brokers across 12 isolated networks (classified up to Secret/SIPR), aggregating and filtering traffic to feed NDR sensors and flow collectors.
- Engineered and certified a Forcepoint Cross-Domain Solution (CDS) guard to pass NetFlow from 12 segregated enclaves up to the SIPR network — delivering cross-domain network visibility while preserving classification boundaries.
- Deployed multiple production Security Onion instances — Zeek and Suricata sensors producing protocol evidence, IDS alerts, and full PCAP for network detection and forensic hunting.
- Built correlation content and CIM-normalized parsers for firewall, NDR, IDS/IPS, NetFlow, EDR, identity, and cloud sources, including risk-based alerting and data-model acceleration.
- Engineered ingestion pipelines with Kafka, Cribl, and NiFi — DLQs, backpressure handling, replay, and schema governance — ensuring zero data loss at DoD scale.
- Achieved 40% MTTR reduction and 25% false-positive drop via UEBA tuning, risk-scoring models, and behavioral baselines aligned to MITRE ATT&CK.
- Implemented Zero Trust with ForeScout NAC achieving 98% device visibility; fed NAC + network posture data into continuous compliance correlation and alerting.
- Used Ansible to automate node builds, parser/TA deployment, and index configuration across classified and unclassified enclaves, eliminating manual drift.
- Led ATO / RMF accreditation across 12 classified domains, aligning network monitoring and logging controls with DoD SRG requirements.
Lead SIEM / SOC Engineer & Architect
· HHS CSIRC, Protiviti, Deloitte, AT&T, DTRA, DISA
2009 – 2017 · Multiple Locations
- Led enterprise Splunk ES deployment for HHS CSIRC (CDC, FDA, NIH, IHS) — HA indexer/search-head architecture, CIM-normalized telemetry, and HIPAA-aligned correlation.
- Architected and migrated DISA-Europe ArcSight SIEM to Splunk ES at Deloitte — theater-wide deployment spanning USCENTCOM AORs (Kuwait, Afghanistan, Iraq, Bahrain, Qatar).
- Built greenfield SIEM programs for Fortune 500 clients at Protiviti — onboarding, parser development, correlation content, and analyst training from zero to operational.
- Led 24×7 NOSC/SOC operations for DTRA — managing 12 network engineers and 12 cyber analysts with network monitoring, IPS, and SolarWinds as primary detection tooling.
Network & Systems Engineer (Early Career)
· U.S. Air Force & Consulting
2002 – 2009 · Multiple Locations
- Served in U.S. Air Force communications/network roles supporting secure voice and data networks across multiple security domains.
- Installed, configured, and hardened routers, switches, firewalls, and Windows/Linux servers — building the packet-level networking foundation behind today's NDR work.
- Implemented patching, AV, backup, and monitoring baselines aligned to STIG requirements; designed LAN/WAN, Wi-Fi, and perimeter security for business clients.
DETECTIONS Network Detection & Hunting Use Cases
C2 Beaconing & Anomalous Connections
Detect periodic callbacks, long-lived connections, and rare destinations using Zeek conn logs, JA3/JA3S TLS fingerprints, and flow timing analysis.
DNS Tunneling & Exfiltration
Surface high-entropy subdomains, abnormal query volumes, TXT-record abuse, and unusual upstream resolvers from Zeek dns logs and NetFlow.
Lateral Movement & East-West Anomalies
Correlate SMB/RDP/WinRM flows, new internal peer relationships, and scanning patterns to flag lateral movement inside the perimeter.
Suspicious TLS / Certificate Activity
Detect self-signed certs, mismatched SNI, expired/abnormal x509, and known-bad JA3 fingerprints from Zeek ssl/x509 evidence.
Data Exfiltration & Volume Anomalies
Baseline per-host egress with NetFlow + Grafana; alert on abnormal upload volumes, off-hours transfers, and rare external destinations.
IDS / Signature & YARA Detection
Author and tune Suricata signatures and YARA rules for malware, tooling, and TTP-specific patterns; correlate EVE alerts with flow context.
STACK Technical Expertise
Corelight
Zeek
Suricata
PCAP
NetFlow / IPFIX
Grafana
Prometheus
InfluxDB
Security Onion
Gigamon (TAP / Packet Broker)
Cisco Stealthwatch (NDR)
Network Security Monitoring (NSM)
Cross-Domain Solution (CDS)
Snort
YARA
Sigma Rules
JA3 / TLS Fingerprinting
Wireshark / tshark
Zero Trust (ZTNA)
ForeScout NAC
Splunk ES / SPL
Palo Alto XSIAM / Cortex XDR
Cortex XSOAR
Elastic / KQL
QRadar · ArcSight
UEBA (Exabeam, Securonix)
MITRE ATT&CK
Kafka / Pulsar
Cribl / Apache NiFi
Python (Automation & APIs)
Flask / FastAPI / REST
Node.js / React
Ansible / IaC
GitHub Actions / CI-CD
Bash / Linux Hardening
AWS / Azure
NIST CSF / RMF
CERTS Certifications
EC-Council Certified Ethical Hacker (CEH)
GIAC Certified Incident Handler (GCIH)
CompTIA Security+
CompTIA Network+
CompTIA A+
Red Hat Certified System Administrator (RHCSA)
ArcSight Certified Administrator (ACIA)
ArcSight Certified Security Analyst (ACSA)
Cribl Certified User
Cribl Certified Services Consultant
Forcepoint Certified HS Guard Admin
Forescout Certified Associate (FSCA)
PROFILE Education & Additional Information
Education
CCAF — Data/Voice Network Systems (Top Honors); Electronics & Communications (Honors)
Clearance
U.S. Top Secret / SCI (DoD) — Active 23 years
Languages
Bilingual English / Spanish
Work Mode
Remote / Hybrid / On-site · Open to relocation
Focus
NDR · NSM · Detection Engineering · Security Observability
Domains
DoD · Federal · Enterprise · Healthcare · Finance
HISTORY Professional Timeline
Feb 2025 – Present
Principal Cybersecurity Engineer / Co-Founder
Xbitium Technologies — Tampa, FL
Oct 2023 – Feb 2025 · 1.4 yrs
Sr. Cybersecurity Consultant & Solutions Architect
Palo Alto Networks | RedMatter Solutions — Tampa, FL / Arlington, VA
May 2017 – Sep 2023 · 6.3 yrs
Lead Cybersecurity Engineer & Architect
GDIT / Crystal Clear Technologies — U.S. CENTCOM HQ, MacDill AFB
Nov 2015 – Apr 2017 · 1.5 yrs
Lead Cybersecurity Engineer
Merlin International (HHS CSIRC) — Atlanta, GA
Aug 2014 – Nov 2015 · 1.3 yrs
Sr. Manager / SIEM SME
Protiviti Inc. (Fortune 500 Clients) — Atlanta, GA
Apr 2012 – Aug 2014 · 2.3 yrs
Sr. Manager / SIEM SME
Deloitte & Touche LLP (DISA Europe) — Stuttgart, Germany
Feb 2011 – Apr 2012 · 1.2 yrs
Sr. Information Assurance Engineer
AT&T GSI (USCENTCOM) — Arifjan, Kuwait
Jan 2009 – Feb 2011 · 2 yrs
NOSC Manager / Network Engineer
Defense Engineering Inc. (DTRA) — Arlington, VA
Aug 2006 – Jan 2009 · 2.5 yrs
Network Engineer
Mutual Telecom Services — Multiple Locations
Aug 2002 – Aug 2006 · 4 yrs
Network Specialist
U.S. Air Force (Active Duty) — Ramstein, Germany