Cyber Defense Operator (CDO)
SMS Data Products Group, Inc. - Lackland Air Force Base, TX
Hiring: Cyber Defense Operator (CDO) Company: SMS Data Products Group, Inc. Location: Lackland Air Force Base, TX Job Posted Time: 2026-09-16 21:22:23 Employment Type: On-site Target Skills & Keywords : Assembly, DNS, SIEM, SOC, TCP/IP About the job Required Skills: •Conduct near real-time network security monitoring and intrusion detection analysis across networks and systems •Review IDS/IPS alerts per Operating Instruction (OI) and checklists •Conduct host security monitoring, alert review, intrusion detection analysis, and event analysis and triage •Develop, Review and Maintain procedures related to the overall monitoring of Hosts/Systems. •Monitor security sensors to analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify and correlate security issues/events and review logs to identify intrusions for remediation. •Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources. •Analyze traffic/logs/events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. •Record who, what, where, why and when for any identified suspicious activity in case management system (CMS) to enable additional investigations. Qualifications: •A minimum of five (5) years of experience in cyber defense operations, network security monitoring, intrusion detection analysis, or a related discipline within a DoD or Intelligence Community environment. •High School Diploma or GED required. •8140 IAT Level 1 CND & GCFA certified •General knowledge of cyber security frameworks, such as the Cyber Kill Chain, MITRE ATT&CK, and the NIST 800 series •General knowledge of physical computer components and architectures, including the functions of computer domains, directory services, various components and peripherals, basic programming concepts, assembly codes, TCP/IP, OSI models, underlying networking protocols (e.g., DNS, ARP, etc.), security hardware and software •Candidate must be self-motivated and able to perform with minimal supervision •Knowledge of cyber forensic collection, preservation, and chain of custody •Prior AFCERT / DCO / SOC experience supporting government networks. •Operational familiarity with producing operational deliverables in a regulated environment (formal ticketing, incident timelines, evidence handling). Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!