Job Requirements
Patrick Space Force Base, FL
Top Secret/SCI Polygraph Unspecified
Mid Level Career (5+ yrs experience)
$120,000 - $145,000
Job Description
About ITI Solutions, Inc.
ITI Solutions, Inc. is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with a strong track record supporting Department of Defense (DoD) programs, including U.S. Army vehicle production, sustainment, and modernization efforts.
Founded by a Service-Disabled Veteran, we bring mission-driven expertise in engineering support, logistics coordination, and program execution to critical national defense initiatives.
As an Equal Opportunity Employer, ITI Solutions is committed to fostering a diverse, inclusive, and respectful workplace. We do not discriminate in employment decisions on the basis of race, color, religion, national origin, sex, gender, gender identity, sexual orientation, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are dedicated to providing equal employment opportunities to all applicants and employees and maintaining a work environment that is free from discrimination and harassment.
Position Summary: ITI Solutions is seeking a Defensive Cyber Operations (DCO) Subject Matter Expert (SME) to support the United States Space Force (USSF) Mission Delta 6 (D6) Defensive Cyber Operations (DCO) contract. The DCO SME is a well-rounded, hands on cyber security expert who supports development, improves proficiency, and increases operational effectiveness of USSF Cyber Squadron personnel by: providing/employing DCO capabilities, conducting intrusion detection monitoring and analysis, identifying malicious cyber activity and determining attack vectors, executing cyber response activities, developing defensive countermeasures, and providing Subject Matter Expertise to the United States Space Force Cyber Guardians.
Responsibilities:
· Provide expertise for DCO-Space capabilities, to include Enterprise Logging Ingest and Cyber Situational Awareness Refinery (ELICSAR), RunZero, Security Incident and Event Management (SIEM) tools; Intrusion Detection and Prevention Systems; ELK (Elasticsearch, Logstash, and Kibana) Stack; Endpoint Protection Systems; Security Orchestration, Automation and Response (SOAR); Firewalls; Log Aggregator; Protocol Analyzers; Vulnerability Assessment Tools; Cyber Defense Environment Representation (CyDER) range; and where applicable, assigned cyber squadron’s internal range(s).
· Develop operational and technical materials
· Provide cyber defense remediation and mitigation implementation recommendations in support of all cyber incidents/events during normal duty hours
· Provide support for all Operational Planning Teams (OPTs) and crew shift planning processes
· Draft, validate, and provide recommendations on the accuracy of DCO TTPs, SOPs, and OIs, as well as DCO Crew training products, training, evaluation, and certification material, and other related materials
· Conduct analysis on new DCO-Space capability releases to assess new functionality and inform technical and operational employment for mission execution
· Attend meetings, teleconferences, and Video Teleconferences (VTCs) at the Unclassified, Secret, and TS/SCI level (as required)
· Provide DCO-S objective recommendations for exercises and mission rehearsals
· Maintain DCO proficiency by performing crew operations for assigned space systems
· Augment and advise the crews performing intrusion detection monitoring and analysis as needed
· Provide input to and review Cyber 9-Line during normal duty hours, and review accuracy of cyber incident inputs
· Advise and assist with cyber incident response processes IAW policies and procedures
· Assist CYS crews in providing in-depth analysis of incidents by determining the incident’s nature, formulating recommended response actions, correlating event and incident data across assigned space mission systems, determining actions to be taken, and assessing possible effects on assigned mission systems
· Participate in Government-established Cyber Incident Response Teams (CIRTs) and provide technical assistance in determining the cyber events/incident’s nature and impact to space mission systems; develop and recommend mitigation and/or remediation COAs; ensure mission system owners/operators and leadership have situational awareness of active response activities via recurring status reports and/or update briefs
· Provide technical expertise in the creation of recommendations for Courses of Action (COA) along with suggested timing and sequencing of actions to mitigate and/or remediate cyber threats
· Participate in post-incident hot washes and lessons learned processes as required by the Government
· Recommend cyber incident response best practices to improve TTPs, processes, and policies
