Cybersecurity Operations Analyst (R-00156)

D.c.Full-Timemid
OperationsOtherEngineerOperations Analyst
0 views0 saves0 applied

Quick Summary

Requirements Summary

CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISSP (or Associate), GCED, GCIH, or CCSP. Active DoD 8570 CSSP Incident

Technical Tools
OperationsOtherEngineerOperations Analyst
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
 
  • Oversee enterprise-wide monitoring and logging across network infrastructure and endpoints to ensure the rapid detection and response to cyber incidents.
  • Maintain and evolve IR SOPs in strict accordance with CJCSM 6510.01B, NIST SP 800-61R2, and DOW regulations to ensure procedural alignment with industry best practices.
  • Translate technical findings into regular status reports for program leadership, DOW officials, and USCYBERCOM /DCDC repositories, detailing incident impact, effectiveness of response strategies, and lessons learned.
  • Drive the evolution of incident response capabilities by identifying weaknesses, recommending advanced technologies, and implementing enhanced processes to stay ahead of evolving cyber threat
  • Support DOW CIO data collection by reviewing PPSM, CAP, SNAP, and GIAP requests against DISA guidelines; cross-train team members on emerging defense techniques and provide after-hours investigative support for critical incidents.
  • Perform thorough post-incident reviews to derive lessons learned, identify security gaps, and implement preventive measures to strengthen the program’s long-term defense posture.
  • Provide expert guidance on cybersecurity directives and risk management policies; review POA&Ms for technical clarity and sound judgment to ensure acceptable remediation timeframes for security controls.
  • Conduct deep-dive forensic investigations into cybersecurity events (data loss, unauthorized access, network exploits) to determine nature and scope; identify corrective actions for containment, eradication, and recovery.
  • Lead response activities for USCYBERCOM and DCDC directives, managing the lifecycle of Situational Awareness Reports (SAR) and ensuring all assets remain compliant with OPORDs, TASKORDs, IAVM notifications, and STIG requirements by published deadlines.
     
  •  
     
    • Bachelor’s degree in computer science or related field
    • U.S. Citizenship and an active Secret Clearance (required) with the ability to obtain and maintain a Top-Secret Clearance.
    • Active DoD 8570 IAT Level II certification or greater, including at least one of the following certifications in good standing: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISSP (or Associate), GCED, GCIH, or CCSP.
    • Active DoD 8570 CSSP Incident Responder certification a plus, including at least one of the following certifications in good standing: CEH, CFR, CCNA Cyber Ops, CHFI, CySA+, GCFA, GCIH, SCYBER, or PenTest+
      • Knowledge of Incident Response Handling Procedures (NIST SP 800-61)
      • Familiarity with cyber adversary tactics and frameworks (such as ATT&CK and D3FEND)
      • Knowledge of one or more of the following cybersecurity tools:
          • Trellix/ESS
          • Tanium
          • Microsoft Defender Endpoint
          • BeyondTrust
          • Splunk
          • Great communication skills and attention to detail.
            • 8+ years in Information Technology or Information Security with 5+ years performing Cybersecurity Operations and Incident Response
            • Required to work onsite daily at our DoD customer office location in Alexandria, VA or Seaside, California.

    Location & Eligibility

    Where is the job
    D.c.
    Hybrid — some on-site time required
    Who can apply
    Same as job location

    Listing Details

    Posted
    April 30, 2026
    First seen
    April 30, 2026
    Last seen
    May 4, 2026

    Posting Health

    Days active
    4
    Repost count
    0
    Trust Level
    62%
    Scored at
    May 4, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    T
    Cybersecurity Operations Analyst (R-00156)