> Markdown version of [/jobs/ext/2585803-defensive-cyber-operations-dco-analyst-ogden-utah](https://www.wearedevelopers.com/jobs/ext/2585803-defensive-cyber-operations-dco-analyst-ogden-utah). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Defensive Cyber Operations (DCO) Analyst Ogden, Utah - **Company:** BuddoBot Inc. - **Location:** Ogden, UT, United States - **Experience:** Experienced - **Salary:** $90,000.0 - $145,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Apache Lucene, Computer Forensics, Continuous Integration, Query Languages, Elasticsearch, Monitoring of Systems, Issue Tracking Systems, Intrusion Detection and Prevention, Machine Learning, Red Hat Enterprise Linux, Logstash, Ansible, Kusto Query Language, Software Engineering, Software Requirements Analysis, Software Vulnerability Management, Privacy Controls, EndPointSecurity, Cyber Threat Analysis, Amazon Virtual Private Cloud (VPC), Gitlab, Infrastructure Automation Frameworks, Information Technology, Cybercrime, Kibana, Terraform, Cyber Warfare, Splunk, Scap Compliance Checker, SentinelOne Expertise, Software Version Control, Devsecops, Elk Stack - **Published:** August 21, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18025990?backUrl=%2Fcareer%2F18025990%2FDefensive-Cyber-Operations-Dco-Analyst-Ogden-Utah-Utah-Ogden ## About the Role * 4+ years of relevant cybersecurity experience, including direct SOC / vSOC / CSSP incident response experience. * 2+ years of hands-on experience using Splunk Enterprise and ELK Stack (Elasticsearch, Logstash, Kibana) for event correlation and threat detection. * Direct experience monitoring, ingesting, and analyzing security telemetry within AWS GovCloud environments (e.g., CloudTrail, VPC Flow Logs, AWS GuardDuty). * Hands-on experience utilizing GitLab (e.g., source control, CI/CD pipelines, issue tracking, or DevSecOps workflows). * 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures to include assessment and authorization activities. * Department of Defense Directive (DoDD) 8140 / 8570 IAT CSSP Certification must be obtained prior to hire (CEH, Security+, GCIH, CySA+ or Equivalent). * Bachelor's degree in Computer Science, Information Technology, or a related field. * US Citizenship and an active Top Secret/SCI security clearance required., * Experience with AI/ML security tools (e.g., generative AI for query generation, automated threat intelligence, or AI-driven behavioral analytics). * AWS Certified Security - Specialty certification. * Splunk Core Certified Power User / Admin or Elastic Certified Analyst certifications. * Experience writing search queries using SPL (Splunk Processing Language) and KQL/Lucene (Kibana Query Language). * Experience with SentinelOne (or similar EDR platforms) for endpoint detection, threat hunting, and automated remediation. * Familiarity with Infrastructure-as-Code (IaC) tools such as Terraform or Ansible within a DevSecOps environment. * Experience performing cybersecurity activities in support of software and system requirements, design, development, testing, and sustainment. * Experience with HBSS, ACAS, SCAP Compliance Checker (SCC), DISA STIGs. * Working knowledge of NIST 800-53 Security and Privacy Controls. * Experience with various operation systems such as RHEL and Windows. * Experience in performing post-incident computer forensics without destruction of critical data. * Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff. ## Description Dark Wolf Solutions is looking for a Defensive Cyber Operations Analyst who will perform continuous system monitoring to identify malicious cyber-attacks while supporting the containment and remediation of IT threats. This role will function as an operator responsible for hands-on incident response, correlation, and threat detection both on-premise using ELK and across AWS GovCloud environments using Splunk Enterprise. Additionally, this position will leverage Artificial Intelligence (AI) and Machine Learning capabilities to enhance threat detection, streamline incident analysis, and accelerate response actions across monitored networks and applications. This role will be fully on-site at Hill AFB in Ogden, Utah., * Active monitoring, detection, and analysis across on-prem (ELK) and cloud-hosted AWS GovCloud (Splunk Enterprise) environments. * Utilize AI-assisted analysis, automation, and correlation of data from various log sources to triage security events, detect anomalies, and reduce response times for complex threats. * Vulnerability Management actions to include providing recommendations and implement mitigations. * Conduct intrusion analysis and correlation of unauthorized activities; provide and implement recommendations to improve detection and customer mitigation processes. * Participate in the Root Cause Analysis process and documentation capturing efforts taken to mitigate unauthorized actions. * Participate in the development of DCO tactics, techniques, and procedures (TTPs) and supporting documentation. * Identify security discrepancies and report and respond to security incidents. * Provide research and analysis in support of expanding programs and areas of responsibility. * Draft documentation for briefings, reports, and informational analyses. * Participate in customer exercises (after duty hours may be required). * Adhere to defined policies, master plans and schedules. * Complete all initial and annual training requirements and disclosures as outlined by BSTG. * Perform all other duties as required, consistent with the goals, objectives, and responsibilities of the department. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Debug a Kubernetes Operator](https://www.wearedevelopers.com/videos/487-debug-a-kubernetes-operator) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [DevOps Engineer Salary [2023]](https://www.wearedevelopers.com/magazine/203-devops-engineer-salary-2023) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)