Test Event Cybersecurity Lead

Cybersecurity Jobs

Colorado Springs (CO)

On-site

USD 110,000 - 140,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

401(k)
401(k) matching
Dental insurance
Flexible schedule
Health insurance
Life insurance
Paid time off
Tuition reimbursement
Vision insurance

Job summary

Cybersecurity Jobs seeks a senior cybersecurity lead to support the Missile Defense Agency on the IRES contract. You will lead engineers and ISSOs, own test-package health, and drive vulnerability management and security posture across mission environments.

Responsibilities include implementing ACAS/Nessus scans, DISA STIGs, PPSM baselines, and RMF guidance, while coordinating incident response and threat hunting in Windows/Linux ecosystems.

Qualifications

  • 6+ years of general security experience.
  • 4+ years directly related to defensive cyber operations.
  • 6+ months in a management or leadership role.
  • Hands-on SIEM experience with data ingestion and dashboards.
  • Experience with EDR/endpoint protection and Windows/Linux.
  • ACAS, vulnerability management, and DoD RMF familiarity.
  • Active DoD Secret clearance and IAT Level II at minimum.

Responsibilities

  • Lead engineers and ISSOs to deliver defensive cyber operations and health checks.
  • Own health and cybersecurity for test event packages; manage scans and remediation.
  • Architect cybersecurity processes; monitor dashboards and threat hunting.
  • Schedule and run ACAS scans; track remediation timelines.
  • Implement DISA STIGs; manage PPSM baselines.
  • Support RMF lifecycle steps with NIST guidance.
  • Triage security incidents; perform root-cause forensics.
  • Oversee Python/PowerShell/Bash automation and ELK log analysis.
  • Manage VMware ESXi environments and Ansible configurations.
  • Respond to high-priority alerts during on-call rotation.

Skills

Leadership
SIEM
EDR
Windows
Linux
On-call
RMF

Tools

ACAS
Nessus
Tenable SecurityCenter
ELK Stack
PowerShell
Python
Ansible
VMware vSphere/ESXi
NIST SP 800-37
NIST SP 800-53

Job description

Support the Missile Defense Agency (MDA) on the IRES contract by leading defensive cyber operations and cybersecurity health for test event packages.

