Defensive Counter Cyber - DCC

STS Systems Support, LLC

San Antonio, Northern (TX, KY)

Hybrid

USD 140,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Paid holidays
Time off (vacation & sick)
Medical, dental, vision insurance
401(k) with company match
Tuition reimbursement

Job summary

STS Systems Support, LLC seeks a Senior Defensive Counter Cyber (DCC) to support mission operations at Lackland AFB in San Antonio, TX. You will hunt threats, analyze indicators, and coordinate defenses against advanced threats within AF networks and enclaves.

Must hold DoD 8570.01-M/IAT Level III and an active TS/SCI, with extensive OS, security, and forensics experience. Role includes mentoring, reporting, and continuous improvement of tactics and tooling.

Qualifications

  • More than five years of experience in OS fundamentals, system admin, and security.
  • Experience with DoD network topology and DMZ protections.
  • Strong knowledge of MITRE ATT&CK and its practical uses.

Responsibilities

  • Perform threat hunting using IOC and anomaly analysis across sources.
  • Identify intrusions and vulnerabilities; propose mitigations.
  • Conduct Defensive Counter Cyber Operations against APTs.
  • Provide incident response impact assessments and reports.

Skills

Threat hunting
MITRE ATT&CK
Incident response
Network security
Forensics
Vulnerability analysis

Education

DoDD8570.01-M/8140.01 IAT Level III
BA/BS or MA/MS

Tools

WireShark
Snort
EnCase/FTK

Job description

STS Systems Support, LLC (SSS) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Defensive Counter Cyber - DCC – Senior to support our mission at Lackland AFB in San Antonio, TX.

What You'll Do:
  • Perform threat hunting for suspicious activity based on anomalous activity and indicators of compromise from various intelligence sources and toolsets.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. (CDRL A002)
  • Identify intrusions and vulnerabilities and recommend mitigation strategies and techniques to secure networks.
  • Identify, analyze and develop defensive counter cyber measures to thwart advanced persistent threats and intrusions of AF networks, domains and enclaves.
  • Conduct and support Defensive Counter Cyber Operations to interactively search for Advanced Persistent Threats (APT) and Indicators of Compromise (IOC) using enhanced data collection and analysis methods.
  • Provide incident response impact assessments.
  • Produce network security posture assessments. (CDRL A008)
  • Analyze systems for suspicious activities related to the DCO mission
  • Determine exploitation methods and attack vectors.
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.
  • Create and document metrics for reporting and analysis to improve weapon system processes, procedures, and mission execution. (CDRL A009)
  • Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
  • Provide requested information to operational flight commander as it relates to the Incident Response processes and procedures.
  • Utilize the Mitre ATT&CK Matrix in performance of duties.
  • Plan hypothesis‐based threat hunt missions. Utilize current Cyber Threat Intel team provided information in threat prioritization/hunt creation.
  • Execute hunt mission within specified cyber terrain.
  • Coordinate with ESM and Content Development to automate threat hunts and/or develop standing detections for threat hunts.
  • Request Tactical Validation and Assessment (TVA) to validate hunt techniques and/or created alerting mechanisms.
  • Identify and report coverage gaps in detection and weapon system visibility/capability.
  • Develop hypothesized schemes‐of‐maneuver of adversary behavior as needed for hunt missions in coordination with Cyber Threat Intel team.
  • Leverage the MITRE ATT&CK matrix to map adversarial TTPs to current security coverage within specified cyber terrain.
  • Develop threat hunts for emerging cyber threats, to include 0‑day proof‑of‑concepts, CVE exploitation, and adversary TTPs.
  • Organize and analyze collected data to determine trends, perform long‑tail and frequency analysis of host and network artifacts, and baseline enterprise activity.
What You Bring:
Requirements:
  • DoDD8570.01‑M/8140.01 I AT Level III CND
  • Active TS/SCI
  • More than 5 years of experience with extensive knowledge of operating systems fundamentals. BA/BS or MA/MS
  • More than five (5) years of experience with extensive knowledge of Operating systems fundamentals (Windows and/or Unix/Linux), System administration (Windows and/or Unix/Linux), Network traffic analysis, Penetration testing, Network security, Incident response & Incident response handling, Computer and network forensics, Vulnerability and malware analysis.
  • Extensive knowledge of network firewalls, computer and server log analysis, computer network servers (DNS, proxy, e‑mail, domain controller, file server, Active Directory) and analysis of their logs
  • Extensive knowledge of digital evidence collection, handling and security
  • Experience with computer incident response and analysis and report dissemination
  • Extensive knowledge and experience with network packet capture and analysis software such as WireShark (Ethereal) and Snort
  • Experience with standard DoD network topology and DMZ boundary protection
  • Experience with system analysis software (i.e. EnCase/EnCase Enterprise or FTK), software coding and debugging, and the virtual machine (VM) environment.
  • Expert knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)
What We Offer:

STS Systems Support, LLC (SSS) offers a competitive benefits package to include paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

SSS is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Defensive Counter Cyber - DCC
Defensive Counter Cyber - DCC

Bristol Bay Native Corporation • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 180,000
Paid holidays
Medical, dental and vision insurance
401(k) with company match
Incident Response Officer (Intermediate)
Incident Response Officer (Intermediate)

Ssd Anc • San Antonio (TX)

On-site
USD 110,000 - 150,000
Health insurance
Paid time off
401(k) with company match
+1
Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

On-site
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
Cyber Threat Emulation & Analyst
Cyber Threat Emulation & Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 80,000 - 110,000
Paid holidays
Paid time off
Medical insurance
+1
Senior Defensive Counter Cyber Threat Hunter
Senior Defensive Counter Cyber Threat Hunter

STS Systems Support, LLC • San Antonio (TX), Northern (KY)

Hybrid
USD 140,000 - 190,000
Paid holidays
Time off (vacation & sick)
Medical, dental, vision insurance
+2
Senior Defensive Cyber Operator - Threat Hunting & IR
Senior Defensive Cyber Operator - Threat Hunting & IR

Bristol Bay Native Corporation • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 180,000
Paid holidays
Medical, dental and vision insurance
401(k) with company match
Emerging Threats Analyst
Emerging Threats Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 85,000 - 110,000
Medical, dental and vision insurance
401(k) with company match
Paid holidays and time off
Signature Writer – Intermediate – Cyber Security
Signature Writer – Intermediate – Cyber Security

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 180,000
Paid holidays
401(k) with company match
Tuition reimbursement
Cyber Data Engineer
Cyber Data Engineer

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 160,000
Tuition reimbursement
Medical and vision insurance
Paid holidays and PTO
Content Developer (SIEM Cyber Security)
Content Developer (SIEM Cyber Security)

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 90,000 - 120,000
Paid holidays
Medical, dental, and vision insurance
401(k) with company match