Defensive Cyber Operations (DCO) Analyst
Dark Wolf · Ogden, UT · 2 wk ago
ManagementFull-time
About the Role
Dark Wolf Solutions is seeking a Defensive Cyber Operations Analyst to perform continuous system monitoring, identify malicious cyber-attacks, and support containment and remediation of IT threats. This position involves monitoring networks and applications to detect cyber-attacks or intrusions and coordinating cyber incident responses.
Responsibilities
- Perform vulnerability management actions, including providing recommendations and implementing mitigations.
- Actively monitor Defensive Cyber Operations (DCO) systems.
- Conduct intrusion analysis and correlate unauthorized activities; provide and implement recommendations to improve customer mitigation processes.
- Perform threat insight processes to support mitigation and remediation activities.
- Analyze cyber incidents, correlate incident details, and formulate and implement response actions with guidance from leadership.
- Participate in Root Cause Analysis and document efforts taken to mitigate unauthorized actions.
- Contribute to the development of DCO tactics, techniques, and procedures.
- Assist in developing DCO concept of operations, processes, and procedures.
- Identify security discrepancies and report and respond to security incidents.
- Provide research and analysis in support of expanding programs and areas of responsibility.
- Draft documentation for briefings, reports, and informational analyses.
- Assist in the development of local Tactics, Techniques, and Procedures (TTPs).
- Participate in customer exercises (after duty hours may be required).
- Adhere to defined policies, master plans, and schedules.
- Complete all initial and annual training requirements and disclosures as outlined by BSTG.
- Perform all other duties as required, consistent with the goals, objectives, and responsibilities of the department.
Requirements
- 4+ years of relevant experience.
- 2+ years of experience with a SIEM Tool (LogRhythm, Splunk).
- 2+ years of experience with employment of DoD cybersecurity requirements, policies, and procedures, including assessment and authorization activities.
- Experience within a vSOC, SOC, or CSSP responding to cyber incidents.
- Department of Defense Directive (DoDD) 8140 (formerly DoDD 8570) IAT CSSP Certification must be obtained prior to hire (CEH, CCNA Security, GCIH, CySA+ or equivalent).
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- U.S. Citizenship and an active Top Secret/SCI security clearance required.
Qualifications
- Experience performing cybersecurity activities in support of software and system requirements, design, development, testing, and sustainment.
- Experience with HBSS, ACAS, SCAP Compliance Checker (SCC), DISA STIGs.
- Working knowledge of NIST 800-53 Security and Privacy Controls.
- Experience with RHEL.
- Experience in performing post-incident computer forensics without destruction of critical data.
- Ability to provide guidance on DoD Cyber regulations and requirements to engineering and software development staff.