Cyber Defense Operator – Intermediate

Viranim Technical SolutionsSan Antonio, TX
Onsite

About The Position

Viranim is seeking a Cyber Defense Operator at Lackland AFB in San Antonio, TX. This role involves reviewing IDS/IPS alerts, conducting host security monitoring, and analyzing security events to identify and remediate intrusions. The operator will develop and maintain procedures for system monitoring, comply with third-party requirements, and correlate suspicious activities with network events and external DoD resources. Responsibilities include triaging alerts, recording suspicious activity, entering event data into mission support systems, providing performance metrics, and escalating security incidents.

Requirements

  • GCFA
  • Top Secret/SCI Clearance

Responsibilities

  • Review all IDS/IPS alerts per AFIN SOC Operating Instruction and checklists at the AOL, COOP, or Ops Floor.
  • Conduct host security monitoring, alert review, and intrusion detection analysis for the AFIN ‐ SOC mission.
  • Develop, Review and Maintain procedures related to the overall monitoring of Hosts/Systems.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements.
  • Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Monitor security sensors to analyze Intrusion Detection Systems and Security Information and Event Management to identify and correlate security issues/events and review logs to identify intrusions for remediation.
  • Correlate suspicious events with network events, if possible, and data stored within databases and other external DoD resources, including but not limited to Big Data Platform.
  • Analyze traffic/logs/events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Record who, what, where why and when for any identified suspicious activity in case management system case to enable additional investigations.
  • Conduct triage of suspicious activity alerts and logs in order to make a fast and accurate triage decision.
  • Enter event data into mission support systems in accordance with AFIN SOC operational procedures and reports.
  • Provide monthly performance metrics including but not limited to readiness, qualifications, events processed, CAT events and incidents identified.
  • Escalate security incidents using established policies and procedures.

Benefits

  • paid holidays
  • paid time off
  • medical
  • dental
  • vision insurance
  • flexible spending accounts
  • health savings accounts
  • short and long term disability
  • company paid life insurance
  • 401(k) with a company match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service