Action Officer
Sentar is an employee-owned company fostering a culture of empowerment, collaboration, and innovation. We develop critical talent to create solutions addressing the convergence of cybersecurity, intelligence, analytics, and systems engineering.
About the role
The Cyber Operations Center (CyOC) Action Officer will support the mission-critical efforts of the Defense Health Agency (DHA) by enabling proactive cybersecurity operations that protect sensitive healthcare systems across the Department of Defense (DoD). This role is embedded within the Naval Information Warfare Center (NIWC) Atlantic's Defensive Cyberspace Operations (DCO) Integrated Product Team (IPT), safeguarding DHA’s global infrastructure against cyber threats, unauthorized access, and emerging vulnerabilities.
As part of the CyOC team, the Action Officer serves as a key operational resource, working directly with DHA subscribers to receive, triage, and respond to Requests for Information (RFIs) related to cybersecurity threats and incidents. This includes performing detailed threat analysis, coordinating with cross-functional intelligence teams, and delivering actionable intelligence reports to bolster the defense posture of supported entities. The role supports frontline military medical operations and critical DoD health IT systems, ensuring mission continuity, data protection, and the safety of warfighters and beneficiaries.
This position requires a Top Secret/SCI clearance, strong knowledge of DoD cyber policy, and a proven ability to analyze and communicate complex threat intelligence in a dynamic, fast-paced environment where analytical precision, rapid response, and interagency collaboration are essential.
Responsibilities
- Receive, assess, and triage incoming Requests for Information (RFIs) from DHA subscribers.
- Conduct detailed research and threat analysis on cyber incidents, indicators, and adversary activity.
- Develop and deliver concise, accurate, and actionable intelligence reports tailored to subscriber needs.
- Collaborate with internal CyOC analysts, incident responders, and threat intelligence teams to ensure comprehensive RFI responses.
- Maintain situational awareness of current and emerging cyber threats, vulnerabilities, and attack techniques.
- Support the development, documentation, and refinement of RFI processing workflows and standard operating procedures (SOPs).
- Provide technical guidance to subscribers regarding cyber threat mitigation and security best practices.
- Track RFI status, metrics, and trends to support operational reporting and performance improvement.
- Coordinate with NIWC Atlantic and DHA stakeholders to ensure mission alignment and timely response to critical intelligence needs.
- Operate in a high-tempo environment with competing priorities and rapidly evolving threat landscapes.
Requirements
- Top Secret/SCI clearance (required).
- Bachelor's Degree in Cyber Security, Information Technology, or Computer Science.
- DoD 8140 (formerly 8570) baseline certification at the time of hire (e.g., Security+, CISM, or CISSP).
- 3+ years of experience in cybersecurity, threat intelligence analysis, or related cyber defense roles supporting DoD or federal agencies.
- Strong understanding of DoD cybersecurity policies, including DoD 8500-series, DoDI 8510.01 (RMF), and CJCSM 6510.01 (Cyber Incident Handling).
- 2+ years of experience conducting cyber threat research, analysis, and reporting in support of SOC, IR, or cyber threat intel teams.
- Proficiency in analyzing cyber threats across the MITRE ATT&CK framework, including TTPs and IOCs.
- Experience with threat intelligence platforms (TIPs), SIEM tools (e.g., Splunk, ELK, QRadar), and open-source intelligence (OSINT) research tools.
- Familiarity with malware analysis, DDoS patterns, phishing campaign forensics, and adversarial behavior.
- Strong written and verbal communication skills, including the ability to draft and present technical intelligence reports to varied audiences.
- Ability to manage and prioritize multiple concurrent RFIs in a high-tempo operations environment.
- Working knowledge of network architecture and protocols, including TCP/IP, DNS, HTTP/S, SMTP, and common intrusion methods.
- Hands-on experience with collaboration and tracking tools such as JIRA, Confluence, MS Teams, and SharePoint.
- Demonstrated ability to work collaboratively in a cross-functional environment under minimal supervision.
Benefits
Sentar’s employee ownership model promotes participation, teamwork, and accountability while ensuring long-term financial security.
- Voluntary Medical, Dental, and Vision insurance, with Health Savings or Flexible Spending Plan options.
- Voluntary Life, Critical Illness, Accident, and Long-Term Care insurance options.
- Group Term Life, Short-Term and Long-Term Disability provided by Sentar to all qualifying employees.
- Generous 401(k) match.
- Competitive PTO plan that graduates with years of service.
- Other leave programs: holiday schedule, bereavement, maternity, jury, and military duty.
- Mental health awareness programs.
- Tuition reimbursement.
- Professional development reimbursement.
- Recognition and Awards programs.