Cyber Defense Operator (CDO)

IPSecure, Inc

San Antonio (TX)

On-site

USD 110,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

IPSecure, Inc. seeks a Cyber Defense Operator (CDO) located in San Antonio, TX, with a TS/SCI clearance to monitor and analyze events across host and network systems.

You will correlate data to protect AF networks, open intrusion investigations, and support law enforcement and counter-intelligence activities as required. The role requires incident response expertise, 3+ years in cyber security, and the ability to obtain GCFA certification within 120 days.

Qualifications

  • Active TS/SCI clearance required.
  • IAT Level II certification (e.g., CompTIA Security+) required or to be obtained.
  • Ability to obtain CSSP Incident Responder (GCFA) within 120 days of hire.

Responsibilities

  • Complete incident response processes (preparation, identification, containment, eradication, recovery, lessons learned).
  • Open network intrusion investigations to validate unauthorized activity and determine scope.
  • Provide AF OSI DCO technical support to law enforcement and counter-intelligence as needed.
  • Participate in lessons learned meetings and briefings.
  • Support planned and same-day Incident Response deployments.
  • Analyze host DCO events to assess need for higher level analysis and initial intrusion assessment.
  • Conduct cyber investigations to identify threat vectors, scope, containment, and remediation actions.
  • Prepare and review IRFs for security incidents with accurate technical detail.

Skills

Incident response
Cyber security
Log analysis
Communication

Education

IAT Level II cert (e.g., CompTIA Security+)
CSSP Incident Responder (GCFA) cert

Tools

JEMS

Job description

Cyber Defense Operator (CDO) - TS/SCI Level Clearance Required - Located in San Antonio, Texas

The ability of the Cyber Defense Operator (CDO) is to complete its mission dependent upon accurate, timely and thorough event analysis in order to identify intruder or potential intruder activities utilizing host and network monitoring and system logs. The CDO shall correlate information gathered to provide effective methods to protect Air Force (AF) systems. Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.

Responsibilities
  • When CAT events are escalated to incident response, complete incident response process, including: preparation, identification and scoping, containment, eradication and remediation, recovery, and lessons learned.
  • Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‑intelligence agencies and activities if required.
  • Participate and contribute to lessons learned meetings and briefings.
  • Support planned and same‑day Incident Response deployments.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Conduct cyber investigations in order to determine the initial vector and overall timeline of intrusion, accurately identify the threat, determine the full scope of impact, and develop containment and remediation actions for approval.
  • Author and review incident report forms (IRF) for security incidents within JEMS. Ensure the document is accurate and provides the correct amount of technical detail needed. (CDRL A008)
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‑intelligence agencies and activities if required.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc.
  • Provide computer security‑related support to AF field units as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
  • Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander.
  • Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable.
  • Design incident response plans (IRP) as directed by the Crew Commander. Ensure CDOs are briefed on objectives, ROEs, plans, contingencies, and applicable TTPs.
  • Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates, and TAR submissions.
Basic Qualifications
  • Active TS/SCI Level Clearance.
  • Active IAT Level II Cert (ex: CompTIA Security+)
  • Ability to gain the CSSP Incident Responder Certification (GCFA) Certification requirement within 120-days of hire date.
Preferred Qualifications
  • 3+ years of relevant technical, cyber security, and business work experience
Benefits
  • Medical
  • Dental
  • Vision
  • Unlimited Vacation
  • Sick Leave
  • Paid Federal Holidays
  • Education and Certification Reimbursement Program
  • 401(k) retirement plan with safe harbor employer match after 3 months
  • Prepaid legal plan and ID protection plan available
  • Accident Insurance
  • Critical Illness Insurance
  • Hospital Indemnity Insurance available
EEOC Statement

IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IP Secure, LLC • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Medical
Dental
Vision
+9
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • Del Rio (TX)

On-site
USD 90,000 - 120,000
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

Sms-Data-Products-Group,-Inc • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator (CDO) – TS/SCI | Incident Responder
Cyber Defense Operator (CDO) – TS/SCI | Incident Responder

IP Secure, LLC • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Medical
Dental
Vision
+9
Cyber Defense Operator | TS/SCI | Incident Response Expert
Cyber Defense Operator | TS/SCI | Incident Response Expert

IPSecure, Inc • San Antonio (TX)

On-site
USD 110,000 - 160,000
Incident Response Officer (Intermediate)
Incident Response Officer (Intermediate)

Ssd Anc • San Antonio (TX)

On-site
USD 110,000 - 150,000
Health insurance
Paid time off
401(k) with company match
+1
Defense Cybersecurity Operations Analyst
Defense Cybersecurity Operations Analyst

The Intellekt Group, LLC • Bellevue (NE)

On-site
USD 85,000 - 120,000
SR Cyber Analyst – Davis-Montham AFB, AZ
SR Cyber Analyst – Davis-Montham AFB, AZ

Cyntel Technologies, LLC • Davis (CA)

On-site
USD 90,000 - 120,000
Paid Holidays
Paid time off (PTO)
Medical Plan
+2