| Agency: | City of Abilene |
|---|---|
| State: | Texas |
| Type of Government: | State & Local |
| NAICS Category: |
|
| Posted Date: | Mar 26, 2026 |
| Due Date: | May 1, 2026 |
| Solicitation No: | RFP CB-2621 |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
| Bid Number: |
RFP CB-2621
|
| Bid Title: |
SIEM SOAR TO Acquisition and Implementation
|
| Category: | City of Abilene Bids & Proposals |
| Status: | Open |
|
REQUEST FOR PROPOSAL
SIEM SOAR TO Acquisition and Implementation
RFP #CB-2621
The City of Abilene is an equal opportunity employer.
Enclosed is pertinent information for use in preparing your proposal. The procurement
timeline is:
RFP Issued: January 11, 2026
Questions Deadline: January 23, 2026 at 5:00 p.m.
Responses to Questions: January 30, 2026
Proposals Due: February 6, 2026 at 4:00 p.m.
ONE SIGNED ORIGINAL, single sided, unbound, plus three (3) complete copies of
your proposal must be submitted. In addition to the copies, a flash drive containing a PDF
copy of the complete proposal, including attachments, must also be provided.
For further information contact Purchasing at Melissa.Gorman@abilenetx.gov. All
correspondence should include the RFP number and title. Written correspondence and
proposal shall be delivered to:
City of Abilene
Attn: Melissa Gorman, Purchasing
555 Walnut St., Room 201A
Abilene, TX 79601
The City of Abilene reserves the right to reject any and all proposals and to waive any
informalities in procedures.
Sincerely,
Melissa Gorman
Division Manager - Purchasing
Table of Contents
1 GENERAL INFORMATION............................................................................................... 5
1.1 PURPOSE .....................................................................................................................................5
1.4 QUESTIONS ..................................................................................................................................6
1.5 PREPARATION COSTS .....................................................................................................................6
1.6 DOCUMENTS ................................................................................................................................6
1.7 TIME OF COMPLETION ....................................................................................................................6
1.8 PROPOSER'S QUALIFICATIONS ..........................................................................................................6
2 RULES GOVERNING COMPETITION .............................................................................. 7
2.1 EXAMINATION OF PROPOSALS ..........................................................................................................7
2.2 PROPOSAL ACCEPTANCE PERIOD .......................................................................................................7
2.3 CONFIDENTIALITY ..........................................................................................................................7
2.4 PROPOSAL FORMAT .......................................................................................................................7
2.5 SIGNATURE REQUIREMENTS .............................................................................................................7
2.6 PROPOSAL SUBMISSION REQUIREMENTS .............................................................................................8
2.6.1 ONE ORIGINAL, SINGLE SIDED UNBOUND, PLUS THREE (3) COMPLETE COPIES OF THE PROPOSAL MUST BE
RECEIVED BY THE CITY PRIOR TO THE DATE AND TIME SPECIFIED IN THE COVER LETTER. COPIES MAY BE BOUND OR ENCLOSED
IN FOLDERS/BINDERS. ......................................................................................................................................... 8
2.6.2 IN ADDITION TO THE COPIES REQUIRED BY PARAGRAPH 2.6.1 ABOVE, PROVIDE A FLASH DRIVE CONTAINING A
PDF COPY OF THE COMPLETE PROPOSAL, INCLUDING ATTACHMENTS. ......................................................................... 8
2.6.3 ALL COPIES OF THE PROPOSALS SHALL BE SUBMITTED IN A SINGLE SEALED COVER WHICH SHALL BE PLAINLY MARKED
AS A REQUEST FOR PROPOSAL RESPONSE WITH THE NUMBER AND TITLE PROMINENTLY DISPLAYED ON THE OUTSIDE OF THE
PACKAGE. ......................................................................................................................................................... 8
2.6.4 PROPOSALS MUST BE DELIVERED OR MAILED TO: ......................................................................................... 8
2.7 NEWS RELEASES ............................................................................................................................8
2.8 DISPOSITION OF PROPOSALS ............................................................................................................8
2.9 ORAL CHANGE/INTERPRETATION ......................................................................................................8
2.10 MODIFICATION/WITHDRAWAL OF PROPOSALS ......................................................................................8
2.11 LATE SUBMISSIONS .........................................................................................................................8
2.12 REJECTION OF PROPOSALS ................................................................................................................9
3 SCOPE OF WORK ........................................................................................................... 9
3.1 PROJECT OVERVIEW ..........................................................................................................................9
3.2 TECHNICAL REQUIREMENTS .................................................................................................................9
3.2.1 DISCOVERY, MIGRATION, AND TOOLS .......................................................................................................... 9
