Blue Team Lead and Senior Cyber Defense Analyst

Strategic Inc
United States
1 day ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Network Analysis CompTIA Security+ Computer Telephony Integration Intrusion Detection Systems Network Security Network Monitoring Comptia Pentest+ CE Security Information and Event Management In-Plane Switching (IPS) SC Clearance Information Technology Cybercrime
+4 more
Tools for Reporting Cyber Warfare Blue Team (Cyber Security) Vulnerability Analysis

Job description

Strategic Operational Solutions (STOPSO) is seeking a Blue Team Lead and Senior Cyber Defense Analyst to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Lead Blue Team monitoring, detection, incident response coordination, and integrated assessment execution. The lead manages analyst coverage, escalation, technical quality, and operational readiness for the DCOMSS mission., · Direct daily Blue Team operations, tiered watch coverage, shift handoffs, priorities, and analyst escalation.

· Coordinate incident response, threat hunting, detection-content development, and defensive tooling with technical staff.

· Maintain Blue Team SOPs, playbooks, quality reviews, training, and response readiness.

· Review significant investigations and ensure timely, accurate operational reports and customer coordination.

· Integrate vulnerability assessment, CTI, tooling, exercises, and surge requirements with steady-state coverage.

· Track staffing, qualifications, access, and performance issues; mentor analysts and drive corrective actions.

· Perform other duties as assigned consistent with the position’s responsibilities, qualifications, clearance, and authorized scope., Leads Blue Team personnel, assigns operational work, reviews quality, and provides coaching and performance input consistent with company authority.

Work Environment and Physical Requirements

Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays.

Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.

Travel

Occasional local, CONUS, or OCONUS travel may be required for authorized mission activities, exercises, assessments, or conferences.

Requirements

· Minimum 5 years of documented relevant experience. Documented specialized operational experience in the cyber functional area in a DoD or enterprise IT environment; cybersecurity analysis, incident response, network monitoring, threat hunting, analyst escalation, and defensive tooling.

· DoD Cyber Workforce Framework (DCWF) 511, Cyber Defense Analyst, Intermediate proficiency. Additional DCWF 521 infrastructure support or 531 incident responder qualification is required if those duties are formally assigned.

· Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.

· Current matrix-listed certification options for 511 Intermediate: CEH(P), Cloud+, FITSP-O, GCED, GDSA, GMON, GRID, GSEC, PenTest+, Security+.

Knowledge, Skills and Abilities

· Demonstrated knowledge of Cyber defense analysis, incident response, network security monitoring, threat hunting, defensive tooling, and technical leadership.

· Proficiency with SIEM, EDR, IDS/IPS, network analysis, incident-management, and reporting platforms appropriate to assigned duties and approved access.

· Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.

· Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.

· Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.

Preferred Qualifications

· Current matrix-listed certification options for 521 Intermediate: CEH, Cloud+, CySA+, GMON, GRID, GSEC, PenTest+, SSCP, Security+.

· Current matrix-listed certification options for 531 Advanced: CBROPS, CCSP, CEH, CEH(P), Cloud+, ECIH, FITSP-O, GCED, GCIH, GRID, GSEC, PenTest+, RCCE Level 1, Security+

· Experience leading tiered DoD cyber defense operations and integrated assessments.

· Relevant DoD or enterprise IT experience with mission tooling and operational reporting.

Security Clearance

Active SECRET clearance and ability to maintain assigned system access. U.S. citizenship is required.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:11 min

Securing heterogeneous legacy payment infrastructure against AI

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

46 sec

Using LLMs to reverse engineer undocumented legacy code

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Videos

See all

Related articles

See all