Cyber Operations Analyst (TS/SCI)

Zachary Piper
Fort Meade, MD, United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$120,000.0 - $180,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Computer Networks Intrusion Detection Systems Network Security Pcap Network Monitoring Network Service ArcSight SIEM Tool Red Team (Cyber Security) Security Information and Event Management Malware
+4 more
Firewalls (Computer Science) Cyber Warfare Splunk Vulnerability Analysis

Job description

  • Coordinate Computer Network Defense (CND) efforts across DoD Component Commands, Services, Agencies, and Field Activities (CC/S/A/FA), and track and report how DCO-IDM operations affect their missions.
  • Provide the Intelligence Community (IC) with priority intelligence requirements (PIRs) and indications-and-warning needs related to potential threats targeting DoD information systems and networks.
  • Centrally manage and/or recommend CND operations that influence more than one DoD Component.
  • Deliver Defense-wide situational awareness and attack sensing and warning by integrating, analyzing, and synchronizing information flows.
  • De-conflict Vulnerability Analysis and Assessments (VAA) and Red Team operations with ongoing CND activities, and advise on adjustments to current or planned VAAs that could adversely impact CND missions.
  • Monitor the DoDIN for Information Assurance Vulnerability Alert (IAVA) compliance and evaluate its implications on overall network defense.
  • Develop a unified curriculum for CND education, training, awareness, and professional development, and ensure its application throughout the CNDS certification and accreditation processes.
  • Ensure that all Computer Network Defense Service (CNDS) providers maintain continuous information sharing and operate in a coordinated manner-executing a shared Course of Action (COA) with the ability to transition to a new COA as directed. CNDS provider coordination is primarily conducted through CNDS Certification Authorities (CNDS/CAs) under USCYBERCOM direction.
  • Recommend changes to Information Operations Conditions (INFOCON) in response to unauthorized activities-such as network attacks, exploitation, or misuse-to reduce risk and limit potential damage to DoD systems and networks.
  • Maintain expert knowledge of DoD Computer Network Defense, including understanding network threat lifecycles, attack vectors, and methods of exploiting vulnerabilities.

Requirements

  • Bachelors degree in related discipline and 4+ years of professional IT and cyber security experience
  • Experience utilizing network monitoring/SIEM tools: ArcSight, CSAAC, Splunk, PCAP
  • Experience working with CNDS providers or working in a CNDSP
  • Technical understanding of network communication using TCP/IP protocols, system administration, malware, Computer Network Defense Operations (Proxy, Firewall, IDS/IPS), Joint Operational Planning
  • Experience supporting security operations center, providing and briefing senior leaders on threats and mitigation strategies

Benefits & conditions

  • Total compensation based on experience level - $120,000-$180,000+ based on experience level
  • Full Benefits: PTO/Holidays, Cigna Medical, Dental, and Vision, 401k with ADP
  • Certification reimbursement
  • Contract stability funded through 2030

LI-MK1 #LI-Onsite

LI-MK1 #LI-Onsite

Keywords: Threat detection, incident response, security event analysis, SIEM monitoring, log correlation, threat hunting, alert triage, intrusion detection, anomaly detection, Splunk, QRadar, ArcSight, Elastic Stack, Splunk, IDS, TCP, IP, TS/SCI, Top secret, polygraph, Federal, government, DoD, clearance, W2, hiring, opentowork, Maryland, PCAP, Wireshark, vulnerability, ACAS, briefing, Wireshark, SOC, security operations center, Sentinel, dashboard creation, log parsing, security automation, playbook execution, SOAR integration, network forensics, endpoint monitoring, malware analysis, vulnerability scanning, vulnerability assessment, Nessus, Tenable.sc, Qualys, Rapid7 InsightVM, risk scoring, patch validation, CVE analysis, CVSS evaluation, vulnerability prioritization, threat intelligence integration, MITRE ATT&CK mapping, IOC enrichment, packet analysis, firewall log review, IDS/IPS tuning, endpoint detection and response (EDR), compliance monitoring, IAVA tracking, DoDIN visibility, configuration baseline review, security hardening, remediation coordination, security reporting, adversary behavior analysis

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

52 sec

Defining application, pipeline, and security operations roles

Aarno Aukia · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

1:23 min

Understanding the complexity of cybersecurity domains

Jennifer Reif · LIVE

Videos

See all

Related articles

See all