3.2.2 DATA RETENTION AND PERFORMANCE ......................................................................................................... 9
3.2.3 SECURITY AND COMPLIANCE ..................................................................................................................... 10
3.2.4 USER AND PERMISSION MAPPING ............................................................................................................. 10
2
3.3 VENDOR REQUIREMENTS AND QUALIFICATIONS ..................................................................................... 10
3.3.1 EXPERIENCE AND CERTIFICATIONS .............................................................................................................. 10
3.3.2 INTEGRATION EXPERIENCE ........................................................................................................................ 10
3.3.3 TRAINING AND CHANGE MANAGEMENT ..................................................................................................... 10
3.3.4 SUPPORT AND SLAS ................................................................................................................................ 11
3.3.5 SCALABILITY AND FUTURE-PROOFING ......................................................................................................... 11
3.4 COST STRUCTURE ............................................................................................................................ 11
3.5 CONTRACTOR DELIVERABLES ............................................................................................................. 11
3.6 PHASED APPROACH AND IMPLEMENTATION .......................................................................................... 11
3.6.1 IMPLEMENTATION PHASES ....................................................................................................................... 11
3.6.2 PHASE DELIVERABLES .............................................................................................................................. 12
3.7 PROJECT MANAGEMENT................................................................................................................... 12
3.8 ACCEPTANCE TESTING ...................................................................................................................... 12
4 PROPOSAL AND SUBMISSION REQUIREMENTS........................................................12
4.1 TITLE PAGE ................................................................................................................................ 12
4.2 TABLE OF CONTENTS .................................................................................................................... 13
4.3 LETTER OF TRANSMITTAL (LIMITED TO TWO (2) PAGES). ....................................................................... 13
4.3.1 BRIEFLY STATE YOUR FIRM'S UNDERSTANDING OF THE SERVICES TO BE PERFORMED AND MAKE A POSITIVE
COMMITMENT TO PROVIDE THE SERVICES AS SPECIFIED. ......................................................................................... 13
4.3.2 LIST YOUR COMPANY'S CONTACT FOR THIS RFP ALONG WITH THEIR PHONE NUMBER AND EMAIL ADDRESS. ........ 13
4.3.3 GIVE THE NAME(S) OF THE PERSON(S) WHO ARE AUTHORIZED TO MAKE REPRESENTATIONS FOR YOUR FIRM, THEIR
TITLES, ADDRESS, AND TELEPHONE NUMBERS ....................................................................................................... 13
4.3.4 THE LETTER OF TRANSMITTAL MUST BE SIGNED BY A CORPORATE OFFICER OR OTHER INDIVIDUAL WHO HAS THE
AUTHORITY TO BIND THE FIRM. .......................................................................................................................... 13
4.4 PROPOSAL SUBMITTAL ................................................................................................................. 13
4.4.1 FIRM QUALIFICATIONS AND EXPERIENCE .................................................................................................. 13
4.4.3 PROJECT MANAGER ............................................................................................................................. 13
4.4.4 KEY PROJECT STAFF AND SUBCONSULTANTS ............................................................................................. 13
4.4.5 PROJECT METHODOLOGY AND APPROACH ............................................................................................... 14
4.4.6 ADDITIONAL REQUIREMENTS ................................................................................................................. 14
4.5 PROPOSED COST ......................................................................................................................... 14
5 EVALUATION CRITERIA AND PROCESS .....................................................................14
5.1 EVALUATION CRITERIA WEIGHTING ................................................................................................. 14
5.2 EVALUATION PROCESS .................................................................................................................. 15
6 SELECTION PROCESS ..................................................................................................15
7 ATTACHMENTS ....................................................................................................................16
3
7.1 ATTACHMENT A ............................................................................................................................. 16
4
1 GENERAL INFORMATION
1.1 Purpose
The purpose of this Request for Proposal (RFP) is to identify and engage a qualified
vendor to provide and implement an enterprise-grade Security Information and Event
Management (SIEM) and Security Orchestration, Automation, and Response (SOAR)
solution. This solution will serve as the foundational component of our organization's
cybersecurity operations, providing centralized visibility, correlation, automated response,
and compliance reporting across our IT and security infrastructure.
