Sentar is seeking a Tier 2 Watch Analyst in Ft. Bragg, NC to serve as the investigation and correlation layer of the 24/7/365 Blue Team watch. Tier 2 analysts stand watch on the rotation, own incident records from creation through closure, perform multi-source correlation, recommend containment and eradication actions, and quality-control Tier 1 work before closure.
Role Description: Watch Operations
• Stand assigned watch periods on the approved 24/7/365 rotation, performing Tier 1 and Tier 2 functions on console within qualification and SOP boundaries
• Execute pass-down log entries, verbal handoff briefings, and critical-incident re-confirmation at every shift change
• Support hunts, training, and exercises only after watch coverage is protected
Investigation and Correlation
• Correlate anomalous activity across SIEM (Elastic), Trellix ENS, Tychon EDR, full packet capture, NetFlow, IDS/IPS, proxy, router/firewall syslog, and boundary-device telemetry to characterize event scope
• Escalate suspected APT activity, complex intrusions, and uncertain containment to the Blue Team Lead (Tier 3) without delay
Incident Handling and Response
• Own incident records through closure, including CJCSM 6510.01B category assignment, timely reporting, and currency of the ARCYBER incident-handling portal
• Recommend containment and eradication actions in coordination with the affected mission owner and ISSO; execute approved critical blocks within the two-hour standard
• Capture and perform initial analysis of volatile data, logs, and captured traffic; maintain chain of custody and coordinate evidence shipment to ARCYBER F&MA when required
• On-Call Responsibilities • Phone response within 30 mins of incident and on-site reporting within one hour, when required
Quality Control and Reporting
• Perform quality-control review of Tier 1 tickets prior to closure; conduct incident trend analysis
• Provide technical inputs to the Daily Blue Team Operations Report and weekly and monthly Blue Team reporting
Work Environment
• Onsite presence at USARC Headquarters, Fort Bragg, NC required
• Rotating 8-hour shifts on a 24/7/365 watch including nights, weekends, and Federal holidays
• Solo watch assignments during evening, night, weekend, and holiday periods
Qualifications: • Bachelor's degree and 5 years of experience, or AA with 7+ years
• DoDM 8140.03 qualification for DCWF 511 Cyber Defense Analyst at Intermediate proficiency (required for any solo watch assignment)
• DoDM 8140.03 qualification for DCWF 531 Cyber Defense Incident Responder at Intermediate proficiency required for selected positions assigned incident-response duties
• Favorably adjudicated Tier 3 investigation; Tier 5 required prior to any privileged access
• US Citizenship required
• Current DoD SECRET clearance required (interim SECRET acceptable at start; final SECRET required within 120 days of award)
• Ability to obtain and maintain a DoD Common Access Card and USARC installation access
• Completion of DoD Cyber Awareness training prior to system access and annually thereafter; AT Level I, OPSEC Level I, TARP, and CUI training within 30 days of start
SPECIFIC KNOWLEDGE, SKILLS, & ABILITIES:
• Demonstrated experience in a DoD or enterprise SOC performing multi-source investigation and correlation
• Hands-on proficiency with an enterprise SIEM (Elastic preferred) and with host-based security, EDR, PCAP, NetFlow, and IDS/IPS analysis
• Working knowledge of MITRE ATT&CK, CJCSM 6510.01B incident categories, and DoD incident reporting timelines
• Familiarity with volatile data capture, evidence preservation, and chain-of-custody procedures
• Familiarity with Windows, Linux, and macOS operating systems and with Wireshark and scripting for repeatable triage
• Ability to work rotating shifts and to maintain accuracy and attention during extended monitoring periods
• Working knowledge of CJCSM 6510.01B incident categories and DoD/Army cyber incident reporting requirements
• Excellent interpersonal and written communication skills to interact effectively with Government stakeholders, ARCYBER and Regional Cyber Center counterparts, and team members
• The ability to communicate complex technical findings clearly to non-technical audiences
• A willingness to uncover, document, and communicate deviations from planned outcomes in order to improve processes and prevent recurrence
• A passion for continuous learning and a commitment to stay current with emerging threats, adversary tradecraft, and defensive technologies
Clearance Level: Secret
Education: BA/BS with 5+ years or AA with 7+ years
Certifications: DoDM 8140.03 qualified as DCWF 511 Cyber Defense Analyst, Intermediate (531 Incident Responder, Intermediate, for IR-assigned seats)
Benefits at Sentar: Our unique employee ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.
- Voluntary Medical, Dental, Vision, with Flexible Spending Plan options
- Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
- Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
- Generous 401(k) match
- Competitive PTO plan that graduates quickly with years of service
- Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
- Tuition reimbursement
- Professional development reimbursement
- Recognition and Awards programs
If you are not ready to apply for this position,
submit your resume here to join our talent community . We\'ll keep you updated occasionally on new job opportunities.