ECS is seeking an Advanced Threat Team Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This role supports Task 3 — Cybersecurity Operations Support — by leading advanced threat and insider threat monitoring operations across ARNG classified and unclassified network environments. The Advanced Threat Team Lead - Senior directs analytic strategy, detection development, and investigation workflows; integrates threat intelligence with user activity monitoring, behavioral analytics, and enterprise security telemetry; and coordinates closely with SOC, CIRT, CTI, defensive cyber, and security engineering teams to improve threat detection and response in support of DCO-IDM objectives across the DoDIN-Army-NG area of responsibility. In this role, the selected candidate contributes to the protection of an enterprise supporting more than 120,000 users and approximately 141,000 endpoints across about 2,800 sites in 54 states and territories. The position supports ARNG missions spanning Title 10 and Title 32 operations, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The role operates within ENOCS’ cyber defense environment, leveraging integrated SIEM/C2C/DLP analytics, USIEM detection engineering, EDR, SOAR, Zeek metadata, Sysmon-informed MITRE ATT&CK analytics, and coordination with NETCOM Global Cyber Center, DISA DCDC, ARCYBER, USCYBERCOM, and regional RCCs to identify anomalous behavior, prioritize mission risk, and strengthen continuous monitoring and enterprise cyber resiliency. Please Note: This position is contingent upon contract award.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior