DCOMSS - Blue Team Lead / Senior Cyber Defense Analyst

Technology, Automation, and Management

  • Fort Bragg, North Carolina
  • 3 days ago

    Highlights

    Mission Objectives - Defensive Cyberspace Operations (DCO) are the passive and active measures taken to detect, characterize, and defeat adversary activity on Army networks and preserve the Army's ability to use its own cyberspace capabilities - a distinct, adversary-focused mission from routine IT infrastructure or help-desk support. This position leads both Blue Team task areas of the USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) effort: Blue Team - Network Security Monitoring, Detection, Analysis, and Incident Response, and Blue Team - Integrated Assessments.

    Numbers & Facts

    LocationFort Bragg, North Carolina

    Description

    Pending Contract Award

    Mission Objectives - Defensive Cyberspace Operations (DCO) are the passive and active measures taken to detect, characterize, and defeat adversary activity on Army networks and preserve the Army's ability to use its own cyberspace capabilities - a distinct, adversary-focused mission from routine IT infrastructure or help-desk support. This position leads both Blue Team task areas of the USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) effort: Blue Team - Network Security Monitoring, Detection, Analysis, and Incident Response, and Blue Team - Integrated Assessments. Together these form the primary operational layer defending U.S. Army Reserve information systems supporting approximately 205,000 Army Reserve personnel across NIPRNet and SIPRNet on a continuous basis. The Blue Team Lead is the single point of accountability for both task areas and is one of three Key Personnel positions on this task order.

    Position Responsibility Summary

    • Serve as Key Personnel and single point of accountability for Blue Team - Network Security Monitoring, Detection, Analysis, and Incident Response across NIPRNet and SIPRNet, maintaining 24/7/365 watch coverage.
    • Lead Tier 3 senior analysis, hypothesis-driven hunt missions, and detection-signature development, coordinating signature submissions with the CTI cell and the ARCYBER signature working group.
    • Own incident categorization and reporting IAW CJCSM 6510.01B; ensure execution of critical blocks within 2 hours of notification/detection and 24-hour mitigation actions where required.
    • Direct shift operations: watch schedule, pass-down log, shift-lead handoff briefings, and surge staffing procedures during declared elevated threat conditions, named operations, or directed exercises.
    • Direct execution of Blue Team - Integrated Assessments, including Network Assistance Visits (NAVs) and Network Damage Assessments (NDAs) under the CDAP construct, with 4-hour NDA deployment readiness.
    • Serve as the Blue Team escalation point to ARCYBER, the supported Regional Cyber Center, JFHQ-DoDIN, and Law Enforcement/Counterintelligence.
    • Mentor and quality-control Tier 1 and Tier 2 analysts; own team compliance with DoDM 8140.03 DCWF qualification requirements.
    • Own Blue Team performance against PRS thresholds, including =99.5% watch availability, mean-time-to-detect under 15 minutes on high-fidelity alerts, and 100% shift-handoff log completeness.
     

    Similar Jobs

    See more jobs