Amentum

Mid-Level Cyber Threat Emulation Analyst IRES - SSFB

Amentum$128K — $136K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of general work experience.
  • 2+ years in manual or automated penetration testing, vulnerability assessment, or incident response.
  • 6+ months in a management or leadership role.
  • Prior Missile Defense Agency experience required.
  • Familiarity with the CVE database and DoD cybersecurity structure essential.
  • Must hold one of the specified cybersecurity certifications (e.g., CompTIA Security+) and acquire CompTIA PenTest+ within 6 months.
  • Active DoW Secret Security Clearance necessary.

Responsibilities

  • Perform Defensive Cyber Operations as part of a DoD Cybersecurity Service Provider.
  • Measure effectiveness of defense-in-depth architectures against known vulnerabilities.
  • Support enterprise Incident Response according to DoD regulations.
  • Develop and lead an Exploitation Analyst training plan for various analyst levels.
  • Execute CTE actions against specific adversary TTPs to assess detection capabilities.
  • Collaborate with the Vulnerability Assessment and Cyber Defense Teams on evaluation methodologies and criteria.
  • Evaluate training and effectiveness of incident response processes against real-world threats.

Benefits

  • Health, dental, and vision insurance.
  • Paid time off and observed holidays.
  • 401(k) retirement benefits with matching.
  • Educational reimbursement opportunities.
  • Parental leave provided.
  • Employee stock purchase plan available.
  • Tax-saving options offered.
  • Disability and life insurance included.
  • Pet insurance offered.
Full Job Description

Position Title: Mid-Level Cyber Threat Emulation Analyst

Location: Schriever Space Force Base, Colorado Springs, CO

Relocation Assistance: None available at this time

Remote/Telework: NO - Not available for this position

Clearance Type: DoW Secret

Shift: Day shift

Travel Required: Up to 10% of the time

Description of Duties:

We are seeking a highly motivated and experienced Mid-Level Cyber Threat Emulation (CTE) Analyst.  The CTE Analyst supports the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract. The CTE Analyst will be responsible for operating the Department of War Cyber Defense Command Information Network’s (DCDC-IN) Cyber Threat Emulation (CTE) toolset. This role requires a deep understanding of cybersecurity vulnerabilities in a DoD environment and the ability to correlate threat and vulnerability data against known adversary exploits and techniques. The ideal candidate will be a customer-focused individual with excellent communication skills and the ability to work both independently and as part of a team.

Key Responsibilities:

  • Perform Defensive Cyber Operations (DCO) as it pertains to a DoD Cybersecurity Service Provider (CSSP)
  • Measures effectiveness of defense-in-depth architecture against known vulnerabilities.
  • Support Incident Response across the enterprise IAW DoD regulations and instructions.
  • Develop an Exploitation Analyst training plan by instructing, evaluating, and mentoring junior, mid, and senior analysts.
  • Execute HHQ directed and custom CTE actions with specific adversary tactics, techniques, and procedures (TTPs) to assess toolset detection and alerting.
  • Collaborate with the Vulnerability Assessment and Cyber Defense Teams to develop evaluation criteria and methodologies aligned with HHQ inspection requirements and industry best practices.
  • Evaluate personnel training and effectiveness in incident response processes and procedures to detect, respond, and mitigate simulated and real-world threats to recognize the need for additional training

The successful candidate will:

  • Have strong initiative, attention to detail, and communication skills (written and verbal).
  • Have a customer-focused approach to problem-solving.

Resumes, in month and year format, must be submitted with application in order to be considered for the position.  The selected candidate may be assigned as an employee for one of our teammate companies.

Basic Requirements:

  • Must have 4, or more, years of general (full-time) work experience
  • May be reduced with completion of advanced education
  • Must have 2, or more, years of combined experience with any of the following:
    • Performing manual or automated penetration testing in an enterprise environment
    • Practical experience with vulnerability assessment, cybersecurity frameworks, or conducting risk assessments
    • Experience performing the full life cycle of incident response and enterprise-level monitoring
  • Must have 6, or more, months of experience working in a management or leadership role
  • Must have prior MDA experience.
  • Must be familiar with the Common Vulnerabilities and Exposures (CVE) database.
  • Must be familiar with the role of a CSSP in the DoD’s tiered cybersecurity structure.
  • Must be familiar with Information Assurance Vulnerability Bulletins (IAVBs) and Alerts (IAVAs)
  • Must have a strong understanding of cyber threat emulation tools, policies, and procedures.
  • Must have an understanding of security, audit, and compliance principles.
  • Must have an understanding of defense in depth principles and defensive cyber operations
  • Must have an understanding of defensive cyber operations common toolsets to include:
    • Next Generation Firewalls (Palo Alto experience Preferred)
    • Intrusion Prevention / Detections Systems
    • Email Security Gateways
    • Network Proxies
    • Reverse Proxies and Web Application Firewalls
    • Security Information and Event Management systems
    • Endpoint Detection and Response
    • Vulnerability Scanning and Assessment tools
  • Must have 1, or more, of the following certifications:
    • CompTIA Security+
    • CompTIA Cybersecurity Analyst (CySA+)
    • ICS2 Systems Security Certified Practitioner (SSCP)
    • GIAC Industry Cyber Security Certification (GICSP)
    • GIAC Security Essentials (GSEC)
  • Must have or obtain within 6 months of start date, the CompTIA PenTest+ certification
  • Must have an active DoW Secret Security Clearance

This position will be posted for a minimum of 3 days. If a candidate has not been selected at that time, it will continue to be posted until a suitable candidate is selected or the position is closed.

Compensation Details:

$128,000 – $136,000

       

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.

 

Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance

 

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

       

Original Posting:

07/21/2026 - 07/29/2026

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

       

About Amentum

Amentum is a leading provider of engineering and technical services to the U.S. government and commercial customers worldwide. The company offers a wide range of services, including environmental remediation, facilities management, and logistics and supply chain management, among others. Amentum has a global presence, with operations in over 20 countries, and serves a diverse range of customers, including the Department of Defense, the Department of Energy, and the Department of State. The company is committed to providing high-quality services and has a strong reputation for technical expertise, innovation, and customer satisfaction.
Learn more about Amentum
Size
20,000 employees
Industry
Net Income
$200 million
Founded
2014
Revenue
$5 billion

Similar Jobs

More Jobs at Amentum

More Aerospace & Defense Jobs

Find similar Mid-Level Cyber Threat Emulation Analyst IRES - SSFB jobs: