×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cyber Defense Operator; Intermediate

Job in San Antonio, Bexar County, Texas, 78208, USA
Listing for: STS Systems Support, LLC
Full Time position
Listed on 2025-12-01
Job specializations:
  • Security
    Cybersecurity
Job Description & How to Apply Below
Position: Cyber Defense Operator (Intermediate)

Lackland Air Force Base, San Antonio, TX, USA

Job Description

Posted Monday, September 8, 2025 at 5:00 AM

STS Systems Support, LLC (SSS) is seeking a Cyber Defense Operator (Intermediate) to support our ongoing mission at Lackland Air Force Base in San Antonio, TX.

What You'll Do:

  • Review all IDS/IPS alerts per AFCERT Operating Instruction (OI) and checklists at the AOL, COOP, or Ops Floor. Conduct host security monitoring, alert review, and intrusion detection analysis for the AFIN‑SOC mission.
  • Develop, Review and Maintain procedures related to the overall monitoring of Hosts/Systems.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities. (CDRL A002)
  • Monitor security sensors to analyze Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify and correlate security issues/events and review logs to identify intrusions for remediation. Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources, including but not limited to Big Data Platform (BDP).
  • Analyze traffic/logs/events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Record who, what, where, why and when for any identified suspicious activity in case management system (CMS) case to enable additional investigations. (CDRL A008)
  • Conduct triage of suspicious activity alerts and logs in order to make a fast and accurate triage decision. (CDRL A008)
  • Enter event data into mission support systems in accordance with AFIN SOC operational procedures and reports. (CDRL A008)
  • Provide monthly performance metrics including but not limited to: readiness, qualifications, events processed, CAT events and incidents identified. (CDRL A005)
  • Escalate security incidents using established policies and procedures.
  • Generate end of mission reports (MISREPS) and provide pass‑on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Provide computer security‑related support to AF field units (examples: 688 Cyber Wing Squadrons, Base Communications Squadrons, Mission Defense Teams), as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
  • Provide focused DCO tailored analysis and monitoring operations of specified sensor locations during contingency operations and in support of named DCO operations and exercises.
  • Conduct 24x7x365 near real‑time network security monitoring and intrusion detection analysis for the networks, systems monitored using AF’s selected IDS/IPS capabilities with no more than a 1% error rate. (CDRL A005)
  • Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated as needed through the approved documentation system, in order to ensure efficient transition when personnel rotate.
  • Create and document metrics for reporting and analysis to improve alert triage processes and mission execution. (CDRL A009)
  • Provide requested information to operational leadership as it relates to mission execution.
  • Conduct intake of administrative and operational communication from external agencies and route the communication to the Mission Lead/Crew Commander.
  • Perform security checks every four hours to verify external doors are properly closed and no suspicious activity is taking place around the facility. If suspicious activity is observed or suspected, contact and inform the Crew Commander.
  • Initiate emergency checklists due to imminent threat, as directed by Crew Commander. Call emergency responders (Security Forces/Fire Department etc.) if needed via 911. The Crew Commander is responsible for all official reporting.
  • Inform Crew Commander for all anomalies…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary