Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc.

Del Rio (TX)

On-site

USD 90,000 - 120,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SMS Data Products Group, Inc. is seeking a Cyber Defense Operator to support AFCERT missions by providing near real-time network security monitoring, intrusion detection analysis, and host security monitoring across the AFIN.

The operator works as part of the DCO Hunt and Assess Crew with mission-ready status for 24x7 operations. Qualified candidates have five years in cyber defense or related DoD/intelligence work, active DoD TS/SCI clearance, a High School Diploma or GED, and GCFA

Qualifications

  • Five (5) years in cyber defense operations or related DoD/IC environment.
  • Active DoD TS/SCI clearance required.
  • High School Diploma or GED required.
  • GCFA certification required within 120 days after hire.
  • Knowledge of Cyber Kill Chain, MITRE ATT&CK, and NIST 800-series.

Responsibilities

  • Conduct near real-time network security monitoring and intrusion detection analysis.
  • Review IDS/IPS alerts per OI and checklists.
  • Conduct host security monitoring, alert review, intrusion detection analysis, and event triage.
  • Develop, review and maintain procedures for monitoring Hosts/Systems.
  • Monitor sensors to identify security issues in IDS/SIEM; review logs for intrusions.

Skills

Cyber defense operations
Network security monitoring
Intrusion detection analysis
DoD environment

Education

High School Diploma or GED

Tools

SIEM
EDR
IDS/IPS
Packet capture

Job description

The Cyber Defense Operator (CDO) supports the Air Force Computer Emergency Response Team (AFCERT) mission by providing continuous, near real-time network security monitoring, intrusion detection analysis, and host security monitoring across the Air Force Information Network (AFIN). The CDO operates as a member of the DCO Hunt and Assess Crew (HAC) and is required to attain and maintain Mission Ready (MR) status in accordance with applicable Air Combat Command Instructions (ACCI) and ACCMANs governing the AFIN weapon system. This position supports 24x7x365 mission operations across rotating crew schedules.

Since 1976, SMS has specialized in modernizing legacy IT and sustaining complex enterprise environments for federal agencies. With the goal of building long-term partnerships with our customers, we invest in our employees by providing the training, tools, and support they need to keep critical missions operational, improve performance, and reduce risk.

SMS is headquartered in McLean, Virginia, with offices and on-site operations at customer locations throughout the United States. For additional information on SMS, visit www.sms.com .

Job Responsibilities
  • Conduct near real-time network security monitoring and intrusion detection analysis across networks and systems
  • Review IDS/IPS alerts per Operating Instruction (OI) and checklists
  • Conduct host security monitoring, alert review, intrusion detection analysis, and event analysis and triage
  • Develop, Review and Maintain procedures related to the overall monitoring of Hosts/Systems.
  • Monitor security sensors to analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify and correlate security issues/events and review logs to identify intrusions for remediation.
  • Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources.
  • Analyze traffic/logs/events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Record who, what, where, why and when for any identified suspicious activity in case management system (CMS) to enable additional investigations.
  • Conduct triage of suspicious activity alerts and logs in order to make a fast and accurate triage decision.li
  • Enter event data into mission support systems in accordance with operational procedures and reports.
  • Escalate security incidents using established policies and procedures.
  • Generate end of mission reports (MISREPS) and provide pass-on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc.
  • Provide computer security-related support to AF field units.
  • Provide feedback on detection mechanisms that are both true and false positive events to Content Development as applicable.
Required Qualifications
  • A minimum of five (5) years of experience in cyber defense operations, network security monitoring, intrusion detection analysis, or a related discipline within a DoD or Intelligence Community environment.
  • Active DoD TS/SCI clearance required.
  • High School Diploma or GED required.
  • GCFA certified (Candidate has 120 days to obtain GCFA after hire)
  • General knowledge of cyber security frameworks, such as the Cyber Kill Chain, MITRE ATT&CK, and the NIST 800 series
  • General knowledge of physical computer components and architectures, including the functions of computer domains, directory services, various components and peripherals, basic programming concepts, assembly codes, TCP/IP, OSI models, underlying networking protocols (e.g., DNS, ARP, etc.), security hardware and software

Candidate must be self-motivated and able to perform with minimal supervision

Preferred Qualifications
  • Knowledge of cyber forensic collection, preservation, and chain of custody
  • Prior AFCERT / DCO / SOC experience supporting government networks.
  • Experience with endpoint and network security tooling such as SIEM, EDR, packet capture, IDS/IPS, and case management workflows.
  • Familiarity with producing operational deliverables in a regulated environment (formal ticketing, incident timelines, evidence handling).

SMS is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Req # 2026-

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

SMS Data Products Group, Inc. • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator – Intermediate
Cyber Defense Operator – Intermediate

SMS DATA PRODUCTS GROUP, INC • San Antonio (TX)

On-site
USD 110,000 - 150,000
Cyber Defense Operator - Intermediate
Cyber Defense Operator - Intermediate

Sms-Data-Products-Group,-Inc • San Antonio (TX)

On-site
USD 90,000 - 130,000
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IP Secure, LLC • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Medical
Dental
Vision
+9
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IPSecure, Inc • San Antonio (TX)

On-site
USD 80,000 - 120,000
Unlimited Vacation
Education and Certification Reimbursement Program
401(k) retirement plan with employer match
+1
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
Mission-Critical Cyber Defense Operator (TS/SCI)
Mission-Critical Cyber Defense Operator (TS/SCI)

SMS Data Products Group, Inc. • Del Rio (TX)

On-site
USD 90,000 - 120,000
Cyber Defense Operator, Intermediate - 24/7 SOC
Cyber Defense Operator, Intermediate - 24/7 SOC

SMS DATA PRODUCTS GROUP, INC • San Antonio (TX)

On-site
USD 110,000 - 150,000
24/7 Cyber Defense Analyst – DoD Network Security
24/7 Cyber Defense Analyst – DoD Network Security

Sms-Data-Products-Group,-Inc • San Antonio (TX)

On-site
USD 90,000 - 130,000
Defensive Cyber Operations (DCO) Analyst
Defensive Cyber Operations (DCO) Analyst

Dark Wolf Solutions, LLC • Clearfield (UT)

On-site
USD 110,000 - 150,000