> Markdown version of [/jobs/ext/926279-intrusion-detection-team-lead-3rd-shift](https://www.wearedevelopers.com/jobs/ext/926279-intrusion-detection-team-lead-3rd-shift). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Intrusion Detection Team Lead - 3rd shift - **Company:** GovCIO - **Location:** Des Moines, IA, United States - **Experience:** Expert - **Salary:** $150,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Networks, Web Servers, Intelligence Analysis, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Log Analysis, Raw Data, Security Information and Event Management, Data Logging, Snort (Software), Firewalls (Computer Science), Cybercrime, Grep, Epic ECSA, Splunk - **Published:** June 19, 2026 - **Apply:** https://dejobs.org/x/x/70742590EDB243B4BBE20C787B9B9D5B/job/ ## About the Role * Bachelor's and 8 years of intrusion detection experience * Minimum Relevant Experience - The requirement states: 7 years of security intrusion detection examination experience involving a range of security technologies that produce logging data; to include wide area networks host and network IPS/IDS/HIPs traffic event review, server web log analysis, raw data logs. Working experience of Splunk SIEM. Contractor will have at least two years as a cyber security or security operations shift team leader. At least five years' experience working at a senior level, performing analytics examination of logs and console events in the following working experience areas of; creating advance queries methods in Splunk or advance Grep skills, firewall ACL review, examining Snort based IDS events, Pcaps, web server log review, and working in a SIEM environment. * Required Certification - The requirement states: Must possess at least one (1) of the following certifications: GIAC Certified Intrusion Analyst (GCIA), EC-Council's Certified Security Analyst (ECSA), GIAC Certified Perimeter Protection Analyst (GPPA), GIAC Certified Enterprise Defender (GCED), Systems Security Certified Practitioner (SSCP), or a Certified Information Systems Security Professional (CISSP). Splunk Fundamentals I & II certification., * A valid photo ID must be presented during each interview * During the Hiring Process * Enhanced Biometrics ID verification screening * Background check, to include: * Criminal history (past 7 years) * Verification of your highest level of education * Verification of your employment history (past 7 years), based on information provided in your application ## Description * Collaborates with intrusion analysts to identify, report on, and coordinate remediation of cyber threats to the client * Provides timely and actionable sanitized intelligence to cyber incident response professionals * Leverages technical knowledge of computer systems and networks with cyber threat information to assess the client's security posture * Conducts intelligence analysis to assess intrusion signatures, tactics, techniques and procedures associated with preparation for and execution of cyber attacks * Researches hackers, hacker techniques, vulnerabilities, exploits, and provides detailed briefings and intelligence reports to leadership ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing Clarity to Event Streams: Enabling Analytics and AI Through Rich Metadata](https://www.wearedevelopers.com/videos/1616-bringing-clarity-to-event-streams-enabling-analytics-and-ai-through-rich-metadata) - [Why Your AI Agent Keeps Hallucinating Your Data: Building Deterministic Context Layers](https://www.wearedevelopers.com/videos/2055-why-your-ai-agent-keeps-hallucinating-your-data-building-deterministic-context-layers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)