Defensive Cyber Operations Analyst

Booz Allen Hamilton•Colorado Springs, CO
•$69,300 - $158,000•Onsite

About The Position

As a cyberspace defender on our team, you’ll be in the middle of the action, monitoring real-time threats, analyzing complex cyber events, and helping protect mission‑critical networks that support operations. Every alert, anomaly, or suspicious pattern you uncover helps ensure the uninterrupted flow of information that commanders and warfighters rely on. We need a Defensive Cyberspace Operations (DCO) Analyst like you to help safeguard enterprise‑level systems against cyber threats targeting Combatant Command Headquarters, Service Components, Joint Task Forces, and mission partners. As a DCO analyst, you’ll monitor and analyze threats using advanced tools, including Assured Compliance Assessment Solution, Splunk, Host‑Based Security System, and Big Data Platform capabilities like SIGACT and RALLY. You’ll use your cyber defense tradecraft to identify malicious activity, distinguish real threats from benign events, and escalate incidents with clear summaries of impact and urgency. You’ll combine threat intelligence, event data, and correlation across multiple sources to uncover attacker patterns and understand their goals, stopping them before they succeed. You’ll work alongside teammates conducting uninterrupted DCO, Computer Network Defense, Information Assurance, and NetOps to maintain situational awareness and ensure secure, available IT C4 systems. Your work will include supporting DCO event and incident response, documenting and escalating cyber events, performing multi‑source correlation, and producing daily reporting that enhances commander awareness. You’ll also coordinate with enterprise‑wide cyber defense partners, respond to CPCON changes, assist with operational briefs, and help implement proactive and reactive security measures that protect Combatant Command networks. You’ll even leverage Department of War AI capabilities to strengthen defensive cyberspace operations. This is a great opportunity to build hands‑on skills in threat detection, incident response, and cyber event analysis while contributing directly to missions vital to homeland defense. Work with us as we secure critical networks from malicious actors. Join us. The world can't wait.

Requirements

  • Experience supporting DCO within a shift work-based 24x7 operations center
  • Experience advising on network security issues and enforcing vulnerability mitigation policies and procedures
  • Experience developing reports, presenting daily network security summaries, and communicating clearly with senior leaders and varied audiences
  • Experience with customer queries and reviewing data for component units
  • Knowledge of management and monitoring of network security components, devices, and services
  • Knowledge of cybersecurity tools such as Splunk, HBSS, Microsoft Defender, or Security Onion
  • Ability to support Panama Schedule DCO Watch Stander shifts, holidays, and weekends on an as‑needed basis
  • TS/SCI clearance
  • HS diploma or GED and 2+ years of experience conducting DCO, SOC, JCC, or NOSC mission operations, or Bachelor’s degree and 1+ years of experience conducting DCO, SOC, JCC, or NOSC mission operations
  • Security+ or DoDM 8140.03 Certification

Nice To Haves

  • Experience developing or delivering cyberspace operations support at the Combatant Command or Major Command level
  • Knowledge of AI in the performance of DCO operations
  • Knowledge of cybersecurity and cyberspace operations doctrine, Joint Publications, and policy implementation
  • Knowledge of implementing security patching across enterprise systems
  • Ability to formulate recommendations for corrective actions that address identified risks and support JCC operations

Responsibilities

  • Monitor real-time threats
  • Analyze complex cyber events
  • Help protect mission-critical networks
  • Safeguard enterprise-level systems against cyber threats
  • Monitor and analyze threats using advanced tools
  • Identify malicious activity
  • Distinguish real threats from benign events
  • Escalate incidents with clear summaries of impact and urgency
  • Combine threat intelligence, event data, and correlation across multiple sources to uncover attacker patterns and understand their goals
  • Support DCO event and incident response
  • Document and escalate cyber events
  • Perform multi-source correlation
  • Produce daily reporting that enhances commander awareness
  • Coordinate with enterprise-wide cyber defense partners
  • Respond to CPCON changes
  • Assist with operational briefs
  • Help implement proactive and reactive security measures
  • Leverage Department of War AI capabilities to strengthen defensive cyberspace operations

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service