Skip to content
Home » Federal Cybersecurity Capabilities | SIEMtune SDVOSB

Federal Cybersecurity Capabilities | SIEMtune SDVOSB

SIEMtune

Cut Through the Noise. Tune Your SIEM. Empower Your SOC.
SDVOSBVOSBHUBZone • Small Business
CAGE 14U14 • UEI E5GUTKXV71L1
siemtune.com • john@siemtune.com

Company Overview

CSITCO LLC (dba SIEMtune) is an SBA-certified Service-Disabled Veteran-Owned
and HUBZone Small Business delivering specialized SIEM engineering, detection content,
and SOC enablement for federal, state, and commercial clients. Founded by a U.S. Air Force
veteran and Principal Cyber Architect, SIEMtune pairs deep SIEM expertise with
AI-augmented tuning and detection engineering to transform raw logs,
noisy alerts, and complex integrations into precise, actionable intelligence —
delivering measurable data-ingestion cost reductions and
substantial improvements in threat-detection fidelity.

Core Competencies

  • AI-Augmented SIEM Tuning & Detection — LLM-assisted parser/rule generation, ML-driven false-positive reduction, embedding-based alert triage
  • Enterprise SIEM Architecture & Engineering — on-prem, Azure GCC / GCC High, multi-cloud
  • Multi-Enclave Architecture — cross-classification, cross-region, multi-tenant
  • Custom Detection Engineering — Sigma, KQL, SPL, LUA, ESPER; MITRE ATT&CK-mapped
  • Alert Tuning & FP Reduction — measurable analyst-hour recovery
  • Data Pipeline & Log Normalization — Cribl, custom parsers, taps/Gigamon, syslog
  • Security Platform Integration — Defender XDR, CrowdStrike, Palo Alto, NetWitness
  • CMMC 2.0 & FedRAMP Compliance Engineering
  • Firewall Engineering — Palo Alto build, migration, rule lifecycle
  • Threat Hunting, Triage & IR Support
  • SOC Training & Knowledge Transfer — former USAF cyberspace instructor

Differentiators

  • 25+ years in cybersecurity (since 2001), SIEM-specialized across Splunk, Sentinel, Devo, NetWitness, ArcSight, QRadar, Elastic, CrowdStrike, Cribl
  • CISO-level engagement — translates executive intent into tuned content and SOC outcomes
  • USAF Undergraduate Cyberspace Training plank owner (Block 3, Defense) — codified training methodology
  • Active Top Secret clearance; Service-Disabled Veteran
  • AI-accelerated results — applied use of LLMs and ML for parser generation, log normalization, and FP triage; advanced AI/ML coursework at The George Washington University (M.Eng., in progress)
  • Vendor-agnostic — we tune the platform you own; no resale dependency

Platforms

Microsoft Sentinel / GCC High
Splunk
Devo
RSA NetWitness
ArcSight
QRadar
Elastic
CrowdStrike
Cribl
Palo Alto
Defender XDR
Carbon Black

NAICS Codes

NAICSDescription
541512Computer Systems Design Services (primary)
541519Other Computer Related Services (Information Assurance / Cybersecurity)
541611Administrative Management & General Management Consulting
541690Other Scientific & Technical Consulting Services
541715R&D in the Physical, Engineering & Life Sciences
518210Computing Infrastructure Providers, Data Processing & Hosting
611420Computer Training
611430Professional & Management Development Training

PSC / Federal Service Codes

PSCDescription
D310IT & Telecom — Cyber Security and Data Backup
D307IT & Telecom — IT Strategy and Architecture
D308IT & Telecom — Programming
DA10IT & Telecom — Cybersecurity Strategy and Plans Services
DA01IT & Telecom — IT Management Support
R425Support — Professional: Engineering and Technical
U012Education/Training — IT / Cybersecurity Training

Certifications & Status

  • SDVOSB — Service-Disabled Veteran-Owned Small Business, SBA certified effective 07/08/2026
  • VOSB — Veteran-Owned Small Business, SBA certified effective 07/08/2026
  • HUBZone — SBA HUBZone Program, certified effective 07/08/2026
  • Small Business under all NAICS above
  • SAM.gov: Active  •  CAGE 14U14  •  UEI E5GUTKXV71L1
  • Principal clearance: Top Secret

Industries & CISA Critical-Infrastructure Sectors Served

Government Facilities
Financial Services
Healthcare & Public Health
Energy
Critical Manufacturing
Food & Agriculture
Communications
International Organizations
Federal R&D
CSITCO LLC dba SIEMtune  •  John Tyson, Principal Cyber Architect
siemtune.com  •  john@siemtune.com  •  linkedin.com/in/siemtune

SIEMtune
Past Performance & Multi-Enclave Engineering
SDVOSBVOSBHUBZone • Small Business
CAGE 14U14 • UEI E5GUTKXV71L1
NAICS primary 541512

Past Performance — Spotlight Engagements

Past performance history of SIEMtune’s principal while serving as Cyber Defense Engineer / Principal Cyber Security Systems Engineer at Raytheon (RTX) / Raytheon Foreground Security and as Principal Cyber Architect at Nightwing. Contract vehicle and engagement details available upon request.

U.S. Government Publishing Office (GPO)
Federal / Government Facilities • Washington, DC
Scope: SIEM tuning, detection content, and log-source onboarding for a legislative-branch agency supporting secure-credential production (U.S. passports) and official government publications.
International Monetary Fund (IMF)
International Organization • Washington, DC
Scope: SIEM engineering and detection content development for an international financial institution with sovereign-level threat exposure. Engineered log-source integrations across the TCP/IP stack — taps/Gigamon, syslog brokers, agent and API sources.
Micron Technology
Critical Manufacturing (Semiconductors) • Boise, ID
Scope: SIEM content engineering and threat-hunting support across a global memory-manufacturing footprint with geopolitically sensitive supply chain (CHIPS Act recipient).
Planned Parenthood Federation of America (PPFA)
Healthcare & Public Health • New York, NY
Scope: SIEM tuning, exploit-triage support, and detection-content engineering for a national non-profit with an elevated targeted-threat profile.

Additional Clients Served (via RTX / Nightwing primes)

Federal / Public Sector
Georgia Technology Authority (GTA) • ASRC Federal • Chemonics International
International / R&D
SRI International
Financial Services
FSARC / ARC • Genworth Financial • Perella Weinberg Partners • Close Brothers Group (UK)
Healthcare & Life Sciences
Vertex Pharmaceuticals • Takeda (Baxalta / Shire)
Critical Manufacturing
Intel Corporation • onsemi
Energy & Utilities
Dominion Energy
Retail / Telecom
Ahold Delhaize • MetTel

Multi-Enclave Architecture & Engineering — Concrete Example

Program: Splunk → Devo SIEM migration and consolidation across 30+ distributed customer enclaves (Raytheon Foreground Security managed-defense portfolio).

Architecture: Designed and engineered a multi-enclave SIEM topology spanning 30+ customer environments — each with its own data-classification posture, regulatory regime (HIPAA, NERC-CIP, SOX, FISMA, sovereign-IO), and tooling baseline (Splunk, RSA NetWitness, Microsoft Sentinel/GCC High). Built ingest pipelines from taps and Gigamon aggregation through syslog brokers and Cribl streams into per-tenant SIEM instances, with centralized detection-content governance and per-enclave content overrides.

Engineering: Tenant-isolated Devo/Splunk indexes per enclave; Cribl pipelines for source normalization and routing; zero-gap migration of customer-specific parsers, dashboards, and rules; Carbon Black → Splunk Cloud integrations across the same footprint; EternalBlue remediation across affected enclaves; CISO/IT coordination for log-source onboarding up the TCP/IP stack.

Relevance: Production experience designing and engineering SIEM/SOC across heterogeneous classification, regulatory, and platform boundaries — directly applicable to DoD multi-enclave (NIPR/SIPR/JWICS), GCC/GCC High federal tenants, and commercial multi-region deployments.

CSITCO LLC dba SIEMtune  •  John Tyson, Principal Cyber Architect  •  SDVOSB • VOSB • HUBZone
CAGE 14U14  •  UEI E5GUTKXV71L1  •  siemtune.com  •  john@siemtune.com