The selected vendor will be responsible for delivering a comprehensive solution that
includes platform licensing, deployment services, integration with our existing security
and identity systems, user training, and post-implementation support.
1.2 Objectives
The primary objective of this initiative is to design and implement a fully operational
SIEM/SOAR platform that will:
Establish centralized monitoring, alerting, and incident response capabilities across on-
premises, cloud, and hybrid environments
Integrate with key components of the existing IT ecosystem, including Heimdal EDR,
Cisco Meraki, Microsoft 365, Azure AD, and on-prem Active Directory
Support compliance and auditing requirements aligned with standards such as NIST CSF,
CJIS, ISO 27001, HIPAA, and PCI-DSS
Provide robust correlation, investigation, and automation workflows to reduce response
time and improve analyst efficiency
Enable long-term scalability and adaptability through flexible architecture and support for
emerging technologies
The solution should enhance our ability to detect, respond to, and recover from
cybersecurity events in a structured and repeatable manner, while also serving as a tool
for ongoing risk reduction and compliance enforcement.
1.3 Background
Historically, our organization has not operated a centralized SIEM or SOAR platform.
Security monitoring and response activities have been conducted using a combination of
individual toolsets, manual workflows, and reactive processes. While sufficient for basic
operations, this approach has proven inadequate in meeting today's elevated threat
landscape and evolving compliance demands.
5
With increased regulatory expectations and a growing volume of distributed
infrastructure-including cloud services, hybrid identity, and remote endpoints-it has
become critical to adopt a cohesive and automated security operations framework.
The implementation of a SIEM/SOAR solution represents a strategic investment to:
* Strengthen our detection and response capabilities
* Improve visibility and accountability across our environment
* Enable consistent application of security policies and playbooks
* Satisfy internal and external compliance audit requirements
* Reduce operational overhead through intelligent automation
This RFP marks a major milestone in the development of a mature, scalable, and
defensible cybersecurity program.
1.4 Questions
Any questions regarding this Request for Proposal are to be submitted electronically to:
Melissa Gorman, Division Manager, Purchasing
melissa.gorman@abilenetx.gov
For ease of identification, please identify the RFP number in the subject line of any
correspondence.
Purchasing Office hours of operation are: 8:00 a.m. to 5:00 p.m. local time Monday
through Friday, excluding City holidays. All questions must be received prior to the
deadline indicated on the RFP cover letter.
1.5 Preparation Costs
The City will not be responsible for proposal preparation costs, nor for costs including
attorney fees associated with any (administrative, judicial, or otherwise) challenge to the
determination of the highest ranked Proposer and/or award of contract and/or rejection of
proposal. By submitting a proposal each Proposer agrees to be bound in this respect
and waives all claims to such costs and fees.
1.6 Documents
The availability of digital procurement and contracting documents can be obtained by
email after January 11, 2026, by contacting Melissa Gorman, Division Manager -
Purchasing at melissa.gorman@abilenetx.gov.
1.7 Time of Completion
Successful proposer shall begin the work immediately following the award of a final
contract and Purchase Order and to be completed by September 30, 2026. City of
Abilene will consider alternate time frames within these limits.
1.8 Proposer's Qualifications
Proposers must be properly licensed under the laws governing their respective trades.
6
2 RULES GOVERNING COMPETITION
2.1 Examination of Proposals
Proposers should carefully examine the entire RFP and any addenda thereto, and all
related materials and data referenced in the RFP. Proposers should become fully aware
of the nature of the work and the conditions likely to be encountered in performing the
work.
2.2 Proposal Acceptance Period
Award of this proposal is anticipated to be announced within 60 calendar days, although
all offers must be complete and irrevocable for 90 calendar days following the submission
date.
