|
Position: Blue Team Lead / Sr Cyber Defense Analyst |
|
Job Id: 546 |
# of Openings: 1 |
|
Blue Team Lead / Sr Cyber Defense Analyst
Fort Bragg, NC
SUMMARY:
Founded in 2001, Indigo IT is an award-winning information technology consulting and services company. We are a trusted services provider to government agencies seeking innovative Cloud, Cybersecurity, Knowledge Management, and Enterprise solutions. We know our defense, federal, and civilian customers have critical IT infrastructures that must remain reliable, available, and maximized. Indigo IT is mission focused and committed to maintaining a sense of urgency in anticipating and supporting our customers' technology goals and objectives. Our unique ability to think beyond today allows our clients to stay ahead of their IT challenges. As a Veteran-Friendly employer, we are proudly partnered with the Virginia Values Veterans (V3) Program, and a recipient of the HIRE Vets Gold Medallion Award, which recognizes our commitment to recruiting our nation's Veterans. Recognized on the Inc. 5000 list of America's fastest growing companies in 2020 & 2021 and named as one of the 2022 Best Places to Work in Virginia, we are always looking to hire top talent in the field - come join us today!
The USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) program establishes a dedicated, 24/7/365 cyber defense capability for the U.S. Army Reserve Command CIO/G-6, operating as a Cyber Security Service Provider - Executor (CSSP-E). The team performs continuous network security monitoring, detection, analysis, and incident response across NIPRNet and SIPRNet; integrated assessments under the Computer Defense Assistance Program (Network Assistance Visits, Network Damage Assessments, and web assessments); and Cyber Threat Intelligence collection, correlation, signature development, and finished intelligence production in support of approximately 205,000 Army Reserve personnel.
We are seeking a Blue Team Lead to serve as the senior technical authority for 24/7/365 Blue Team operations and as the Tier 3 / Incident Response Lead. The Lead owns Tier 3 analysis, advanced incident handling, hunt planning, detection-content governance, the Blue Team SOP, and mentorship of Tier 1 and Tier 2 analysts, and is the designated Alternate Program Manager for short absences.
ESSENTIAL FUNCTIONS/RESPONSIBILITIES:
Tier 3 Analysis and Incident Command
- Lead analysis on suspected APT activity and complex intrusions; serve as incident commander for critical incidents and named operations
- Ensure critical blocks are executed within two hours of notification or detection and immediate mitigation actions within 24 hours; ensure 100 percent CJCSM 6510.01B reporting timeliness and ARCYBER portal currency
- Coordinate internal defensive measures with the Theater Signal Command, DoDIN-A staff, and supported Regional Cyber Center, including IP blocking, ACL changes, and signature deployment recommendations to the CCB
- Maintain the Law Enforcement and Counterintelligence point-of-contact roster and coordinate scoped analytic assistance to LE/CI requests
Watch Operations and SOP Ownership
- Own the Blue Team SOP, shift operations plan, pass-down and verbal handoff procedures, escalation criteria, and minimum staffing by tier on each watch
- On-Call Responsibilities - Phone response within 30 mins of incident and on-site reporting within one hour, when required
- Serve as Alternate Program Manager for short PM absences and urgent actions; provide watch backfill when required
Threat Hunting and Detection Content
- Plan and execute hypothesis-driven and indicator-based threat hunt missions; produce the Weekly Threat Hunting Summary
- Govern detection content: SIEM correlation rules, watchlists, YARA, Snort/Suricata, and host-based policies; coordinate signature submissions with the CTI cell and ARCYBER signature working groups
- Provide governance and prioritization for tooling lifecycle and configuration management executed by the assessment/malware analysts
Reporting, Training, and Exercises
- Author the Daily Blue Team Operations Report inputs, Monthly Blue Team Assessment Report, and Quarterly Defensive Readiness Assessment
- Provide on-the-job training and mentorship to Tier 1 and Tier 2 personnel; lead monthly internal DCO training sessions with a COR-approved POI, attendee log, and AAR
- Select and prepare SMEs for ARCYBER, ARNG, USAR, and Joint exercises; contribute to After-Action Reports
EDUCATION, EXPERIENCE, & CERTIFICATIONS:
- Minimum five (5) years of documented, specialized operational experience in cyber defense analysis and incident response in a DoD or enterprise environment
- Bachelor's degree and 7 years of experience
- DoDM 8140.03 qualification for DCWF 511 Cyber Defense Analyst at Advanced proficiency and DCWF 531 Cyber Defense Incident Responder at Advanced proficiency (commercial certifications alone are not sufficient; the 8140.03 qualification matrix governs)
- DCWF 521 Cyber Defense Infrastructure Support Specialist appointment required only if assigned hands-on sensor/SIEM infrastructure duties
- ARCYBER Cyber Intrusion Analysis Program (CIAP) completion desired
- Favorably adjudicated Tier 5 (T5) investigation, or ability to obtain, prior to privileged access
- US Citizenship required
- Current DoD SECRET clearance required (interim SECRET acceptable at start; final SECRET required within 120 days of award)
- Ability to obtain and maintain a DoD Common Access Card and USARC installation access
- Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I, OPSEC Level I, TARP, and CUI training within 30 days of start
SPECIFIC KNOWLEDGE, SKILLS, & ABILITIES:
- Expert-level experience in network security monitoring, incident response, and threat hunting in a DoD or large enterprise SOC/CSSP environment
- Hands-on proficiency with:
- Enterprise SIEM (Elastic preferred)
- Host-based security (Trellix ENS or equivalent) and EDR (Tychon or equivalent)
- Full packet capture, NetFlow, and IDS/IPS (Snort, Suricata, Zeek, Fidelis, Sourcefire)
- Proxy and firewall log analysis
- Demonstrated ability to develop and validate detection content (YARA, Snort/Suricata, SIEM correlation logic) with low false-positive rates
- Deep familiarity with MITRE ATT&CK, CJCSM 6510.01B, AR 25-2, ARCYBER and RCC TTPs, and DoD Cybersecurity Services Evaluator Scoring Matrix expectations
- Experience with forensic evidence handling and chain of custody consistent with ARCYBER Forensics and Malware Analysis procedures
- Proven ability to lead, schedule, and mentor a 24/7 watch team and to design sustainable rotation and handoff procedures
- Working knowledge of CJCSM 6510.01B incident categories and DoD/Army cyber incident reporting requirements
- Excellent interpersonal and written communication skills to interact effectively with Government stakeholders, ARCYBER and Regional Cyber Center counterparts, and team members
- The ability to communicate complex technical findings clearly to non-technical audiences
- A willingness to uncover, document, and communicate deviations from planned outcomes in order to improve processes and prevent recurrence
- A passion for continuous learning and a commitment to stay current with emerging threats, adversary tradecraft, and defensive technologies
Work Environment
- Onsite presence at USARC Headquarters, Fort Bragg, NC required
- Core hours with after-hours on-call rotation; 30-minute telephonic and one-hour on-site response when on call
- CONUS/OCONUS travel in support of assessments and exercises as directed
At Indigo IT, we offer an expansive benefits package for our employees, which includes: Medical, Dental, and Vision coverage options. In addition, we offer 401(k) with company match, Group life and disability, Flex Spending Accounts (FSA), Paid Time Off (PTO), Paid holidays, and Education assistance. We also have in house training programs for employees, we reward thought leadership with bonuses and recognition for publishing, speaking, and innovative thought leadership in our industry.
Indigo IT is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. This employer uses E-Verify.
|
Pay Range: $100,000 - $140,000 per year |
Apply for this Position
|
|