Cyber Defense Analyst [Various Levels] Contingent

Lufco•Belleville, IL
•$95,000 - $105,000

About The Position

The Cyber Defense Analyst serves as the Cybersecurity Operations Lead for an Army project. Operating within the Cybersecurity Operations (CSO) capability area, this Key Personnel role leads real-time security monitoring, event correlation, incident analysis, threat vector evaluation, and defensive posture enforcement to preserve the operational effectiveness and mission assurance of global C4ISR networks.

Requirements

  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline.
  • Minimum of 6 years of dedicated, hands-on experience in cyber defense operations, threat analysis, and incident response.
  • Must comply fully with DoDM 8140.03 ('Cyberspace Workforce Qualification and Management Program'), DoDD 8140.01, DoDI 8140.02, and USTCI 6600.01 standards.
  • Meets the foundational qualification standards for DCWF Work Role 621 (Cyber Defense Analyst) at the Intermediate or Advanced level prior to assumption of duties.
  • Must be Residentially Qualified as an IT Privileged User with elevated access prior to performing technical work.
  • Intermediate Level Qualifying Certifications: CompTIA CySA+, SecurityX (CASP+), or Certified Ethical Hacker (CEH).
  • Advanced Level Qualifying Certifications: SecurityX (CASP+) or CISSP.
  • Must hold an active, fully adjudicated Top Secret security clearance.
  • Must be vetted and approved through the Defense Information System for Security (DISS) and Mission Partner Identity, Credential and Access Management (MP ICAM) prior to CAC issuance and network access.

Responsibilities

  • Leads real-time cybersecurity operational monitoring, threat vector analysis, event correlation, and defensive posture enforcement across command enclaves.
  • Analyzes SIEM (Splunk) feeds, firewall logs (Palo Alto NGFW), and intrusion detection system alerts to identify potential compromises, policy violations, and unauthorized activity.
  • Coordinates vulnerability assessments and mitigation verification across secure communications enclaves. Executes weekly vulnerability scans utilizing ACAS and generates the weekly Vulnerability Index (VI) report and Plan of Action & Milestones (POA&M).
  • Authors, reviews, and sustains RMF documentation packages to achieve and maintain Authorizations to Operate (ATO) for all in-scope systems.
  • Immediately reports suspected security incidents to the Contracting Officer's Representative (COR) and executes measures to identify, contain, eradicate, and recover from security events.
  • Operates, manages, and configures Government-furnished cybersecurity tools, including Trellix ePO/HBSS, Cisco Identity Services Engine (ISE), Palo Alto NGFW, Splunk, and Symantec ProxySG.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service