Defensive Cyber Operations Lead (Senior Watch Officer)

Description

Job Description:

This position provides technical leadership to C5ISR Center Sustaining Base Network Assurance Branch (SBNAB) Defensive Cyber Operations (DCO) Security Operations Center (SOC). Beyond advising and guiding technical matters, this position is tasked with driving implementation and adoption of new tools, research, capabilities, frameworks, and methodologies while ensuring those already in use are implemented, utilized properly, and improved.

Primary Responsibilities
  • Provide technical leadership to SBNAB DCO team
  • Drive implementation and adoption of new tools, capabilities, frameworks, and methodologies across all teams within the SOC
  • Provide technical guidance and support to SBNAB Branch Operations Manager and Government leadership
  • Identify and offer solutions to gaps in capabilities and visibility
  • Promote and drive research and implementation of automation and process efficiencies


Basic Qualifications
  • Bachelor's degree and 5+ years of prior IT experience, or Associate degree with 7+ years of experience. Additional certifications and experience may be considered in lieu of degree.
  • 5+ years' experience working in a SOC environment
  • DoD 8570 IAT III certifications required prior to starting
  • Prior experience supervising employees of various labor categories and skills in efforts similar in size and scope to the SBNAB DCO program
  • Advanced knowledge of solution development techniques and best practices related to demonstration, pilot, and test management and operations.
  • Demonstrated advanced knowledge of industry accepted standards.
  • Demonstrated experience with researching and fielding new and innovative technology;
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic finding.
  • Strong analytical and troubleshooting skills.
  • Must be a US Citizen.
  • Candidate must possess an active TS/SCI, with SAP eligibility


Preferred Qualifications
  • Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.
  • Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization.
  • Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.
  • Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework.


Pay Range: