Julio Martinez

JULIO MARTINEZ

Network Detection & Response Engineer  //  NSM · Threat Detection · Security Observability

15+ yrs cybersecurity 25+ yrs IT / networking TS/SCI (DoD) DoD · Federal · Enterprise · Health · Finance

SUMMARY Profile

Principal Cybersecurity Engineer with 15+ years securing large-scale enterprise and federal networks, with deep hands-on focus on Network Detection & Response (NDR) and Network Security Monitoring (NSM). Designs sensor-to-dashboard detection pipelines that turn raw PCAP and NetFlow into high-fidelity, MITRE ATT&CK-aligned detections — from packet capture and protocol analysis through enrichment, alerting, and executive-ready visibility.

Production NSM/NDR experience deploying Security Onion (Zeek + Suricata) sensors and Gigamon network taps across multi-classification environments — plus Corelight for enterprise-grade network evidence and Grafana, Prometheus, and InfluxDB for time-series telemetry and custom operational dashboards. Pairs that network depth with a decade of SIEM/UEBA detection engineering (Splunk ES, XSIAM, Elastic) and SOAR automation, so network findings flow seamlessly into SOC triage and response. Strong Python/API tooling for ingestion pipelines, integrations, and dashboards across cloud and on-prem.

12 TB/day
Telemetry ingest scale
150k+ EPS
Peak event throughput
40%
MTTR reduction
98%
Network device visibility

● LIVE LAB Network Detection & Response Lab

Self-architected, full-stack NDR lab that extends my production NSM / Security Onion background onto a modern open stack — the discipline of capturing, parsing, and detecting on live network evidence. Sensors tap a mirrored/SPAN segment; PCAP and NetFlow are captured, parsed by Zeek, scored by Suricata, and rendered into custom dashboards over a time-series observability backend.

CorelightZeekSuricata PCAPNetFlow / IPFIX GrafanaPrometheusInfluxDB

CAPABILITIES Core Qualifications

Network Detection & Response (NDR)

Stand up and operate NDR sensors (Zeek/Corelight, Suricata, Security Onion, Cisco Stealthwatch) across mirrored and segmented networks; tune detections for east-west traffic, lateral movement, C2 beaconing, and exfiltration.

Packet & Flow Telemetry

Engineer Gigamon TAP/packet-broker visibility and pipelines for full PCAP and NetFlow/IPFIX — including cross-domain (CDS) NetFlow delivery; protocol analysis (DNS, TLS/JA3, HTTP, SMB); retention, indexing, and replay for hunting and forensics.

Security Observability Stack

Operational dashboards and metrics with Grafana, Prometheus, and InfluxDB — sensor health, flow baselines, detection KPIs, and SLOs — plus Kibana and Power BI for executive reporting.

Detection Engineering & Content Lifecycle

Detection-as-code with Git + CI/CD: authoring, testing, promotion, and rollback of Suricata rules, Zeek scripts, Sigma, YARA, and SIEM correlation content mapped to MITRE ATT&CK.

SIEM / UEBA Integration

Feed normalized network evidence into Splunk ES, XSIAM, and Elastic for cross-source correlation, risk-based alerting, and behavioral analytics — bridging the network and SOC views.

Automation, APIs & Tooling

Python/Flask/FastAPI services, REST APIs, and webhooks for ingestion, enrichment, and SOAR (Cortex XSOAR) orchestration; Ansible for sensor/node builds and configuration drift control.

Zero Trust & Network Security

Micro-segmentation, NAC (ForeScout), VPN/SD-WAN, secure web gateways, and cloud firewalls; integrate posture and flow data into continuous monitoring and compliance.

Platform Reliability & IaC

Highly available monitoring pipelines via automated patching, upgrade runbooks, health checks, and rollback strategies that protect mission-critical capture and logging paths.

