Jobs · OTHR · Missouri

Cyber Security Operations Specialist III - Tier 3

CACI International Inc · St Louis, MO · 3 wk ago
OTHR$75k–$158k/yrFull-time

About the Role

The Cyber Security Operations Specialist III (Tier 3) provides 24x7x365 coordination, execution, and implementation of containment, eradication, and recovery measures for cyber events and incidents. Responsibilities include malware and implant analysis, forensic artifact handling, and serving under the direct control of the Government CIRT Commander during incident response. When not responding to incidents, the role involves continuous exercises and dry runs to improve response outcomes. All personnel must obtain a DoDD 8140.01 and DoD 8570.01-M IAT Level III and CSSP Incident Responder certification within six months of starting.

Shift 5 schedule: Saturday/Sunday, 6:00 AM to 6:00 PM or 6:00 PM to 6:00 AM, plus two additional 8-hour shifts during the week, coordinated with the Team Lead.

Responsibilities

  • Coordinate and implement tasks during cyber security incident response, including containment measures, IP/domain blocks, and disabling user accounts as directed by the Government.
  • Collaborate with the Security and Installations Directorate (SI) Office of Counterintelligence (SIC), Insider Threat Office (SIII), and other law enforcement/counterintelligence personnel for advanced incident investigation and triage.
  • Produce security incident reports in collaboration with appropriate authorities.
  • Categorize incidents and events, ensuring proper reporting, containment, and eradication through coordination with other contracts, organizations, and services.
  • De-conflict blue/red team activity with open incidents/events.
  • Ensure NGA recovers from incidents/events through coordination with relevant stakeholders.
  • Build timelines, documents, briefings, and other products to inform stakeholders of incident response actions, analysis, and impacts of adversary and blue force activities.
  • Document actions and analysis in the authorized ticketing system to enable systematic reconstruction of response efforts.
  • Develop and update reports in the Joint Incident Management System (JIMS), Incident Case Management System (ICMS), or other authorized systems as directed.
  • Develop, maintain, and execute custom scripts, tools, and capabilities for data collection, analysis, and incident response (with Government approval).
  • Perform digital media analysis on host, server, and network data, including volatile/non-volatile memory and system artifact collection and analysis.
  • Develop and identify indicators of compromise for dissemination to Cybersecurity stakeholders and other contract services.
  • Provide adversary attribution and perform malware analysis and signature development.
  • Coordinate with CSOC Tier 1 and 2 services to remediate discrepancies and recommend preventive measures.
  • Develop and deliver daily CSOC Significant Activity Reports, Operations Updates, and Weekly Status Reports in coordination with stakeholders.
  • Serve as a C-IRT member under the direct control of the Government C-IRT Commander.
  • Develop and coordinate courses of action for Defensive Cyberspace Operations-Internal Defensive Measures (with Government approval).
  • Execute custom scripts, tools, and capabilities for data collection and analysis (with Government approval).
  • Develop incident investigation reports within 30 days of C-IRT stand-down, including adversary/friendly forces activity, host/network analysis, timelines, and recommendations for corrective actions and new TTPs.
  • Conduct quality control reviews of closed CSOC Tier 2 tickets to ensure proper analysis, categorization, documentation, and notification.

Requirements

  • Bachelor’s degree and/or 6 years of experience in Cyber Security (CSOS).
  • Active TS/SCI clearance; ability to obtain a polygraph.
  • DoDD 8140.01 and DoD 8570.01-M IAT Level II and CSSP Incident Responder certification (IAT Level III required within six months).

Qualifications (Desired)

  • Master’s degree.
  • IAT Level III certification.

Benefits

CACI offers a culture of integrity, trust, and continuous growth, with a focus on mission-driven work. Benefits include:

  • Flexible time off and robust learning resources.
  • Comprehensive benefits package: healthcare, wellness, financial, retirement, family support, continuing education, and time off.

Pay

The proposed salary range for this position is $75,200–$158,100. Final salary is influenced by factors such as geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education, and certifications.

Similar jobs