· Provide recommendations on how to best optimize DCO-Space capabilities, to include countermeasure development (i.e., signatures, rules, policies, etc.) for defensive tools
· Assist and support Government personnel with identifying, documenting, and tracking normal baseline activity for assigned space mission systems by monitoring, collecting, and analyzing traffic; and reviewing, auditing, and analyzing network and endpoint logs
· Assist and support Government personnel in performing Mission Relevant Terrain – Cyber (MRT-C) identification and mapping, leveraging Functional Mission Analysis – Cyber (FMA-C) concepts
· Assist and support CYS Government personnel on assigned space mission systems to detect, track, and disrupt Advanced Persistent Threats (APTs)
· Provide operational and technical on-the-job training (OJT) to Government CYS personnel executing defense cyber operations (DCO)
Qualifications
Qualifications:
· Active DoD TS/SCI clearance (Company does not sponsor those with no prior TS/SCI)
· Required DoD 8140.03 Qualification (Must have one of the Foundational Qualification Options below):
o Education: BS degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering, from an ABET-accredited or CAE-designated institution
Or one or more of the following training
o DOD/Military Training: 4C-255S (CP), M03385G, M10395B, M223854, A-531-0451, A-531-4421, A-531-1900, Cyber Defense Analyst (Intermediate) Playlist, DISA (511) Training, 4-11-C32-255S (CP), 4C-255N (CP), 4C-255A (CP), M0923W1, A-531-4417, DCWF WRC 511 Cyber Defense Analyst (Advanced) Playlist
Or one of the following DoDM certifications
o Certifications: CEH(P), GMON, GRID, Cloud+, FITSP-O, GCED, GDSA, GSEC, PenTest+, Security+, CBROPS, CFR, CySA+, GCFA, GCIA, or GICSP
Qualifications (Preferred):
· Eight (8)+ years of relevant hands-on DCO Analyst work experience using Elicsar, RunZero, SIEMs, IPD/IDS, rule tuning tools, or equivalent (ISSO/RMF/IA/System Admin cyber analyst experience does not count)
Required Experience/Skills:
· Hands-on Experience with the following tools:
o ELK Stack, Kibana, Teleseer, Suricata, Splunk, Snort, Wireshark, Bro/Zeek logs, TCPdump, editcap, Carbon Black, bash scripting, Python, Microsoft Office 365
· Experience performing Defensive Cyber Operations, Continuous Cybersecurity Monitoring, Intrusion Detection, and Cyber Incident Response
Preferred Experience
· Previously worked in a DCO SOC as an analyst or Site Lead
· Familiarity with Space Operations is highly desired
Location:
· Patrick Space Force Base (SFB), Florida
Salary: $120,000 to $145,000
ITI Solutions, Inc. is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with a strong track record supporting Department of Defense (DoD) programs, including U.S. Army vehicle production, sustainment, and modernization efforts.
Founded by a Service-Disabled Veteran, we bring mission-driven expertise in engineering support, logistics coordination, and program execution to critical national defense initiatives.
As an Equal Opportunity Employer, ITI Solutions is committed to fostering a diverse, inclusive, and respectful workplace. We do not discriminate in employment decisions on the basis of race, color, religion, national origin, sex, gender, gender identity, sexual orientation, age, disability, protected veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law. We are dedicated to providing equal employment opportunities to all applicants and employees and maintaining a work environment that is free from discrimination and harassment.
Position Summary: ITI Solutions is seeking a Defensive Cyber Operations (DCO) Subject Matter Expert (SME) to support the United States Space Force (USSF) Mission Delta 6 (D6) Defensive Cyber Operations (DCO) contract. The DCO SME is a well-rounded, hands on cyber security expert who supports development, improves proficiency, and increases operational effectiveness of USSF Cyber Squadron personnel by: providing/employing DCO capabilities, conducting intrusion detection monitoring and analysis, identifying malicious cyber activity and determining attack vectors, executing cyber response activities, developing defensive countermeasures, and providing Subject Matter Expertise to the United States Space Force Cyber Guardians.
Responsibilities:
· Provide expertise for DCO-Space capabilities, to include Enterprise Logging Ingest and Cyber Situational Awareness Refinery (ELICSAR), RunZero, Security Incident and Event Management (SIEM) tools; Intrusion Detection and Prevention Systems; ELK (Elasticsearch, Logstash, and Kibana) Stack; Endpoint Protection Systems; Security Orchestration, Automation and Response (SOAR); Firewalls; Log Aggregator; Protocol Analyzers; Vulnerability Assessment Tools; Cyber Defense Environment Representation (CyDER) range; and where applicable, assigned cyber squadron’s internal range(s).
