Cyber Defense Operator (CDO)

IPSECURE, INC.

San Antonio (TX)

On-site

USD 110,000 - 150,000

Full time

25 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Unlimited vacation
Sick leave
Paid holidays
Education reimbursement
401(k) plan
Legal plan
ID protection
Accident insurance
Critical illness insurance
Hospital indemnity insurance

Job summary

IPSecure in San Antonio, TX is seeking a Cyber Defense Operator (CDO) to join our defensive operations team. The role focuses on accurate event analysis, intrusion investigations, and timely reporting to protect Air Force networks.

You will lead incident response steps, generate IRFs and MISREPs, coordinate with law enforcement, and develop containment and remediation actions. A TS/SCI clearance is required for this position.

Qualifications

  • GCFA certification within 120 days of hire.
  • 3+ years of cyber security/technical experience preferred.

Responsibilities

  • Perform incident analysis to identify intrusions using host, network, and log data.
  • Open investigations to validate unauthorized activity and determine impact.
  • Generate IRFs for security incidents and MISREPs for knowledge transfer.
  • Support incident response deployments and coordinate with AFOSI as required.
  • Provide CDO support to law enforcement and counter‑intelligence agencies when needed.
  • Develop and brief incident response plans and TTPs.
  • Contribute to lessons learned meetings and briefings.

Education

GCFA Certification

Job description

Cyber Defense Operator (CDO ) - TS/SCI Level Clearance Required - Located in San Antonio, Texas

Job Description

The ability of the Cyber Defense Operator (CDO ) is to complete its mission dependent upon accurate, timely and thorough event analysis in order to identify intruder or potential intruder activities utilizing host and network monitoring and system logs. The CDO shall correlate information gathered to provide effective methods to protect Air Force (AF) systems. Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.

Responsibilities
  • When CAT events are escalated to incident response, complete incident response process, including: preparation, identification and scoping, containment, eradication and remediation, recovery, and lessons learned.
  • Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‑intelligence agencies and activities if required.
  • Participate and contribute to lessons learned meetings and briefings.
  • Support planned and same‑day Incident Response deployments.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Conduct cyber investigations in order to determine the initial vector and overall timeline of intrusion, accurately identify the threat, determine the full scope of impact, and develop containment and remediation actions for approval.
  • Author and review incident report forms (IRF) for security incidents within JEMS. Ensure the document is accurate and provides the correct amount of technical detail needed. (CDRL A008)
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‑intelligence agencies and activities if required.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc.
  • Provide computer security‑related support to AF field units as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
  • Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander.
  • Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable.
  • Design incident response plans (IRP) as directed by the Crew Commander. Ensure CDOs are briefed on objectives, ROEs, plans, contingencies, and applicable TTPs.
  • Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates, and TAR submissions.
Basic Qualifications
  • Ability to gain the CSSP Incident Responder Certification (GCFA)Certification requirement within 120‑days of hire date.
Preferred Qualifications
  • 3+ years of relevant technical, cyber security, and business work experience

Medical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid legal plan and ID protection plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.

EEOC Statement

IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.

IPSecure is an Equal Opportunity Aff…

EEO, Minorities, Females, Vet, Disabled, Sexual Orientation, Gender Identity or any other protected class. All qualified job seekers are encouraged to apply. IPSecure is committed to America's veterans by providing opportunities for them to continue contributing after service to our nation. We also work to provide reasonable accommodations to individuals with disabilities.

EEO Is The Law

Disability Accessibility Accommodation

If you have a disability and require assistance with our online application process, please tell us how we can help. E‑mail hr@ipsecureinc.com or call 210-877-1111.

Note:

Pay Transparency - The company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IP Secure, LLC • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Medical
Dental
Vision
+9
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IPSecure, Inc • San Antonio (TX)

On-site
USD 80,000 - 120,000
Unlimited Vacation
Education and Certification Reimbursement Program
401(k) retirement plan with employer match
+1
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • Del Rio (TX)

On-site
USD 90,000 - 120,000
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

Sms-Data-Products-Group,-Inc • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator – Intermediate
Cyber Defense Operator – Intermediate

SMS DATA PRODUCTS GROUP, INC • San Antonio (TX)

On-site
USD 110,000 - 150,000
Incident Response Officer (Intermediate)
Incident Response Officer (Intermediate)

Ssd Anc • San Antonio (TX)

On-site
USD 110,000 - 150,000
Health insurance
Paid time off
401(k) with company match
+1
Information Assurance Engineer III
Information Assurance Engineer III

IPSECURE, INC. • San Antonio (TX)

On-site
USD 120,000 - 160,000
Cyber Defense Operator: IR & Investigations (TS/SCI)
Cyber Defense Operator: IR & Investigations (TS/SCI)

IPSecure, Inc • San Antonio (TX)

On-site
USD 80,000 - 120,000
Unlimited Vacation
Education and Certification Reimbursement Program
401(k) retirement plan with employer match
+1