Test Event Cybersecurity Lead
Manager
Analytics
Cyber Security
Cybersecurity Leadership
Cybersecurity Tools
Data Platform
Data Security
Digital Marketing
Endpoint Security
Facilities Management
Information Security
Information Technology (IT)
InfoSec
Log Management
Management
Nessus
Project Management
Risk Management
Security
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
Solution Architecture
Splunk
Splunk Siem
Tenable
Job Description
Support the Missile Defense Agency (MDA) on the IRES contract by leading defensive cyber operations and cybersecurity health for test event packages.
Responsibilities
- Lead engineers and ISSOs to deliver defensive cyber operations, vulnerability lifecycle management, and security posture monitoring across mission environments.
- Own overall health and cybersecurity for test event packages, including work assignment, goal and priority setting, vulnerability scanning via ACAS, endpoint protection, and compliance enforcement aligned with DoD Risk Mals.
- Architect and manage cybersecurity processes; oversee operational monitoring dashboard construction; support query-based threat hunting across log repositories.
- Schedule and run credentialed ACAS vulnerability scans; correlate findings, track remediation timelines, and generate technical remediation tickets.
- Implement, verify, and document DISA STIGs; manage system configurations and enforce PPSM baselines (Ports, Protocols, and Services Management).
- Support Continuous Monitoring and authorization packages through the DoD RMF lifecycle steps (referencing NIST SP 800-37 / NIST SP 800-53).
- Triage and contain operational security anomalies; perform preliminary root-cause forensics and support defensive cyber reporting.
- Oversee engineering work in Python, PowerShell, and Bash to automate administrative tasks, parse security logs, and streamline scan analysis.
- Oversee engineering work using ELK Stack (Elasticsearch, Logstash, Kibana) or equivalent centralized log aggregation platforms.
- Oversee engineering work in VMware vSphere / ESXi virtualized infrastructures and automated configuration management with Ansible.
- Oversee firewall rule management, network access control lists (ALs), and traffic analysis.
- Respond to high-priority cybersecurity alerts outside standard operational hours during an on-call rotation.
- Interface with System Administrators, ISSMs, and Network Engineers to validate patches and mitigate identified vulnerabilities.
- Maintain audit readiness for Command Cyber Readiness Inspections (CCRI) and external cybersecurity assessments.
- Schedule and manage a team of engineers for test events, including off core hour support.
- Respond to and triage Cyber Tasking Orders (CTOs) applicable to the managed packages.
Requirements
- 6+ years of general (full-time) work experience (may be reduced with advanced education completion).
- 4+ years directly related experience.
- 6+ months experience in a management or leadership role.
- Proven hands-on experience with a SIEM platform, including data ingestion, building security monitoring dashboards, and performing query-based analysis of security events.
- Experience with an EDR or endpoint protection platform (examples provided: ESS (Trellix), Microsoft Defender for Endpoint).
- ACAS & vulnerability management: current ACAS certificate, performing vulnerability scans using ACAS (Tenable SecurityCenter/Nessus).
- Ability to participate in an on-call rotation and respond to incidents outside standard business hours.
- Familiarity and experience with both Windows and Linux operating systems.
- Must meet DoD 8570/8140 IAT Level II at a minimum (examples provided: CompTIA Security+ CE, CySA+, GSEC).
- Active DoD Secret Security Clearance.
Technologies
- ACAS, Tenable SecurityCenter, Nessus
- DISA STIGs, PPSM (Ports, Protocols, and Services Management)
- NIST SP 800-37, NIST SP 800-53
- Python, PowerShell, Bash
- ELK Stack (Elasticsearch, Logstash, Kibana)
- VMware vSphere, ESXi, Ansible
- SIEM, Endpoint Detection and Response (ED), Endpoint Protection Platform
- ESS (Trellix), Microsoft Defender for Endpoint
- DoD 8570/8140 IAT, CompTIA Security+ CE, CySA+, GSEC
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible schedule
- Health insurance
- Life insurance
- Paid time off
- Tuition reimbursement
- Vision insurance
Location
- Colorado Springs, CO (onsite)