STS Systems Support, LLC (SSS) is a government consulting and contracting firm supporting federal agencies and military installations across the U.S. We are seeking a Defensive Counter Cyber - DCC – Senior to support our mission at Lackland AFB in San Antonio, TX. What You'll Do: Perform threat hunting for suspicious activity based on anomalous activity and indicators of compromise from various intelligence sources and toolsets.Comply with 3rd party MOU/MOA monitoring and reporting requirements. (CDRL A002)Identify intrusions and vulnerabilities and recommend mitigation strategies and techniques to secure networks.Identify, analyze and develop defensive counter cyber measures to thwart advanced persistent threats and intrusions of AF networks, domains and enclaves.Conduct and support Defensive Counter Cyber Operations to interactively search for Advanced Persistent Threats (APT) and Indicators of Compromise (IOC) using enhanced data collection and analysis methods.Provide incident response impact assessments.Produce network security posture assessments. (CDRL A008)Analyze systems for suspicious activities related to the DCO missionDetermine exploitation methods and attack vectors.Provide OJT to other contractor employees, military, and/or civilian personnel, and ensure continuity folders/working aids are updated at least once per quarter in order to ensure efficient transition when personnel rotate.Create and document metrics for reporting and analysis to improve weapon system processes, procedures, and mission execution. (CDRL A009)Maintain currency on latest industry trends and provide operational reports/assessments for development of tactics, techniques, and procedures. (CDRL A002)Provide requested information to operational flight commander as it relates to the Incident Response processes and procedures.Utilize the Mitre ATT&CK Matrix in performance of duties.Plan hypothesis‐based threat hunt missions. Utilize current Cyber Threat Intel team provided information in threat prioritization/hunt creation.Execute hunt mission within specified cyber terrain.Coordinate with ESM and Content Development to automate threat hunts and/or develop standing detections for threat hunts.Request Tactical Validation and Assessment (TVA) to validate hunt techniques and/or created alerting mechanisms.Identify and report coverage gaps in detection and weapon system visibility/capability.Develop hypothesized schemes‐of‐maneuver of adversary behavior as needed for hunt missions in coordination with Cyber Threat Intel team.Leverage the MITRE ATT&CK matrix to map adversarial TTPs to current security coverage within specified cyber terrain.Develop threat hunts for emerging cyber threats, to include 0‐day proof‐of‐concepts, CVE exploitation, and adversary TTPs.Organize and analyze collected data to determine trends, perform long‐tail and frequency analysis of host and network artifacts, and baseline enterprise activity.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
1,001-5,000 employees