Action Officer

Sentar

$95K — $115K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Top Secret/SCI clearance required
  • DoD 8140 baseline certification at time of hire (Security+, CISM, CISSP)
  • 5+ years of experience in cybersecurity or related analyst roles supporting DoD
  • Strong understanding of DoD cybersecurity policies and frameworks
  • 5+ years of experience in cyber threat research and incident response
  • Proficiency in MITRE ATT&CK framework analysis
  • Experience with threat intelligence platforms and SIEM tools

Responsibilities

  • Receive and triage incoming cybersecurity requests from DHA subscribers
  • Conduct detailed threat analysis on cyber incidents and adversary activity
  • Develop and deliver actionable intelligence reports tailored to subscriber needs
  • Collaborate with internal analysts and incident responders for comprehensive RFI replies
  • Maintain situational awareness of emerging cyber threats and vulnerabilities
  • Support the development of RFI processing workflows and SOPs
  • Provide technical guidance on cyber threat mitigation and security best practices
  • Track RFI metrics to support performance improvements

Benefits

  • Voluntary Medical, Dental, Vision insurance options
  • Group Term Life and Disability insurance provided
  • Generous 401(k) match
  • Competitive PTO plan that increases with service time
  • Mental health awareness programs
  • Tuition and professional development reimbursement
  • Recognition and Awards programs
Full Job Description
Sentar is seeking an Action Officer in Charleston, SC!

The Cyber Operations Center (CyOC) Action Officer will support the mission-critical efforts of the Defense Health Agency (DHA) by enabling proactive cybersecurity operations that protect sensitive healthcare systems across the Department of Defense (DoD). This role is embedded within the Naval Information Warfare Center (NIWC) Atlantic's Defensive Cyberspace Operations (DCO) Integrated Product Team (IPT), which is tasked with safeguarding DHA's global infrastructure against cyber threats, unauthorized access, and emerging vulnerabilities.

As part of the CyOC team, the Action Officer serves as a key operational resource, working directly with DHA subscribers to receive, triage, and respond to Requests for Information (RFIs) related to cybersecurity threats and incidents. This includes performing detailed threat analysis, coordinating with cross-functional intelligence teams, and delivering actionable intelligence reports to bolster the defense posture of supported entities.

Analysts in this role serve on the front lines of cyber defense, translating raw threat data and subscriber inquiries into strategic insights. By supporting frontline military medical operations and critical DoD health IT systems, the RFI Analyst plays a direct role in ensuring mission continuity, data protection, and the safety of warfighters and beneficiaries alike.

This position requires a Top Secret/SCI clearance, strong knowledge of DoD cyber policy, and a proven ability to analyze and communicate complex threat intelligence. Candidates will be part of a dynamic, fast-paced environment where analytical precision, rapid response, and interagency collaboration are essential to mission success.

Role Description:

The CyOC Action Officer will support the Defensive Cyberspace Operations mission by delivering actionable intelligence and analytical support to DHA stakeholders. Specific responsibilities include:
  • Receive, assess, and triage incoming Requests for Information (RFIs) from DHA subscribers.
  • Conduct detailed research and threat analysis on cyber incidents, indicators, and adversary activity.
  • Develop and deliver concise, accurate, and actionable intelligence reports tailored to subscriber needs.
  • Collaborate with internal CyOC analysts, incident responders, and threat intelligence teams to ensure comprehensive RFI responses.
  • Maintain situational awareness of current and emerging cyber threats, vulnerabilities, and attack techniques.
  • Support the development, documentation, and refinement of RFI processing workflows and standard operating procedures (SOPs).
  • Provide technical guidance to subscribers regarding cyber threat mitigation and security best practices.
  • Track RFI status, metrics, and trends to support operational reporting and performance improvement.
  • Coordinate with NIWC Atlantic and DHA stakeholders to ensure mission alignment and timely response to critical intelligence needs.
  • Operate in a high-tempo environment with competing priorities and rapidly evolving threat landscapes.

Qualifications:

Clearance Level: TS/SCI required

Certifications: Candidate must meet DoD 8140 (Formerly 8570) baseline certification at the time of hire. The following are commonly accepted: Security+, CISM, or CISSP

Experience:
  • 5+ years of experience in cybersecurity, threat intelligence analysis, or related cyber defense roles supporting DoD or federal agencies
  • Strong understanding of DoD cybersecurity policies, including DoD 8500-series, DoDI 8510.01 (RMF), and CJCSM 6510.01 (Cyber Incident Handling)
  • 5+ years of experience conducting cyber threat research, analysis, and reporting in support of SOC, IR, or cyber threat intel teams
  • Proficiency in analyzing cyber threats across the MITRE ATT&CK framework, including TTPs and IOCs
  • Experience with threat intelligence platforms (TIPs), SIEM tools (e.g., Splunk, ELK, QRadar), and open-source intelligence (OSINT) research tools
  • Familiarity with malware analysis, DDoS patterns, phishing campaign forensics, and adversarial behavior
  • Strong written and verbal communication skills, including the ability to draft and present technical intelligence reports to varied audience.
  • Ability to manage and prioritize multiple concurrent RFIs in a high-tempo operations environment
  • Working knowledge of network architecture and protocols, including TCP/IP, DNS, HTTP/S, SMTP, and common intrusion methods
  • Hands-on experience with collaboration and tracking tools such as JIRA, Confluence, MS Teams, and SharePoint
  • Demonstrated ability to work collaboratively in a cross-functional environment under minimal supervision

Benefits at Sentar:

Our unique ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.
  • Voluntary Medical, Dental, Vision, with Health Savings or Flexible Spending Plan options
  • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
  • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
  • Generous 401(k) match
  • Competitive PTO plan that graduates quickly with years of service
  • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
  • Mental health awareness programs
  • Tuition reimbursement
  • Professional development reimbursement
  • Recognition and Awards programs

If you are not ready to apply for this position, submit your resume here to join our talent community . We'll keep you updated occasionally on new job opportunities.

Similar Jobs

More Jobs at Sentar

More Aerospace & Defense Jobs

Find similar Action Officer jobs: