EOE Statement
Technology Automation & Management (TeAM), Inc.
TeAM is looking for highly motivated and highly skilled individuals who are ready for exciting opportunities with a growing company. For more than a quarter of a century, we've built our reputation as a premier solutions provider to the Federal Government, and eagerly seek creative problem solvers to join our TeAM.
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law.
Description
Pending Contract Award
Mission Objectives - Defensive Cyberspace Operations (DCO) are the passive and active measures taken to detect, characterize, and defeat adversary activity on Army networks and preserve the Army's ability to use its own cyberspace capabilities - a distinct, adversary-focused mission from routine IT infrastructure or help-desk support. This position leads both Blue Team task areas of the USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) effort: Blue Team - Network Security Monitoring, Detection, Analysis, and Incident Response, and Blue Team - Integrated Assessments. Together these form the primary operational layer defending U.S. Army Reserve information systems supporting approximately 205,000 Army Reserve personnel across NIPRNet and SIPRNet on a continuous basis. The Blue Team Lead is the single point of accountability for both task areas and is one of three Key Personnel positions on this task order.
Position Responsibility Summary
- Serve as Key Personnel and single point of accountability for Blue Team - Network Security Monitoring, Detection, Analysis, and Incident Response across NIPRNet and SIPRNet, maintaining 24/7/365 watch coverage.
- Lead Tier 3 senior analysis, hypothesis-driven hunt missions, and detection-signature development, coordinating signature submissions with the CTI cell and the ARCYBER signature working group.
- Own incident categorization and reporting IAW CJCSM 6510.01B; ensure execution of critical blocks within 2 hours of notification/detection and 24-hour mitigation actions where required.
- Direct shift operations: watch schedule, pass-down log, shift-lead handoff briefings, and surge staffing procedures during declared elevated threat conditions, named operations, or directed exercises.
- Direct execution of Blue Team - Integrated Assessments, including Network Assistance Visits (NAVs) and Network Damage Assessments (NDAs) under the CDAP construct, with 4-hour NDA deployment readiness.
- Serve as the Blue Team escalation point to ARCYBER, the supported Regional Cyber Center, JFHQ-DoDIN, and Law Enforcement/Counterintelligence.
- Mentor and quality-control Tier 1 and Tier 2 analysts; own team compliance with DoDM 8140.03 DCWF qualification requirements.
- Own Blue Team performance against PRS thresholds, including =99.5% watch availability, mean-time-to-detect under 15 minutes on high-fidelity alerts, and 100% shift-handoff log completeness.
Position Requirements
Government/Minimum Qualification:
Candidate cannot be proposed without these
Experience:
- Minimum 5 years of documented, specialized operational experience in DoD or enterprise cyber defense operations.
- U.S. citizenship.
Certifications and Qualification
- Certifications: Qualification for DCWF 531/511 (Cyber Defense Incident Responder / Cyber Defense Analyst, Advanced) under DoDM 8140.03. Candidates qualify through one of three recognized pathways: (1) a certification recognized under the current DoD 8140.03 Qualification Matrix for this work role/proficiency —highly desired certifications include GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Forensic Analyst (GCFA), or (ISC)² CISSP; (2) an approved degree plus DoD/commercial training combination; or (3) documented equivalent experience per Component-specific 8140.03 implementation guidance. No single certification is independently mandatory.
- Qualification Verification: TeAM verifies each candidate's qualifying certification, training, or degree/experience combination against the current DoD Cyber Workforce Framework Qualification Matrix at https://public.cyber.mil/wf/dcwf/ at proposal, at hire and throughout performance. Treat the certifications listed above as illustrative screening examples, not an exhaustive or exclusive list — the published matrix governs.
- Years of Experience: 5 years minimum.
TeAM Required Qualification:
TeAM's recruiting requirement based on performance risk — not independently Government-mandated
Experience:
- Demonstrated experience leading or serving in a senior role within a 24/7/365 Security Operations Center or equivalent continuous cyber-defense watch operation.
- Direct experience with DoD cyber incident categorization and reporting frameworks (e.g., CJCSM 6510.01B or equivalent).
- Hands-on proficiency with SIEM platforms, IDS/IPS (Snort, Suricata, or equivalent), endpoint detection and response tooling, and full packet capture/NetFlow analysis.
- Experience developing or validating network- and host-based detection signatures (YARA, Snort/Suricata rules, or equivalent).
- Demonstrated Tier III advanced intrusion analysis and hands-on threat hunting capability.
- Education: Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a related field, or equivalent demonstrated experience in lieu of degree
Highly Preferred / Discriminator:
Improves candidate ranking — does not automatically eliminate
Experience:
- Prior direct performance on USARC's current legacy NEC-aligned support contract, or on another Army Reserve, ARCYBER, or NETCOM-supported network.
- Currently resides in or near Fayetteville/Fort Bragg, NC, or able to report on-site within a short timeframe of award without relocation lead time.
- Existing TS/SCI clearance in place.
- Hands-on experience with the specific deployed toolset: Elastic SIEM, Trellix ENS, and Tychon EDR.
- Web application assessment tooling proficiency (Burp Suite Pro, OWASP ZAP, Nessus Web App).
- RMF/Assessment & Authorization or eMASS Plan of Action and Milestones (POA&M) support experience.
- Experience coordinating with Law Enforcement/Counterintelligence organizations (e.g., Army Computer Crimes Investigative Unit) on cyber incident investigations.
- Participation in Army or Joint cyber exercises (Cyber Shield, Cyber Yankee, Cyber Flag, or similar).
- OCONUS deployment readiness, including current passport and no travel restrictions, to support theater-specific TDY.
Additional Credentials:
- Education: Master's degree in Cybersecurity or a related field.
- Certifications/Training: CASP+, ARCYBER Cyber Intrusion Analysis Program (CIAP) credential, Army Penetration Testing Course (APTC), OSCP, or GREM — advanced credentials beyond the baseline 8140.03 qualification shown above.
- Other: Existing DoD CAC and Fort Bragg installation access; prior Army or Army Reserve network experience.
Duty Location:
USARC Headquarters, Fort Bragg, North Carolina (on-site — the default performance posture for this task order)
Work Arrangement:
Onsite. Telework is authorized only with prior written COR approval and, when approved, is performed exclusively over Government-furnished equipment via the supported RCC-managed VPN — not a standard work arrangement for this role.
Travel Requirements:
CONUS and OCONUS as required to support Network Damage Assessments, incident response, and CDAP integrated assessments, including TDY to theater locations (Germany, Republic of Korea, Southwest Asia, Japan) IAW applicable theater-specific procedures and the Joint Travel Regulations.
Work Hours:
24/7/365 mission-essential function — leads and schedules continuous watch coverage; on-call and required to respond to after-hours incident notification within 2 hours; core administrative hours 0600–1700 local, Monday–Friday, for non-watch duties.
Minimum Security Clearance Required:
Active SECRET or ability to satisfy this clearance requirement at performance start. Higher-level access/investigation eligibility (e.g., Tier 5) may be required based on assigned privileged duties.
Full-Time/Part-Time -unspecified-
Relocation Assistance
Sign-on Bonus
Travel Required
RFI/RFP
Req Number INF-26-00042
Location Defensive Cyberspace Operations (DCO) Mission Support Services (DCOMSS)