2.3 Confidentiality
Subject to Texas state law, the content of all proposals will be kept confidential until the
contract is awarded. If a proposer wishes individual pages, which contain actual business,
proprietary information to be held confidential, each page must be marked, and an
explanation furnished of its proprietary nature. In addition to marking individual pages,
the Proposal's Cover must also be annotated with the words "THIS PROPOSAL
CONTAINS PROPRIETARY INFORMATION". "Confidential and Proprietary" information
is not meant to include any information which, at the time of disclosure, is generally known
by the public and/or competitors. Disclosure of proprietary information is governed by
Texas State law and is subject to the determination of the Texas Attorney General's
Office.
2.4 Proposal Format
Proposals are to be prepared in such a way as to provide a straightforward, concise
delineation of the Proposer's capabilities to satisfy the requirements of this RFP.
Emphasis should be concentrated on
1) Conformance to the RFP instructions.
2) Responsiveness to the RFP requirements.
3) Completeness and clarity of content.
2.5 Signature Requirements
All proposals must be signed. Proposals must be signed: by an officer or other agent of
a corporate vendor, if authorized to sign contracts on its behalf; a member of a
partnership; the owner of a privately-owned vendor; or other agent if properly authorized
by a power of attorney or equivalent document. Signature on the "Letter of Transmittal"
(See Para 4.3.4) will meet this requirement.
Failure to sign the Proposal is grounds for rejection. The name and title of the individual(s)
signing the proposal must be clearly shown immediately below the signature.
7
2.6 Proposal Submission Requirements
2.6.1 ONE ORIGINAL, single sided unbound, plus three (3) complete copies of the
proposal must be received by the City prior to the date and time specified on the cover
letter. Copies may be bound or enclosed in folders/binders.
2.6.2 IN ADDITION to the copies required by paragraph 2.6.1 above, provide a flash
drive containing a PDF copy of the complete proposal, including attachments.
2.6.3 All copies of the proposals shall be submitted in a single sealed cover which shall
be plainly marked as a Request for Proposal Response with the Number and Title
prominently displayed on the outside of the package.
2.6.4 Proposals must be delivered or mailed to:
Physical Address
CITY OF ABILENE
ATTN: MELISSA GORMAN - PURCHASING
555 WALNUT ST., ROOM 201A
ABILENE, TX 79601
2.7 News Releases
News releases by or on the behalf of any Proposer pertaining to the award resulting from
the RFP shall not be made without prior written approval of the City Purchasing Officer.
2.8 Disposition of Proposals
All materials submitted in response to this RFP will become the property of the City of
Abilene.
2.9 Oral Change/Interpretation
No oral change or interpretation of any provision contained in this RFP is valid whether
issued at a pre-proposal conference or otherwise. Written addenda will be issued when
changes, clarifications, or amendments to proposal documents are deemed necessary
by the City.
2.10 Modification/Withdrawal of Proposals
A Proposer may withdraw a proposal at any time prior to the final submission date by
sending written notification of its withdrawal, signed by an agent authorized to represent
the agency. A submitted proposal cannot be changed or withdrawn after the submission
date, except for modifications requested by the City after the date of receipt and following
oral presentations.
2.11 Late Submissions
PROPOSALS NOT RECEIVED BY THE DATE AND TIME AND AT THE LOCATION
SPECIFIED IN THE RFP COVER LETTER WILL NOT BE CONSIDERED AND WILL BE
RETURNED UNOPENED.
8
2.12 Rejection of Proposals
The City of Abilene reserves the right to reject any or all proposals if determined to be in
the best interest of the City.
3 SCOPE OF WORK
3.1 Project Overview
This Request for Proposal (RFP) seeks qualified vendors to provide, deploy, and integrate
an enterprise-grade Security Information and Event Management (SIEM) and Security
Orchestration, Automation, and Response (SOAR) solution.
Our organization currently lacks a centralized SIEM/SOAR platform. The purpose of this
project is to establish a unified security operations capability that enables real-time threat
detection, automated incident response, and centralized visibility across our hybrid
infrastructure.
The selected vendor will provide a turnkey solution that includes software licensing,
deployment, integration, role-based training, documentation, and post-implementation
support. Integration with our hybrid identity environment (Azure Active Directory and on-
premises Active Directory) and Microsoft 365 (M365) is critical to project success.
