Senior Cyber Defense Analyst / Incident Responder IRES - SSFB/HSV
Location: Schriever Space Force Base, Colorado Springs, CO or Redstone Arsenal, Huntsville, AL. No relocation assistance available. This is an on-site position requiring an active DoD Top Secret with SCI eligibility. Rotating shift work in a 24/7 operational environment; up to 10% travel.
About the Role
The Senior Cyber Defense Analyst / Incident Responder supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. The candidate will provide oversight and guidance on the MDA Cybersecurity Service Provider - Computer Emergency Response Team’s (MDA CSSP-CERT) Cyber Defense and Incident Response program and serve as the primary point of contact for junior and mid-level Cyber Defense Analysts.
Responsibilities
- Perform Defensive Cyber Operations (DCO) and Cyber Security Service Provider (CSSP) duties as outlined in Evaluator Scoring Metrics (ESM).
- Conduct proactive and reactive cybersecurity duties on customer networks to improve enterprise-wide security posture.
- Perform preliminary analysis, identification, and response actions to detect, characterize, and respond to cyber incidents in accordance with CJCSM 6510.01B.
- Lead event and incident investigations from start to conclusion, including data gathering, analysis, reporting, and preservation of incident artifacts, evidence, and chain of custody.
- Analyze correlated asset, threat, and vulnerability data against known adversary exploits and techniques to determine impact and improve network defensive posture.
- Support the development and execution of a Cyber Defense Analyst and Incident Responder training plan by instructing, evaluating, and mentoring junior and mid-level personnel.
- Support the development, establishment, review, and update of DCO procedures, processes, manuals, and other documentation.
- Leverage actionable Cyber Threat Intelligence data to search for indicators of compromise and develop SIEM content/signatures to detect known attack patterns; recommend improvements.
- Coordinate with CSSP-CERT subscribers to develop current configurations, rules, and signatures for cybersecurity-related toolsets.
- Notify, investigate, and remediate discrepancies in security logging and CSSP-CERT alignment with subscribers.
- Provide standardized and targeted training in support of CSSP-CERT subscriber cyber defense and incident response programs.
- Review data of ongoing intrusions or cybersecurity incidents and report, analyze, and document findings in accordance with CJCSM 6510.01B guidelines.
- Provide support to internal and external Insider Threat and law enforcement/counterintelligence (LE/CI) agencies during cyber incidents and investigations.
- Use MS Office applications (Word, Excel, PowerPoint, Visio) to document and present findings.
- Multitask and prioritize projects in a dynamic environment to meet scheduled and unscheduled customer requests.
Requirements
- Six or more years of combined experience performing the full life-cycle of incident response and enterprise-level monitoring and analysis of events.
- Two or more years of experience in management or leadership in a team environment.
- Active DoD Top Secret with SCI eligibility.
- One of the following certifications: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP.
Qualifications
- Master’s degree or higher in Cybersecurity, Computer Science, or a related field (desired).
- Advanced cybersecurity certifications such as:
- Offensive Security: OSCP, PNPT, GPEN
- Forensics/Incident Response: GCFA, GCFE, GCIH, EC-Council Certified Hacking Forensic Investigator (CHFI)
- Threat Hunting/Analysis: GIAC Certified Cyber Threat Intelligence (GCTI)
- Experience with security analysis and solutions in WAN/LAN environments, including routers, switches, network devices, and operating systems (e.g., Windows, Linux).
- Experience with Security Operations Centers (SOC)/DCO tools and applications, such as firewalls, IDS/IPS, Network Security Manager, forward proxy, spam firewall, etc.
- Experience analyzing security compliance scans across a WAN (ACAS/Nessus preferred).
- Experience analyzing network and host-based threats (ESS preferred).
- Ability to mentor and train personnel in a high-paced environment.
- Familiarity with DoD Security Operations Centers (SOC) and DCO/Cybersecurity Service Provider (CSSP) guiding policies and procedures.
- Demonstrable experience in offensive security operations, such as penetration testing, red teaming, or exploit development.
- Experience with advanced digital forensics, including host-based and memory analysis.
- Proficiency in scripting and data analysis with languages such as Python, PowerShell, Bash, or KQL to automate tasks and parse large datasets.
- Familiarity with the intelligence cycle and its application to cybersecurity operations.
- Experience with hunt-centric security platforms, including industry-standard EDR, SIEM, and SOAR tools.
- Familiarity with the application of Artificial Intelligence (AI) and Large Language Models (LLMs) in cybersecurity, including leveraging AI-driven security tools and critically assessing their output.
Pay
$145,000 – $152,000 per year.
Benefits
- Health, dental, and vision insurance.
- Paid time off and holidays.
- Retirement benefits, including 401(k) matching.
- Educational reimbursement.
- Parental leave.
- Employee stock purchase plan.
- Tax-saving options.
- Disability and life insurance.
- Pet insurance.
Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions or benefits.