EXPERIENCE Professional Experience

Principal Cybersecurity Engineer / Co-Founder  ·  Xbitium Technologies
Feb 2025 – Present · Tampa, FL
  • Architect and operate NDR + NSM environments — Zeek/Corelight, Suricata, and flow sensors — capturing PCAP and NetFlow and converting them into MITRE ATT&CK-aligned network detections.
  • Build custom Grafana dashboards over Prometheus and InfluxDB for sensor health, flow baselines, protocol anomalies, and detection KPIs across client environments.
  • Engineer Python microservices and REST APIs (FastAPI/Flask) for telemetry ingestion pipelines, real-time KPI dashboards, webhook integrations, and automated reporting.
  • Author and tune Suricata rules, Zeek scripts, Sigma, and YARA under a detection-as-code workflow with GitHub Actions — automated testing, versioning, promotion, and rollback.
  • Integrate network evidence into Cortex XSIAM/XDR and Splunk ES, then automate triage, enrichment, and containment via Cortex XSOAR playbooks for zero manual handoff.
  • Design incident lifecycle workflows from ingestion and deduplication through escalation, remediation, and post-incident reporting with full audit trail.
Sr. Cybersecurity Consultant & Solutions Architect  ·  Palo Alto Networks | RedMatter Solutions
Oct 2023 – Feb 2025 · Tampa, FL / Arlington, VA (Remote)
  • Architected and deployed Splunk Enterprise Security for FHFA — data models, correlation searches, adaptive response, and risk-based alerting (RBA) aligned to MITRE ATT&CK.
  • Onboarded and normalized IDS/IPS, firewall, NetFlow, and network telemetry into the platform (CIM), giving analysts unified network + host visibility for hunting.
  • Built and tuned Cortex XSOAR playbooks (Python) to automate notable-event response — threat-intel enrichment, VirusTotal, identity APIs, auto-ticketing, and containment.
  • Optimized detection performance at scale — SPL refactoring, summary indexing, search-head clustering, and data-model acceleration — to reduce runtime and licensing pressure.
  • Integrated STIX/TAXII/MISP threat-intel feeds for automated IoC enrichment, scoring, and network-aware hunting across ingested telemetry.
  • Delivered SPL/detection training and runbook documentation enabling SOC analysts to independently build searches, dashboards, and investigations.
Lead Cybersecurity Engineer & Architect  ·  GDIT / Crystal Clear Technologies — U.S. CENTCOM HQ
May 2017 – Sep 2023 · MacDill AFB, Tampa, FL
  • Architected and operated enterprise security monitoring processing 12 TB/day at 150k EPS across multi-domain DoD networks — indexer clusters, search-head clusters, and heavy forwarders.
  • Deployed and managed Gigamon network TAPs / packet brokers across 12 isolated networks (classified up to Secret/SIPR), aggregating and filtering traffic to feed NDR sensors and flow collectors.
  • Engineered and certified a Forcepoint Cross-Domain Solution (CDS) guard to pass NetFlow from 12 segregated enclaves up to the SIPR network — delivering cross-domain network visibility while preserving classification boundaries.
  • Deployed multiple production Security Onion instances — Zeek and Suricata sensors producing protocol evidence, IDS alerts, and full PCAP for network detection and forensic hunting.
  • Built correlation content and CIM-normalized parsers for firewall, NDR, IDS/IPS, NetFlow, EDR, identity, and cloud sources, including risk-based alerting and data-model acceleration.
  • Engineered ingestion pipelines with Kafka, Cribl, and NiFi — DLQs, backpressure handling, replay, and schema governance — ensuring zero data loss at DoD scale.
  • Achieved 40% MTTR reduction and 25% false-positive drop via UEBA tuning, risk-scoring models, and behavioral baselines aligned to MITRE ATT&CK.
  • Implemented Zero Trust with ForeScout NAC achieving 98% device visibility; fed NAC + network posture data into continuous compliance correlation and alerting.
  • Used Ansible to automate node builds, parser/TA deployment, and index configuration across classified and unclassified enclaves, eliminating manual drift.
  • Led ATO / RMF accreditation across 12 classified domains, aligning network monitoring and logging controls with DoD SRG requirements.
Lead SIEM / SOC Engineer & Architect  ·  HHS CSIRC, Protiviti, Deloitte, AT&T, DTRA, DISA
2009 – 2017 · Multiple Locations
  • Led enterprise Splunk ES deployment for HHS CSIRC (CDC, FDA, NIH, IHS) — HA indexer/search-head architecture, CIM-normalized telemetry, and HIPAA-aligned correlation.
  • Architected and migrated DISA-Europe ArcSight SIEM to Splunk ES at Deloitte — theater-wide deployment spanning USCENTCOM AORs (Kuwait, Afghanistan, Iraq, Bahrain, Qatar).
  • Built greenfield SIEM programs for Fortune 500 clients at Protiviti — onboarding, parser development, correlation content, and analyst training from zero to operational.
  • Led 24×7 NOSC/SOC operations for DTRA — managing 12 network engineers and 12 cyber analysts with network monitoring, IPS, and SolarWinds as primary detection tooling.
Network & Systems Engineer (Early Career)  ·  U.S. Air Force & Consulting
2002 – 2009 · Multiple Locations
  • Served in U.S. Air Force communications/network roles supporting secure voice and data networks across multiple security domains.
  • Installed, configured, and hardened routers, switches, firewalls, and Windows/Linux servers — building the packet-level networking foundation behind today's NDR work.
  • Implemented patching, AV, backup, and monitoring baselines aligned to STIG requirements; designed LAN/WAN, Wi-Fi, and perimeter security for business clients.

