Jobs · Management · Colorado

Defensive Cyber Operations SME

Tyto Athene, LLC · Colorado Springs, CO · Today
Management$115k–$130k/yrFull-time

Responsibilities

  • Develop operational and technical materials to aid in increasing proficiency of the crews
  • Provide cyber defense remediation and mitigation implementation recommendations in support of all incidents/events
  • Support for all Operational Planning Teams (OPTs) and crew shift planning processes. Support includes participating in the planning process, recommending course of action (COAs), and validating the technical approach to meet mission objectives
  • Draft and validate accuracy of squadron level DCO Tactics, Techniques, and Procedures (TTPs); Standard Operating Procedures (SOPs); Operational Instructions (OIs); as well as DCO Crew operations products, evaluation and material, and other related materials
  • Conduct analysis on new DCO-Space capability releases to assess new functionality and inform employment for mission execution
  • Attend meetings, teleconferences, and Video Teleconferences (VTCs) at the Unclassified, Secret, and TS/SCI level (as required)
  • Provide recommendations for exercises and mission rehearsals
  • Maintain proficiency by performing DCO crew operation for assigned space mission systems
  • Provide expertise for DCO-Space capabilities, to include Security Incident and Event Management (SIEM); Intrusion Detection and Prevention Systems; ELK (Elasticsearch, Logstash, and Kibana) Stack; Endpoint Protection Systems; Security Orchestration, Automation and Response (SOAR); Firewalls; Log Aggregator; Protocol Analyzers; Vulnerability Assessment Tools
  • Augment and advise the crews performing intrusion detection monitoring and analysis
  • Provide input and review Cyber 9-Line; and review accuracy of cyber incident inputs for SITREP and MISREP
  • Advise and assist with cyber incident response processes IAW squadron policies and procedures, to include Assist in providing in-depth analysis of incidents by determining the incident’s nature, formulating recommended response actions, correlating event and incident data across assigned space mission systems, determining actions to be taken, and assessing possible effects on assigned mission systems
  • Participate in Government-established Cyber Incident Response Teams (CIRTs) and provide technical assistance in determining the cyber events/incident’s nature and impact to space mission systems; develop and recommend mitigation and/or remediation COAs; ensure mission system owners/operators and leadership have situational awareness of active response activities via recurring status reports and/or update briefs
  • Provide technical expertise in the creation of recommendation of Courses of Action (COA) along with suggested timing and sequencing of actions to mitigate and/or remediate cyber threats to space mission systems
  • Participate in post-incident hot washes and lessons learned processes as required by the Government
  • Recommend cyber incident response best practices to improve TTPs, processes, and policies
  • Recommend cyber mission best practices to improve TTPs, processes, and policies
  • Assist and support CYS Government personnel on how to identify, document, and track normal baseline activity for assigned space mission systems by monitoring, collecting, and analyzing space mission system data traffic; and reviewing, auditing, and analyzing network and endpoint logs
  • Assist and support CYS Government personnel on performing Mission Relevant Terrain - Cyber (MRT-C) identification and mapping, leveraging Functional Mission Analysis - Cyber (FMA-C) concepts for assigned space mission systems
  • Assist and support CYS Government personnel on how to conduct cyber missions, to include Survey, Recon, Escort, Hunt, Strike, Recover and others on assigned space mission systems to detect, track, and disrupt Advanced Persistent Threats (APTs) that evade existing cybersecurity controls and detection capabilities
  • Provide inputs to post-mission analysis process for Cyber missions as required by the Government

Requirements

  • Minimum of one (1) active DoD 8570.07-M Cyber Security Services Provider (CSSP) "Analyst" or "Incident Responder" certifications CEH, CySA+, GCIH, GCIA, CFR, CCNA Cyber Ops, CCNA-Security, GICSP, Cloud+, SCYBER, PenTest+, CHFI or GCFASix (6) years of Cyber Security Analyst work experience (or equivalent)
  • Experience includes Cybersecurity Monitoring; Cybersecurity Analyst; Intrusion Detection and/or Cyber Incident Response
  • Experience performing Continuous Cybersecurity Monitoring, Intrusion Detection and Cyber Incident Response
  • Experience with the following toolsELK Stack, Kibana, Suricata, Splunk, Snort, Wireshark, Bro/Zeek logs, tcpdump, editcap, LogRhythm, ePo/HBSS, ACAS, SolarWinds, Microsoft Office 365, Active Directory WMIC commands
  • Cybersecurity Service Provider (CSSP) experience is preferred
  • Eight (8)+ years of relevant cybersecurity experience
  • IAT Level III Certification required IAW DoD 8570.07-M. Qualifying certifications include CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP
  • Familiarity with Space Operations is highly desired

Qualifications

  • Active DoD TS/SCI clearance

Benefits

Highest quality benefits package including:

  • Health/Dental/Vision
  • 401(k) match
  • Paid Time Off
  • STD/LTD/Life Insurance
  • Referral Bonuses
  • Professional development reimbursement
  • Parental leave

Similar jobs

Cyberspace Operations SME

Systems Planning & AnalysisAlexandria, VA· 2 wk ago
Management$185k/yrapply on careers-spa.icims.com

Cyber Security SME

TENICA Global SolutionsHerndon, VA· 26 mo ago
Engineeringapply on tenica.hrmdirect.com

Cybersecurity SME

JobgetherUnited States· 1 wk ago
RemoteEngineering$155k–$185k/yrapply on jobs.lever.co