DCOMSS - CTI Lead / Senior Threat-Warning Analyst

Technology, Automation, and Management

  • Fort Bragg, North Carolina
  • 5 days ago

    Highlights

    This position leads the Cyber Threat Intelligence (CTI) task area of the USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) effort, informing Blue Team detection priorities, driving assessment scoping, and delivering finished intelligence products to supported commanders, the supported Regional Cyber Center, and ARCYBER. Mission Objectives – Defensive Cyberspace Operations (DCO) are the passive and active measures taken to detect, characterize, and defeat adversary activity on Army networks and preserve the Army's ability to use its own cyberspace capabilities — a distinct, adversary-focused mission from routine IT infrastructure or help-desk support.

    Numbers & Facts

    LocationFort Bragg, North Carolina

    Description

    Pending Contract Award

    Mission Objectives – Defensive Cyberspace Operations (DCO) are the passive and active measures taken to detect, characterize, and defeat adversary activity on Army networks and preserve the Army's ability to use its own cyberspace capabilities — a distinct, adversary-focused mission from routine IT infrastructure or help-desk support. This position leads the Cyber Threat Intelligence (CTI) task area of the USARC Defensive Cyberspace Operations Mission Support Services (DCOMSS) effort, informing Blue Team detection priorities, driving assessment scoping, and delivering finished intelligence products to supported commanders, the supported Regional Cyber Center, and ARCYBER. The CTI Lead is one of three Key Personnel positions on this task order.

    Position Responsibility Summary

    • Serve as Key Personnel and single point of accountability for the CTI pillar, directing persistent collection, aggregation, and analysis of OSINT, commercial threat feeds, ISAC reporting, and Government-Furnished Intelligence.
    • Own production and dissemination of finished intelligence products: Threat Intelligence Reports (minimum 4 per month), Indicator of Compromise packages, and Request for Information responses (initial response within 24 hours, substantive response within 5 business days).
    • Direct development, testing, and recommendation of host- and network-based detection signatures derived from threat intelligence, coordinating submissions with the ARCYBER signature working group; own the sub-72-hour report-to-sensor development cycle and =10% false-positive threshold.
    • Lead adversary tactics, techniques, and procedures analysis mapped to the MITRE ATT&CK framework to inform Blue Team detection priorities and hunt tasking.
    • Direct hypothesis-driven and indicator-based threat hunt missions in coordination with the Blue Team Lead.
    • Manage the DCO test lab (isolated network) supporting malware analysis and OSINT collection.
    • Serve as the CTI interface to the supported command's G2, the supported Regional Cyber Center, and ARCYBER for intelligence requirements management.
    • Maintain DCWF 171 (Cyber Threat Intelligence Analyst, Advanced) qualification and oversee CTI team compliance with DoDM 8140.03, including oversight of analysts assigned to SCI/JWICS systems.
     

    Similar Jobs