DETECTIONS Network Detection & Hunting Use Cases

C2 Beaconing & Anomalous Connections

Detect periodic callbacks, long-lived connections, and rare destinations using Zeek conn logs, JA3/JA3S TLS fingerprints, and flow timing analysis.

DNS Tunneling & Exfiltration

Surface high-entropy subdomains, abnormal query volumes, TXT-record abuse, and unusual upstream resolvers from Zeek dns logs and NetFlow.

Lateral Movement & East-West Anomalies

Correlate SMB/RDP/WinRM flows, new internal peer relationships, and scanning patterns to flag lateral movement inside the perimeter.

Suspicious TLS / Certificate Activity

Detect self-signed certs, mismatched SNI, expired/abnormal x509, and known-bad JA3 fingerprints from Zeek ssl/x509 evidence.

Data Exfiltration & Volume Anomalies

Baseline per-host egress with NetFlow + Grafana; alert on abnormal upload volumes, off-hours transfers, and rare external destinations.

IDS / Signature & YARA Detection

Author and tune Suricata signatures and YARA rules for malware, tooling, and TTP-specific patterns; correlate EVE alerts with flow context.

STACK Technical Expertise

Corelight Zeek Suricata PCAP NetFlow / IPFIX Grafana Prometheus InfluxDB Security Onion Gigamon (TAP / Packet Broker) Cisco Stealthwatch (NDR) Network Security Monitoring (NSM) Cross-Domain Solution (CDS) Snort YARA Sigma Rules JA3 / TLS Fingerprinting Wireshark / tshark Zero Trust (ZTNA) ForeScout NAC Splunk ES / SPL Palo Alto XSIAM / Cortex XDR Cortex XSOAR Elastic / KQL QRadar · ArcSight UEBA (Exabeam, Securonix) MITRE ATT&CK Kafka / Pulsar Cribl / Apache NiFi Python (Automation & APIs) Flask / FastAPI / REST Node.js / React Ansible / IaC GitHub Actions / CI-CD Bash / Linux Hardening AWS / Azure NIST CSF / RMF

CERTS Certifications

EC-Council Certified Ethical Hacker (CEH) GIAC Certified Incident Handler (GCIH) CompTIA Security+ CompTIA Network+ CompTIA A+ Red Hat Certified System Administrator (RHCSA) ArcSight Certified Administrator (ACIA) ArcSight Certified Security Analyst (ACSA) Cribl Certified User Cribl Certified Services Consultant Forcepoint Certified HS Guard Admin Forescout Certified Associate (FSCA)

PROFILE Education & Additional Information

Education

CCAF — Data/Voice Network Systems (Top Honors); Electronics & Communications (Honors)

Clearance

U.S. Top Secret / SCI (DoD) — Active 23 years

Languages

Bilingual English / Spanish

Work Mode

Remote / Hybrid / On-site · Open to relocation

Focus

NDR · NSM · Detection Engineering · Security Observability

Domains

DoD · Federal · Enterprise · Healthcare · Finance

HISTORY Professional Timeline

Feb 2025 – Present
Principal Cybersecurity Engineer / Co-Founder
Xbitium Technologies — Tampa, FL
Oct 2023 – Feb 2025 · 1.4 yrs
Sr. Cybersecurity Consultant & Solutions Architect
Palo Alto Networks | RedMatter Solutions — Tampa, FL / Arlington, VA
May 2017 – Sep 2023 · 6.3 yrs
Lead Cybersecurity Engineer & Architect
GDIT / Crystal Clear Technologies — U.S. CENTCOM HQ, MacDill AFB
Nov 2015 – Apr 2017 · 1.5 yrs
Lead Cybersecurity Engineer
Merlin International (HHS CSIRC) — Atlanta, GA
Aug 2014 – Nov 2015 · 1.3 yrs
Sr. Manager / SIEM SME
Protiviti Inc. (Fortune 500 Clients) — Atlanta, GA
Apr 2012 – Aug 2014 · 2.3 yrs
Sr. Manager / SIEM SME
Deloitte & Touche LLP (DISA Europe) — Stuttgart, Germany
Feb 2011 – Apr 2012 · 1.2 yrs
Sr. Information Assurance Engineer
AT&T GSI (USCENTCOM) — Arifjan, Kuwait
Jan 2009 – Feb 2011 · 2 yrs
NOSC Manager / Network Engineer
Defense Engineering Inc. (DTRA) — Arlington, VA
Aug 2006 – Jan 2009 · 2.5 yrs
Network Engineer
Mutual Telecom Services — Multiple Locations
Aug 2002 – Aug 2006 · 4 yrs
Network Specialist
U.S. Air Force (Active Duty) — Ramstein, Germany