
Cybersecurity Operations Analyst II (R-00170)
True Zero Technologies
šŗšø United States
On-site
2 months ago
- Risk Management
- Incident Response
- Secret Clearance
- CCNA
- CySA+
- GSEC
- CCNP
- CISSP
- GCIH
- CCSP
- CEH
- GCFA
- ATT&CK
- Microsoft Defender
- Splunk
- Pension
2 months ago
Job Summary and Duties
- Lead response activities for USCYBERCOM and DCDC directives, managing the lifecycle of
Situational Awareness Reports (SAR) and ensuring all assets remain compliant with OPORDs,
TASKORDs, IAVM notifications, and STIG requirements by published deadlines. - Conduct deep-dive forensic investigations into cybersecurity events (data loss, unauthorized
access, network exploits) to determine nature and scope; identify corrective actions for
containment, eradication, and recovery. - Perform thorough post-incident reviews to derive lessons learned, identify security gaps, and
implement preventive measures to strengthen the programās long-term defense posture. - Provide expert guidance on cybersecurity directives and risk management policies; review
POA&Ms for technical clarity and sound judgment to ensure acceptable remediation timeframes
for security controls. - Oversee enterprise-wide monitoring and logging across network infrastructure and endpoints to
ensure the rapid detection and response to cyber incidents. - Maintain and evolve IR SOPs in strict accordance with CJCSM 6510.01B, NIST SP 800-61R2,
and DOW regulations to ensure procedural alignment with industry best practices. - Translate technical findings into regular status reports for program leadership, DOW officials,
and USCYBERCOM /DCDC repositories, detailing incident impact, effectiveness of response
strategies, and lessons learned. - Drive the evolution of incident response capabilities by identifying weaknesses, recommending
advanced technologies, and implementing enhanced processes to stay ahead of evolving cyber
threats. - Support DOW CIO data collection by reviewing PPSM, CAP, SNAP, and GIAP requests against
DISA guidelines; cross-train team members on emerging defense techniques and provide after-
hours investigative support for critical incidents.
Job Qualifications
- Bachelorās degree in computer scienceĀ or related field
- U.S. CitizenshipĀ and anĀ activeĀ Secret ClearanceĀ (required)Ā with the ability to obtain and maintain a Top-Secret Clearance.
- Active DoD 8570 IAT Level IIĀ certification or greater, including at least one of the following certifications in good standing: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISSP (or Associate), GCED, GCIH, or CCSP.
- Active DoD 8570 CSSP Incident Responder certification a plus, including at least one of the following certifications in good standing: CEH, CFR, CCNA Cyber Ops, CHFI, CySA+, GCFA, GCIH, SCYBER, or PenTest+
- Knowledge of Incident Response Handling Procedures (NIST SP 800-61)
- Familiarity with cyber adversary tactics and frameworks (such as ATT&CK and D3FEND)
- Knowledge of one or more of the following cybersecurity tools:
- Trellix/ESS
- Tanium
- Microsoft Defender Endpoint
- BeyondTrust
- Splunk
- Great communication skills and attention to detail.
- 8+ yearsĀ in Information Technology or Information Security withĀ 5+ yearsĀ performing Cybersecurity Operations and Incident Response
- Required to work onsite daily at our DoD customer office location in Alexandria, VA or Seaside, California.
Cybersecurity Operations Analyst II (R-00170) Ā· True Zero Technologies