Support the Missile Defense Agency (MDA) on the IRES contract by leading defensive cyber operations and cybersecurity health for test event packages.
Responsibilities
- Lead engineers and ISSOs to deliver defensive cyber operations, vulnerability lifecycle management, and security posture monitoring across mission environments.
- Own overall health and cybersecurity for test event packages, including work assignment, goal and priority setting, vulnerability scanning via ACAS , endpoint protection, and compliance enforcement aligned with DoD Risk Mals .
- Architect and manage cybersecurity processes; oversee operational monitoring dashboard construction; support query-based threat hunting across log repositories.
- Schedule and run credentialed ACAS vulnerability scans; correlate findings, track remediation timelines, and generate technical remediation tickets.
- Implement, verify, and document DISA STIGs ; manage system configurations and enforce PPSM baselines (Ports, Protocols, and Services Management).
- Support Continuous Monitoring and authorization packages through the DoD RMF lifecycle steps (referencing NIST SP 800-37 / NIST SP 800-53 ).
- Triage and contain operational security anomalies; perform preliminary root-cause forensics and support defensive cyber reporting.
- Oversee engineering work in Python , PowerShell , and Bash to automate administrative tasks, parse security logs, and streamline scan analysis.
- Oversee engineering work using ELK Stack (Elasticsearch, Logstash, Kibana) or equivalent centralized log aggregation platforms.
- Oversee engineering work in VMware vSphere / ESXi virtualized infrastructures and automated configuration management with Ansible .
- Oversee firewall rule management, network access control lists (ALs), and traffic analysis.
- Respond to high-priority cybersecurity alerts outside standard operational hours during an on-call rotation.
- Interface with System Administrators, ISSMs, and Network Engineers to validate patches and mitigate identified vulnerabilities.
- Maintain audit readiness for Command Cyber Readiness Inspections (CCRI) and external cybersecurity assessments.
- Schedule and manage a team of engineers for test events, including off core hour support.
- Respond to and triage Cyber Tasking Orders (CTOs) applicable to the managed packages.
Requirements
- 6+ years of general (full-time) work experience (may be reduced with advanced education completion).
- 4+ years directly related experience.
- 6+ months experience in a management or leadership role.
- Proven hands‑on experience with a SIEM platform, including data ingestion, building security monitoring dashboards, and performing query-based analysis of security events.
- Experience with an EDR or endpoint protection platform (examples provided: ESS (Trellix) , Microsoft Defender for Endpoint ).
- ACAS & vulnerability management : current ACAS certificate, performing vulnerability scans using ACAS (Tenable SecurityCenter/Nessus).
- Ability to participate in an on‑call rotation and respond to incidents outside standard business hours.
- Familiarity and experience with both Windows and Linux operating systems.
- Must meet DoD 8570/8140 IAT Level II at a minimum (examples provided: CompTIA Security+ CE, CySA+, GSEC).
- Active DoD Secret Security Clearance.
Technologies
- ACAS, Tenable SecurityCenter, Nessus
- DISA STIGs, PPSM (Ports, Protocols, and Services Management)
- NIST SP 800-37, NIST SP 800-53
- Python, PowerShell, Bash
- ELK Stack (Elasticsearch, Logstash, Kibana)
- VMware vSphere, ESXi, Ansible
- SIEM, Endpoint Detection and Response (ED), Endpoint Protection Platform
- ESS (Trellix), Microsoft Defender for Endpoint
- DoD 8570/8140 IAT, CompTIA Security+ CE, CySA+, GSEC
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible schedule
- Health insurance
- Life insurance
- Paid time off
- Tuition reimbursement
- Vision insurance
Location
- Colorado Springs, CO (onsite)
Test Event Cybersecurity Lead in colorado springs at Unknown Company
This position is listed as contract and onsite.