As a Tier 1 Defensive Cyber Operations (DCO) Watch Analyst you will be responsible for monitoring and triaging security events within a Cybersecurity Service Provider (CSSP) environment. You will identify and validate suspicious events, escalate incidents as needed, and support basic incident response activities. This role ensures compliance with reporting requirements and operates under close supervision. Position Requirements and Duties Monitor network and host-based systems for suspicious activity using provided tools and SOPs Validate security events and escalate potential incidents to Tier 2 analysts per CJCSM 6510.01B guidelines Enter incident data into designated reporting systems with accuracy and timeliness Assist in managing incident response campaigns by documenting and tracking basic incident details under supervision Provide 24/7 support for incident response during assigned shifts, including non-core hours as needed Participate in training to develop familiarity with CSSP tools and processes Support basic log correlation tasks using tools like Splunk, Elastic, and Sentinel Assist in program reviews and product evaluations as directed Operations are conducted 24/7/365 across three regional operation centers (ROC) Each ROC works four ten-hour shifts (Sunday-Wednesday or Wednesday-Saturday) Shift placement is at the discretion of assigned managers Overtime may be required to support incident response actions (Surge) Up to 10% travel may be required
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Entry Level
Number of Employees
5,001-10,000 employees