Cyber Defense Operator (CDO) – TS/SCI | Incident Responder

IP Secure, LLC

Town of Texas (WI)

On-site

USD 110,000 - 140,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical
Dental
Vision
Unlimited Vacation
Sick Leave
Paid Federal Holidays
Education and Certification Reimburs e
401(k) retirement plan with safe harb
Prepaid legal plan and ID protection
Accident Insurance
Critical Illness Insurance
Hospital Indemnity Insurance

Job summary

IPSecure seeks a Cyber Defense Operator (CDO) to perform comprehensive event analysis and incident response for AF networks. The role emphasizes coordinating with law enforcement and counter-intelligence agencies, validating intrusions, and producing detailed incident reports.

Candidates should hold TS/SCI clearance and IAT II certification, with the ability to obtain GCFA within 120 days. The position involves planning, debriefings, and knowledge transfer in a fast-paced environment, with a

Qualifications

  • Active TS/SCI Level Clearance.
  • Active IAT Level II Certification (e.g., CompTIA Security+)
  • Ability to gain the CSSP Incident Responder Certification (GCFA) within 120 days of hire.

Responsibilities

  • When CAT events are escalated to incident response, complete incident response process, including: preparation, identification and scoping, containment, eradication and remediation, recovery, and lessons learned.
  • Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter-intelligence agencies and activities if required.
  • Participate and contribute to lessons learned meetings and briefings.
  • Support planned and same-day Incident Response deployments.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Conduct cyber investigations in order to determine the initial vector and overall timeline of intrusion, accurately identify the threat, determine the full scope of impact, and develop containment and remediation actions for approval.
  • Author and review incident report forms (IRF) for security incidents within JEMS. Ensure the document is accurate and provides the correct amount of technical detail needed. (CDRL A008)
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter-intelligence agencies and activities if required.
  • Generate end of mission reports (MISREPS) and provide pass-on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Generate end of mission reports (MISREPS) and provide pass-on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc.
  • Provide computer security-related support to AF field units as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
  • Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander.
  • Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable.
  • Design incident response plans (IRP) as directed by the Crew Commander. Ensure CDOs are briefed on objectives, ROEs, plans, contingencies, and applicable TTPs.
  • Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates, and TAR submissions.

Job description

IPSecure seeks a Cyber Defense Operator (CDO) to perform comprehensive event analysis and incident response for AF networks. The role emphasizes coordinating with law enforcement and counter-intelligence agencies, validating intrusions, and producing detailed incident reports.

Candidates should hold TS/SCI clearance and IAT II certification, with the ability to obtain GCFA within 120 days. The position involves planning, debriefings, and knowledge transfer in a fast-paced environment, with a

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IP Secure, LLC • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Medical
Dental
Vision
+9
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

SMS DATA PRODUCTS GROUP, INC • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

SMS Data Products Group, Inc. • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • Del Rio (TX)

On-site
USD 90,000 - 120,000
Mission-Critical Cyber Defense Operator (TS/SCI)
Mission-Critical Cyber Defense Operator (TS/SCI)

SMS Data Products Group, Inc. • Del Rio (TX)

On-site
USD 90,000 - 120,000
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

Sms-Data-Products-Group,-Inc • San Antonio (TX)

On-site
USD 90,000 - 130,000
DoD Cyber Defense Operator — 24/7 Mission Security
DoD Cyber Defense Operator — 24/7 Mission Security

SMS DATA PRODUCTS GROUP, INC • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

Sms-Data-Products-Group,-Inc • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Incident Response Analyst – 24/7 IR, TS/SCI
Cyber Incident Response Analyst – 24/7 IR, TS/SCI

CACI International • Hampton (VA)

On-site
USD 75,000 - 158,000