Incident Response Officer (Intermediate)

Ssd Anc

San Antonio (TX)

On-site

USD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Paid time off
401(k) with company match
Tuition reimbursement

Job summary

STS Systems Defense, LLC (SSD) seeks an Incident Response Officer (Intermediate) to support Lackland AFB in San Antonio, TX. The role requires handling cyber incidents, conducting investigations, and coordinating with AF OSI and other agencies.

Responsibilities include IRP execution, MISREPS, and knowledge transfer to duty crews. Candidates need TS/SCI and GCFA certification, with a strong background in forensics and DoD networks.

Qualifications

  • Active TS/SCI security clearance required.
  • GCFA certification required (GIAC Certified Forensic Analyst).
  • Experience with DoD network topology and DMZ protection.
  • Proficient in incident response, analysis, and reporting.
  • Experience with packet capture and tools like WireShark and Snort.
  • Knowledge of MITRE ATT&CK framework.
  • BA/BS or MA/MS degree.

Responsibilities

  • Open intrusion investigations upon suspicious activity on DoD networks.
  • Lead incident response processes and remediation actions.
  • Generate end-of-mission reports (MISREPS) with high accuracy.
  • Provide DCO technical support to law enforcement and CI agencies as needed.
  • Coordinate with crews and plan incident response deployments.

Skills

Incident response
Network forensics
Log analysis
MITRE ATT&CK
WireShark/Snort
DoD network knowledge
EnCase/FTK

Education

BA/BS or MA/MS

Tools

WireShark
Snort
EnCase
EnCase Enterprise
FTK

Job description

San Antonio, TX, USA •

Lackland Air Force Base, San Antonio, TX, USA

Job Description

Posted Wednesday, July 1, 2026 at 5:00 AM

STS Systems Defense, LLC (SSD) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking an Incident Response Officer (Intermediate) to support our mission at Lackland AFB in San Antonio, TX.

What You’ll Do:
  • Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
  • Participate and contribute to lessons learned meetings and briefings.
  • When CAT events are escalated to incident response, complete incident response process, including: preparation, identification and scoping, containment, eradication and remediation, recovery, and lessons learned.
  • Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‑intelligence agencies and activities if required.
  • Support planned and same‑day Incident Response deployments.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. (CDRL A002)
  • Conduct cyber investigations in order to determine the initial vector and overall timeline of intrusion, accurately identify the threat, determine the full scope of impact, and develop containment and remediation actions for approval.
  • Author and review incident report forms (IRF) for security incidents within JEMS. Ensure the document is accurate and provides the correct amount of technical detail needed. (CDRL A008)
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‑intelligence agencies and activities if required.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Provide computer security‑related support to AF field units (examples: 688 Cyber Wing Squadrons, Base Communications Squadrons, Mission Defense Teams), as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
  • Initiate emergency checklists due to imminent threat, as directed by Crew Commander. Call emergency responders (Security Forces/Fire Department etc.) if needed via 911. The Crew Commander is responsible for all official reporting.
  • Inform Crew Commander for all anomalies to include, but not limited to: utility outages, flooding, sick/missing members, or any other irregularity with the potential to adversely impact the mission.
  • Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander.
  • Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable.
  • When assigned as CDO Mission Lead, assign tasks to CDOs as prioritized by the Crew Commander, accounting for all required mission systems and functions.
  • Design incident response plans (IRP) as directed by the Crew Commander. Ensure CDOs are briefed on objectives, ROEs, plans, contingencies, and applicable TTPs.
  • Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates, and TAR submissions.
  • Coordinate with CDO, FMA, DCC, ESM, CTE&A, and intelligence as required. Provide force presentation recommendations to Crew Commander.
What You Bring:
Requirements:
  • Active TS/SCI
  • GCFA Cert required (GIAC Certified Forensic Analyst)
  • Extensive knowledge of network firewalls, computer and server log analysis, computer network servers (DNS, proxy, e‑mail, domain controller, file server, Active Directory) and analysis of their logs; extensive knowledge of digital evidence collection, handling and security
  • Experience with computer incident response and analysis and report dissemination
  • Extensive knowledge and experience with network packet capture and analysis software such as WireShark (Ethereal) and Snort
  • Experience with standard DoD network topology and DMZ boundary protection
  • Experience with system analysis software (i.e. EnCase/EnCase Enterprise or FTK), software coding and debugging, and the virtual machine (VM) environment.
  • Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)
  • BA/BS or MA/MS
What We Offer:

STS Systems Defense, LLC (SSD) offers a competitive benefits package to include paid holidays, paid time off including sick and vacation leave, medical, dental and vision insurance, flexible spending accounts, short and long term disability, company paid life insurance, 401(k) with a company match and discretionary profit sharing and tuition reimbursement.

SSD is an Equal Opportunity Employer. Employment decisions are made without regard to any protected category. Hiring preference will be given to BBNC shareholders, their spouses and descendants and Alaska Natives in accordance with Public Law 93-638

Lackland Air Force Base, San Antonio, TX, USA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Operator (Intermediate)
Cyber Defense Operator (Intermediate)

Ssd Anc • San Antonio (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Paid holidays
Medical insurance
401(k) with company match
Emerging Threats Analyst
Emerging Threats Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 85,000 - 110,000
Medical, dental and vision insurance
401(k) with company match
Paid holidays and time off
Signature Writer – Intermediate – Cyber Security
Signature Writer – Intermediate – Cyber Security

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 180,000
Paid holidays
401(k) with company match
Tuition reimbursement
Incident Response Officer - Intermediate (TS/SCI, GCFA)
Incident Response Officer - Intermediate (TS/SCI, GCFA)

Ssd Anc • San Antonio (TX)

On-site
USD 110,000 - 150,000
Health insurance
Paid time off
401(k) with company match
+1
Cyber Threat Emulation & Analyst
Cyber Threat Emulation & Analyst

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 80,000 - 110,000
Paid holidays
Paid time off
Medical insurance
+1
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IP Secure, LLC • Town of Texas (WI)

On-site
USD 110,000 - 140,000
Medical
Dental
Vision
+9
Content Developer (SIEM Cyber Security)
Content Developer (SIEM Cyber Security)

STS Systems Support, LLC • San Antonio (TX)

On-site
USD 90,000 - 120,000
Paid holidays
Medical, dental, and vision insurance
401(k) with company match
Cyber Data Engineer
Cyber Data Engineer

Ssd Anc • San Antonio (TX)

On-site
USD 120,000 - 160,000
Tuition reimbursement
Medical and vision insurance
Paid holidays and PTO
Cyber Defense Operator (CDO)
Cyber Defense Operator (CDO)

IPSecure, Inc • San Antonio (TX)

On-site
USD 80,000 - 120,000
Unlimited Vacation
Education and Certification Reimbursement Program
401(k) retirement plan with employer match
+1
Network Security Analyst 0056A
Network Security Analyst 0056A

Sistema Technologies Inc. • San Antonio (TX)

Hybrid
USD 90,000 - 140,000