Tier 3 DCO Senior Analyst / Threat Hunter

BreakPoint Labs LLC

South Carolina

On-site

USD 110,000 - 140,000

Full time

7 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

BreakPoint Labs LLC is seeking a Tier 3 DCO Watch Analyst to lead complex incident response, conduct proactive threat hunting, and enhance detection capabilities within a CSSP environment. The analyst coordinates with internal and external stakeholders, leads purple team exercises, and ensures strict compliance with CJCSM 6510.01B standards.

Responsibilities include directing incident response campaigns, refining detection mechanisms, performing forensic analysis, and mentoring junior analysts.

Qualifications

  • 5+ years supporting CSSP or similar SOC role.
  • Deep knowledge of CJCSM 6510.01B incident response procedures.
  • Experience with IDS/IPS solutions and rule development.
  • DoD 8570 IAT Level II certification and CSSP/CND certification.
  • DoD Secret clearance and related security requirements.

Responsibilities

  • Lead incident response efforts, including analysis, mitigation, and reporting of significant incidents per CJCSM 6510.01B.
  • Manage incident response campaigns by developing strategies, coordinating multi-team efforts, and ensuring comprehensive resolution and reporting.
  • Conduct proactive threat hunting to identify advanced threats and network vulnerabilities.
  • Lead purple team exercises with red and blue teams to evaluate and enhance detection and response capabilities.
  • Evaluate and refine detection mechanisms, including IDS/IPS signatures and log correlation rules.
  • Perform digital forensics on Windows and other operating systems to support investigations.
  • Coordinate with reporting agencies and subscriber sites for comprehensive incident analysis and reporting.
  • Develop and maintain internal SOP documentation aligned with CJCSM 6510.01B.
  • Provide 24/7 support for incident response and mentor junior analysts.

Skills

Incident response
Threat hunting
IDS/IPS expertise
Operational leadership

Education

Bachelor's degree in Cybersecurity / related field

Tools

IDS/IPS systems
Log correlation tools

Job description

BreakPoint Labs is seeking a Tier 3 DCO Watch Analyst responsible for leading complex incident response, conducting proactive threat hunting, and enhancing detection capabilities within a Cybersecurity Service Provider (CSSP) environment. The analyst oversees incident analysis, coordinates with internal and external stakeholders, leads purple team exercises, and drives improvements to detection and response capabilities. This position requires advanced expertise, operational leadership, and strict compliance with CJCSM 6510.01B standards.

Required Responsibilities:
  • Lead incident response efforts, including analysis, mitigation, and reporting of significant incidents per CJCSM 6510.01B.
  • Manage incident response campaigns by developing strategies, coordinating multi-team efforts, and ensuring comprehensive resolution and reporting.
  • Conduct proactive threat hunting to identify advanced threats and network vulnerabilities.
  • Lead purple team exercises in collaboration with red and blue teams to evaluate and enhance detection and response capabilities.
  • Evaluate and refine detection mechanisms, including IDS/IPS signatures and log correlation rules, to improve accuracy and reduce false positives.
  • Perform advanced network and host-based digital forensics on Windows and other operating systems to support investigations.
  • Coordinate with reporting agencies and subscriber sites for comprehensive incident analysis and reporting.
  • Develop and maintain internal SOP documentation, ensuring alignment with CJCSM 6510.01B and applicable directives.
  • Work with a team to provide 24/7 support for incident response, including non-core hours, and mentor junior analysts.
  • Participate in program reviews, product evaluations, and onsite certification assessments.
  • Work four 10-hour shifts (Sunday-Wednesday or Wednesday Saturday); shift placement at management’s discretion.
  • Surge support may be required to support incident response actions.
  • Up to 10% travel may be required, to include OCONUS locations.
Required Experience:
  • 5 years experience supporting CSSP or similar SOC technical role.
  • Comprehensive knowledge of CJCSM 6510.01B and incident response procedures.
  • In depth expertise with IDS/IPS solutions, including signature development and optimization.
Certifications Required:

DoD 8570 IAT Level II certification and CSSP/CND certification
required.

Security Clearance Required:

DoD Secret

Education Level Required:

Bachelor’s Degree in Cybersecurity, Computer, Electrical, or Electronics Engineering, OR Mathematics with a concentration in computer science or equivalent

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Tier 3 DCO Senior Analyst / Threat Hunter (Malware)
Tier 3 DCO Senior Analyst / Threat Hunter (Malware)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 95,000 - 150,000
Tier 3 DCO Threat Hunter & IR Lead
Tier 3 DCO Threat Hunter & IR Lead

BreakPoint Labs LLC • South Carolina

On-site
USD 110,000 - 140,000
Tier 1 Defensive Cyber Operations (DCO) Analyst
Tier 1 Defensive Cyber Operations (DCO) Analyst

BreakPoint Labs LLC • Hawaii

On-site
USD 70,000 - 95,000
Tier 3 DCO (Defensive Cyber Operations) Watch Analyst
Tier 3 DCO (Defensive Cyber Operations) Watch Analyst

Valiant Solutions • South Carolina

On-site
USD 80,000 - 120,000
Cyber Defense Operations Analyst - Tier 1 (CSSP)
Cyber Defense Operations Analyst - Tier 1 (CSSP)

BreakPoint Labs LLC • Hawaii

On-site
USD 70,000 - 95,000
Detection Engineer (Cloud)
Detection Engineer (Cloud)

BreakPoint Labs LLC • Charleston (SC), Northern (KY)

Hybrid
USD 120,000 - 150,000
Senior Tier 3 DCO Watch Analyst – Incident Response Lead
Senior Tier 3 DCO Watch Analyst – Incident Response Lead

Valiant Solutions • South Carolina

On-site
USD 80,000 - 120,000
Incident Response Expert - III
Incident Response Expert - III

Base One Technologies • Arlington (VA), Northern (KY)

Hybrid
USD 140,000 - 190,000
Incident Response Senior Analyst (Tier 3)
Incident Response Senior Analyst (Tier 3)

Forensic Focus Limited • Virginia (IL), Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000