> Markdown version of [/jobs/ext/2495668-tier-3-dco-watch-analyst](https://www.wearedevelopers.com/jobs/ext/2495668-tier-3-dco-watch-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Tier 3 DCO Watch Analyst - **Company:** BreakPoint Labs - **Location:** North Charleston, SC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Digital Forensics, Intrusion Detection Systems, Information Technology, 3-tier Architectures, Purple Team (Cyber Security) - **Published:** August 31, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9130921/tier-3-dco-watch-analyst ## About the Role 5 year's experience supporting CSSP or similar SOC technical role. - Comprehensive knowledge of CJCSM 6510.01B and incident response procedures. - In depth expertise with IDS/IPS solutions, including signature development and optimization. - Extensive experience performing digital forensics across multiple operating systems. Certifications Required: DoD 8570 IAT Level II certification and CSSP/CND certification required. Security Clearance Required: DoD Secret Education Level Required: Bachelor's Degree in Cybersecurity, Computer, Electrical, or Electronics Engineering, OR Mathematics with a concentration in computer science or equivalent ## Description BreakPoint Labs is seeking a Tier 3 DCO Watch Analyst responsible for leading complex incident response, conducting proactive threat hunting, and enhancing detection capabilities within a Cybersecurity Service Provider (CSSP) environment. The analyst oversees incident analysis, coordinates with internal and external stakeholders, leads purple team exercises, and drives improvements to detection and response capabilities. This position requires advanced expertise, operational leadership, and strict compliance with CJCSM 6510.01B standards. Required Responsibilities: - Lead incident response efforts, including analysis, mitigation, and reporting of significant incidents per CJCSM 6510.01B. - Manage incident response campaigns by developing strategies, coordinating multi-team efforts, and ensuring comprehensive resolution and reporting. - Conduct proactive threat hunting to identify advanced threats and network vulnerabilities. - Lead purple team exercises in collaboration with red and blue teams to evaluate and enhance detection and response capabilities. - Evaluate and refine detection mechanisms, including IDS/IPS signatures and log correlation rules, to improve accuracy and reduce false positives. - Perform advanced network and host-based digital forensics on Windows and other operating systems to support investigations. - Coordinate with reporting agencies and subscriber sites for comprehensive incident analysis and reporting. - Develop and maintain internal SOP documentation, ensuring alignment with CJCSM 6510.01B and applicable directives. - Work with a team to provide 24/7 support for incident response, including non-core hours, and mentor junior analysts. - Participate in program reviews, product evaluations, and onsite certification assessments. - Work four 10-hour shifts (Sunday-Wednesday or Wednesday Saturday); shift placement at management's discretion. - Surge support may be required to support incident response actions. - Up to 10% travel may be required, to include OCONUS locations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI Space Factories, Hacking Self-Driving Cars & Detecting Deepfakes](https://www.wearedevelopers.com/videos/1812-ai-space-factories-hacking-self-driving-cars-detecting-deepfakes) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)