· Develop operational and technical materials
· Provide cyber defense remediation and mitigation implementation recommendations in support of all cyber incidents/events during normal duty hours
· Provide support for all Operational Planning Teams (OPTs) and crew shift planning processes
· Draft, validate, and provide recommendations on the accuracy of DCO TTPs, SOPs, and OIs, as well as DCO Crew training products, training, evaluation, and certification material, and other related materials
· Conduct analysis on new DCO-Space capability releases to assess new functionality and inform technical and operational employment for mission execution
· Attend meetings, teleconferences, and Video Teleconferences (VTCs) at the Unclassified, Secret, and TS/SCI level (as required)
· Provide DCO-S objective recommendations for exercises and mission rehearsals
· Maintain DCO proficiency by performing crew operations for assigned space systems
· Augment and advise the crews performing intrusion detection monitoring and analysis as needed
· Provide input to and review Cyber 9-Line during normal duty hours, and review accuracy of cyber incident inputs
· Advise and assist with cyber incident response processes IAW policies and procedures
· Assist CYS crews in providing in-depth analysis of incidents by determining the incident’s nature, formulating recommended response actions, correlating event and incident data across assigned space mission systems, determining actions to be taken, and assessing possible effects on assigned mission systems
· Participate in Government-established Cyber Incident Response Teams (CIRTs) and provide technical assistance in determining the cyber events/incident’s nature and impact to space mission systems; develop and recommend mitigation and/or remediation COAs; ensure mission system owners/operators and leadership have situational awareness of active response activities via recurring status reports and/or update briefs
· Provide technical expertise in the creation of recommendations for Courses of Action (COA) along with suggested timing and sequencing of actions to mitigate and/or remediate cyber threats
· Participate in post-incident hot washes and lessons learned processes as required by the Government
· Recommend cyber incident response best practices to improve TTPs, processes, and policies
· Provide recommendations on how to best optimize DCO-Space capabilities, to include countermeasure development (i.e., signatures, rules, policies, etc.) for defensive tools
· Assist and support Government personnel with identifying, documenting, and tracking normal baseline activity for assigned space mission systems by monitoring, collecting, and analyzing traffic; and reviewing, auditing, and analyzing network and endpoint logs
· Assist and support Government personnel in performing Mission Relevant Terrain – Cyber (MRT-C) identification and mapping, leveraging Functional Mission Analysis – Cyber (FMA-C) concepts
· Assist and support CYS Government personnel on assigned space mission systems to detect, track, and disrupt Advanced Persistent Threats (APTs)
· Provide operational and technical on-the-job training (OJT) to Government CYS personnel executing defense cyber operations (DCO)
Qualifications
Qualifications:
· Active DoD TS/SCI clearance (Company does not sponsor those with no prior TS/SCI)
· Required DoD 8140.03 Qualification (Must have one of the Foundational Qualification Options below):
o Education: BS degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering, from an ABET-accredited or CAE-designated institution
Or one or more of the following training
o DOD/Military Training: 4C-255S (CP), M03385G, M10395B, M223854, A-531-0451, A-531-4421, A-531-1900, Cyber Defense Analyst (Intermediate) Playlist, DISA (511) Training, 4-11-C32-255S (CP), 4C-255N (CP), 4C-255A (CP), M0923W1, A-531-4417, DCWF WRC 511 Cyber Defense Analyst (Advanced) Playlist
Or one of the following DoDM certifications
o Certifications: CEH(P), GMON, GRID, Cloud+, FITSP-O, GCED, GDSA, GSEC, PenTest+, Security+, CBROPS, CFR, CySA+, GCFA, GCIA, or GICSP
Qualifications (Preferred):
· Eight (8)+ years of relevant hands-on DCO Analyst work experience using Elicsar, RunZero, SIEMs, IPD/IDS, rule tuning tools, or equivalent (ISSO/RMF/IA/System Admin cyber analyst experience does not count)
Required Experience/Skills:
· Hands-on Experience with the following tools:
o ELK Stack, Kibana, Teleseer, Suricata, Splunk, Snort, Wireshark, Bro/Zeek logs, TCPdump, editcap, Carbon Black, bash scripting, Python, Microsoft Office 365
· Experience performing Defensive Cyber Operations, Continuous Cybersecurity Monitoring, Intrusion Detection, and Cyber Incident Response
Preferred Experience
· Previously worked in a DCO SOC as an analyst or Site Lead
· Familiarity with Space Operations is highly desired
Location:
· Patrick Space Force Base (SFB), Florida
Salary: $120,000 to $145,000
group id: 10200317