Responsibilities
  • Lead engineers and ISSOs to deliver defensive cyber operations, vulnerability lifecycle management, and security posture monitoring across mission environments.
  • Own overall health and cybersecurity for test event packages, including work assignment, goal and priority setting, vulnerability scanning via ACAS, endpoint protection, and compliance enforcement aligned with DoD Risk Mals.
  • Architect and manage cybersecurity processes; oversee operational monitoring dashboard construction; support query-based threat hunting across log repositories.
  • Schedule and run credentialed ACAS vulnerability scans; correlate findings, track remediation timelines, and generate technical remediation tickets.
  • Implement, verify, and document DISA STIGs; manage system configurations and enforce PPSM baselines (Ports, Protocols, and Services Management).
  • Support Continuous Monitoring and authorization packages through the DoD RMF lifecycle steps (referencing NIST SP 800-37 / NIST SP 800-53).
  • Triage and contain operational security anomalies; perform preliminary root-cause forensics and support defensive cyber reporting.
  • Oversee engineering work in Python, PowerShell, and Bash to automate administrative tasks, parse security logs, and streamline scan analysis.
  • Oversee engineering work using ELK Stack (Elasticsearch, Logstash, Kibana) or equivalent centralized log aggregation platforms.
  • Oversee engineering work in VMware vSphere / ESXi virtualized infrastructures and automated configuration management with Ansible.
  • Oversee firewall rule management, network access control lists (ALs), and traffic analysis.
  • Respond to high-priority cybersecurity alerts outside standard operational hours during an on-call rotation.
  • Interface with System Administrators, ISSMs, and Network Engineers to validate patches and mitigate identified vulnerabilities.
  • Maintain audit readiness for Command Cyber Readiness Inspections (CCRI) and external cybersecurity assessments.
  • Schedule and manage a team of engineers for test events, including off core hour support.
  • Respond to and triage Cyber Tasking Orders (CTOs) applicable to the managed packages.
Requirements
  • 6+ years of general (full-time) work experience (may be reduced with advanced education completion).
  • 4+ years directly related experience.
  • 6+ months experience in a management or leadership role.
  • Proven hands‑on experience with a SIEM platform, including data ingestion, building security monitoring dashboards, and performing query-based analysis of security events.
  • Experience with an EDR or endpoint protection platform (examples provided: ESS (Trellix), Microsoft Defender for Endpoint).
  • ACAS & vulnerability management: current ACAS certificate, performing vulnerability scans using ACAS (Tenable SecurityCenter/Nessus).
  • Ability to participate in an on‑call rotation and respond to incidents outside standard business hours.
  • Familiarity and experience with both Windows and Linux operating systems.
  • Must meet DoD 8570/8140 IAT Level II at a minimum (examples provided: CompTIA Security+ CE, CySA+, GSEC).
  • Active DoD Secret Security Clearance.
Technologies
  • ACAS, Tenable SecurityCenter, Nessus
  • DISA STIGs, PPSM (Ports, Protocols, and Services Management)
  • NIST SP 800-37, NIST SP 800-53
  • Python, PowerShell, Bash
  • ELK Stack (Elasticsearch, Logstash, Kibana)
  • VMware vSphere, ESXi, Ansible
  • SIEM, Endpoint Detection and Response (ED), Endpoint Protection Platform
  • ESS (Trellix), Microsoft Defender for Endpoint
  • DoD 8570/8140 IAT, CompTIA Security+ CE, CySA+, GSEC
Benefits
  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Flexible schedule
  • Health insurance
  • Life insurance
  • Paid time off
  • Tuition reimbursement
  • Vision insurance
Location
  • Colorado Springs, CO (onsite)
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Mid Cybersecurity Engineer
Mid Cybersecurity Engineer

Cybersecurity Jobs • Colorado Springs (CO)

On-site
USD 100,000 - 145,000
Health, dental, and vision insurance
PTO and holidays
401(k) matching
+5
Cybersecurity Test & Evaluation (T&E) Lead
Cybersecurity Test & Evaluation (T&E) Lead

Lockheed Martin • Colorado Springs (CO)

On-site
USD 121,000 - 224,000
Medical
Dental
Vision
+2
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Cybersecurity Jobs • Colorado Springs (CO)

On-site
USD 90,000 - 190,000
Healthcare and wellness
Financial and retirement
Family support
+3
Network Engineer 2
Network Engineer 2

Cts Technology Solutions, Inc. • Colorado Springs (CO)

On-site
USD 85,000 - 115,000
Referral bonuses
Cyber Security Engineer
Cyber Security Engineer

Triglocon • Arlington (VA)

On-site
USD 110,000 - 150,000
Medical, Dental & Vision Coverage
Paid Time Off
Paid Holidays
+3
Cyber Systems Engineer (ISSE)
Cyber Systems Engineer (ISSE)

Lockheed Martin • Schriever (LA)

On-site
USD 98,000 - 182,000
Flexible work arrangements
401(k) match
Paid time off
Cyber Security Architect
Cyber Security Architect

iQuasar, LLC • Colorado Springs (CO)

On-site
USD 100,000 - 140,000
401(k)
Health insurance
Dental insurance
+2
CYBER SECURITY ENGINEER
CYBER SECURITY ENGINEER

MCSG Technologies • Colorado Springs (CO)

On-site
USD 100,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+2
Cyber Security Engineer
Cyber Security Engineer

Systems Planning & Analysis • Huntsville (AL)

On-site
USD 80,000 - 110,000
Competitive compensation
Industry-leading 401k contribution
Intermediate Cybersecurity Analyst
Intermediate Cybersecurity Analyst

Cybersecurity Jobs • Quantico (VA)

On-site
USD 100,000 - 145,000
Medical insurance
Dental insurance
Vision insurance
+4