Demo

Cyber Defense Operator

TEKsystems c/o Allegis Group
San Antonio, TX Full Time
POSTED ON 4/24/2025
AVAILABLE BEFORE 6/24/2025

Job Details

Description
Review all IDS/IPS alerts per AFCERT Operating Instruction (OI) and checklists at the AOL, COOP, or Ops Floor. Conduct host security monitoring, alert review, and intrusion detection analysis for the AFIN-SOC mission.
Develop, Review and Maintain procedures related to the overall monitoring of Hosts/Systems.
Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. (CDRL A002)
Monitor security sensors to analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify and correlate security issues/events and review logs to identify intrusions for remediation. Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources, including but not limited to Big Data Platform (BDP).
Analyze traffic/logs/events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
Record who, what, where, why and when for any identified suspicious activity in case management system (CMS) case to enable additional investigations. (CDRL A008)
Conduct triage of suspicious activity alerts and logs in order to make a fast and accurate triage decision. (CDRL A008)
Enter event data into mission support systems in accordance with AFIN SOC operational procedures and reports. (CDRL A008)
Provide monthly performance metrics including but not limited to: readiness, qualifications, events processed, CAT events and incidents identified. (CDRL A005)
Escalate security incidents using established policies and procedures.
Generate end of mission reports (MISREPS) and provide pass-on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
Provide computer security-related support to AF field units (examples: 688 Cyber Wing Squadrons, Base Communications Squadrons, Mission Defense Teams), as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
Provide focused DCO tailored analysis and monitoring operations of specified sensor locations during contingency operations and in support of named DCO operations and exercises.
Conduct 24x7x365 near real-time network security monitoring and intrusion detection analysis for the networks, systems monitored using AF's selected IDS/IPS capabilities with no more than a 1% error rate. (CDRL A005)
Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated as needed through the approved documentation system, in order to ensure efficient transition when personnel rotate.
Create and document metrics for reporting and analysis to improve alert triage processes and mission execution. (CDRL A009)
Provide requested information to operational leadership as it relates to mission execution.
Conduct intake of administrative and operational communication from external agencies and route the communication to the Mission Lead/Crew Commander.
Perform security checks every four hours to verify external doors are properly closed and no suspicious activity is taking place around the facility. If suspicious activity is observed or suspected, contact and inform the Crew Commander.
Initiate emergency checklists due to imminent threat, as directed by Crew Commander. Call emergency responders (Security Forces/Fire Department etc.) if needed via 911. The Crew Commander is responsible for all official reporting.
Inform Crew Commander for all anomalies to include, but not limited to: utility outages, flooding, sick/missing members, or any other irregularity with the potential to adversely impact the mission.
Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)
Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable.
Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander.
Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates and TAR submissions.
Execute approved scoping actions. Find endpoints matching target: accounts, registry configurations, files, processes, IP addresses, ports, domains, or other correlating data to determine extent of compromises.
Execute approved response actions against target: accounts, registry configurations, files, processes, IP addresses, ports, domains, or other system components to contain compromises.
Analyze threat intelligence (TIPPERS) as directed by CDO Mission Lead or Crew Commander to include contextual information, IoCs, TTPs, vulnerabilities, effects, and actionable intelligence about threats mapped to the MITRE threat framework.
Work with CDO Mission Lead for prioritization and assignment of tasks.
Provide CDO Mission Lead support, notify CDOs of Crew Commander prioritized tasks, tracking all required mission systems and functions.
Skills
Cyber security, Soc, Incident response, ids, siem
Top Skills Details
Cyber security,Soc,Incident response,ids,siem
Additional Skills & Qualifications
Active TS/SCI
Intermediate knowledge with one or more of the IDS/IPS systems currently in use by the Department of Defense (DoD), Services, and Agencies (i.e., AF, Navy, Army, DC3, DISA) or Federal Government and intermediate experience in the following areas: IP addressing and domain name service; network components; Transmission Control Protocol (TCP)/User Datagram Protocol (UDP), File Transfer Protocol (FTP), Simple Mail Transfer Protocol (SMTP), and Hypertext Transfer Protocol (HTTP); and understand the network Open Systems Interconnection (OSI) model. Extensive knowledge of MITRE ATT&CK framework, and its uses within the cybersecurity community (e.g., Open Source projects)
Pay and Benefits
The pay range for this position is $40.00 - $55.00/hr.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:
Medical, dental & vision
Critical Illness, Accident, and Hospital
401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available
Life Insurance (Voluntary Life & AD&D for the employee and dependents)
Short and long-term disability
Health Spending Account (HSA)
Transportation benefits
Employee Assistance Program
Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a fully onsite position in San Antonio,TX.
Application Deadline
This position is anticipated to close on May 6, 2025.

About TEKsystems:

We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.

Salary : $40 - $55

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cyber Defense Operator?

Sign up to receive alerts about other jobs on the Cyber Defense Operator career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$99,793 - $130,112
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$163,631 - $209,073
Income Estimation: 
$192,911 - $256,346
Income Estimation: 
$150,041 - $190,701
Income Estimation: 
$163,631 - $209,073
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965

Sign up to receive alerts about other jobs with skills like those required for the Cyber Defense Operator.

Click the checkbox next to the jobs that you are interested in.

  • Cybersecurity Skill

    • Income Estimation: $76,865 - $99,440
    • Income Estimation: $77,991 - $108,747
  • Data Control Skill

    • Income Estimation: $54,658 - $80,222
    • Income Estimation: $58,384 - $80,655
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at TEKsystems c/o Allegis Group

TEKsystems c/o Allegis Group
Hired Organization Address Omaha, NE Full Time
Job Details Description We are seeking a skilled IVR Developer with expertise in few or more of IVR development technolo...
TEKsystems c/o Allegis Group
Hired Organization Address Westbrook, ME Full Time
Job Details Description Data Analyst TOP (3) REQUIRED SKILLSETS: Able to aggregate data from multiple sources and build ...
TEKsystems c/o Allegis Group
Hired Organization Address Las Vegas, NV Full Time
Job Details Description Network or CCNA preferred. Project: Planning Tech will provide support for the building and deve...
TEKsystems c/o Allegis Group
Hired Organization Address Oklahoma, OK Full Time
Job Details Description Required: Active Clearance. Secret Knowledge of DoD-Secret operations, I need someone who has be...

Not the job you're looking for? Here are some other Cyber Defense Operator jobs in the San Antonio, TX area that may be a better fit.

Cyber Defense Operator (Intermediate)

SGSCANDIDATEPORTAL, San Antonio, TX

Cyber Defense Operator (Intermediate)

SSSCANDIDATEPORTAL, San Antonio, TX

AI Assistant is available now!

Feel free to start your new journey!