3.2 Technical Requirements
3.2.1 Discovery, Migration, and Tools
- Conduct a full assessment of the current IT and security landscape, identifying critical
systems, existing log sources, and visibility gaps.
- Deploy the SIEM/SOAR platform, including infrastructure provisioning (cloud, on-
premises, or hybrid), log pipeline configuration, and baseline use case deployment.
- Prioritize integrations as follows:
- Required parsing support for: Azure AD, on-prem AD, M365 (Exchange, Teams,
SharePoint), Heimdal EDR, Cisco Meraki, and core firewall(s).
- Future Log Sources (Phase 2+): Identity management platforms, additional or
replacement EDR solutions, and third-party SaaS tools.
- Use vendor-recommended or supported connectors and tools for log parsing,
normalization, and onboarding.
- Provide architecture diagrams, integration mappings, and configuration
documentation.
3.2.2 Data Retention and Performance
- Log Retention Requirements: Minimum of 30-90 days hot storage, 12 months warm
storage, and 5 years cold storage, with options for extended retention if required by
regulation.
- Performance Thresholds: The proposed platform must support an initial throughput of
up to 5,000 events per second (EPS), scalable to at least 15,000 EPS within three
9
years. Vendors should specify hardware or cloud resource sizing to meet these
thresholds.
- Include compression ratios, indexing strategies, and storage growth estimates in the
technical proposal.
3.2.3 Security and Compliance
- Align with NIST CSF, CJIS, HIPAA, and PCI-DSS requirements.
- Ensure encryption in transit and at rest, immutable log storage, and verifiable audit
trails.
- Provide customizable dashboards and compliance reporting with exportable data.
- Confirm all vendor personnel with potential access to CJIS data possess or can obtain
CJIS-level clearance or equivalent background checks prior to access.
3.2.4 User and Permission Mapping
- Support hybrid identity federation with Azure AD and Active Directory.
- Implement granular Role-Based Access Control (RBAC) for administrators, analysts,
and auditors.
- Utilize identity enrichment and correlation for improved event context and detection
fidelity.
3.3 Vendor Requirements and Qualifications
3.3.1 Experience and Certifications
- Provide at least three examples of comparable SIEM/SOAR deployments within hybrid
environments of similar scale (log volume, EPS, and integration complexity).
- Include staff certifications relevant to the proposed solution, such as CISSP, CISM,
GIAC, or vendor-specific credentials (e.g., Microsoft, Splunk, IBM, Palo Alto, etc.).
- Identify key project personnel and their certifications, roles, and project responsibilities.
3.3.2 Integration Experience
- Demonstrate successful integrations with:
- Azure AD / on-prem AD (hybrid identity)
- Microsoft 365 services (Exchange, Teams, SharePoint, OneDrive)
- Heimdal EDR, Cisco Meraki, and comparable platforms
- List available native connectors and describe any customization required to achieve
full ingestion and correlation.
3.3.3 Training and Change Management
- Deliver role-based training programs tailored for administrators, analysts, and IT staff.
- Minimum required training:
- Administrators: 12 hours
- Security Analysts: 16 hours
- IT/Helpdesk Staff: 8 hours
- Provide training deliverables, including:
- Recorded sessions and presentation materials
- Hands-on playbook development labs
10
With Free Trial, you can:
You will have a full access to bids, website, and receive daily bid report via email and web.
Project: RFI/Sources Sought - P-Card Commercial Card Compliance Solution Ref. #: 26-0208 Type:
City of Fort Worth
Bid Due: 8/10/2026
Project: Multifamily Developer Partner(s) for Bivens Place Apartments Ref. #: RFQ No. 2026-203
Fort Worth Housing Solutions
Bid Due: 8/11/2026
Bid #. Bid Title Addendums Closing Date Closing Time Buyer 2425-003-2029-A Online Only
Eagle Mountain-Saginaw Independent School District (EMS ISD)
Bid Due: 7/31/2026
Bid #. Bid Title Addendums Closing Date Closing Time Buyer 2425-003-2029-A Online Only
Eagle Mountain-Saginaw Independent School District (EMS ISD)
Bid Due: 7/31/2026