Test Event Cyber Security Lead (Secret)

Aegis Aerospace

$150K — $170K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. citizenship required.
  • Active DoD Secret security clearance or higher.
  • Six years of full-time work experience; reduced with advanced education.
  • Four years of relevant professional experience.
  • Six months in a management or leadership role.
  • Hands-on experience with a Security Information and Event Management platform.
  • Experience with an Endpoint Detection and Response or Protection Platform solution.
  • Current ACAS certificate; experience with vulnerability scans using ACAS.

Responsibilities

  • Architect and manage cybersecurity processes and develop operational monitoring dashboards.
  • Assist with query-based threat hunting across centralized log repositories.
  • Schedule and execute credentialed ACAS vulnerability scans.
  • Track remediation timelines and generate technical remediation tickets.
  • Implement and document DISA STIGs for system security compliance.
  • Manage system configurations and enforce PPSM baselines.
  • Support DoD RMF lifecycle continuous monitoring and authorization packages.
  • Triage operational security anomalies; conduct preliminary root-cause forensic analysis.
  • Oversee engineers automating tasks with Python, PowerShell, or Bash.
  • Coordinate with system administrators and network engineers for patch validation.

Benefits

  • Full-time, day shift work schedule.
  • Opportunity to lead cybersecurity efforts for the Missile Defense Agency.
  • Engagement in high-stakes defense projects.
  • Collaborative environment with diverse cybersecurity professionals.
  • Support innovative approaches to vulnerability management and threat detection.
Full Job Description
Test Event Cybersecurity Lead
Location: Schriever Space Force Base, Colorado Springs, CO
Relocation Assistance: None available at this time
Remote/Telework: No - Onsite support required
Citizenship Requirement: U.S. citizenship required
Clearance Required: Active DoD Secret security clearance
Work Schedule: Full-Time, Day Shift
Travel: Up to 10%

Position Summary
Aegis Aerospace is seeking a Test Event Cybersecurity Lead to support the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract at Schriever Space Force Base in Colorado Springs, Colorado. The Test Event Cybersecurity Lead manages engineers and Information System Security Officers (ISSOs) responsible for defensive cyber operations, vulnerability lifecycle management, and security-posture monitoring across mission environments. This position is responsible for the overall cybersecurity and operational health of test-event packages. The lead assigns work, establishes team goals and priorities, oversees vulnerability scanning through Assured Compliance Assessment Solution (ACAS), manages endpoint-protection activities, and ensures compliance with Department of Defense Risk Management Framework (RMF) requirements.

Primary Responsibilities
  • Architect and manage cybersecurity processes and oversee the development of operational monitoring dashboards.
  • Assist with complex, query-based threat hunting across centralized log repositories.
  • Develop and manage the scheduling and execution of credentialed ACAS vulnerability scans.
  • Correlate vulnerability-scan findings, track remediation timelines, and generate technical remediation tickets.
  • Implement, verify, and document Defense Information Systems Agency Security Technical Implementation Guides (DISA STIGs).
  • Manage system configurations and enforce Ports, Protocols, and Services Management (PPSM) baselines.
  • Support continuous monitoring and authorization packages throughout the DoD RMF lifecycle in accordance with NIST SP 800-37 and NIST SP 800-53.
  • Triage and contain operational security anomalies, conduct preliminary root-cause forensic analysis, and support defensive cybersecurity reporting.
  • Oversee engineers using Python, PowerShell, or Bash to automate administrative tasks, parse security logs, and streamline vulnerability-scan analysis.
  • Oversee engineers working with the ELK Stack-Elasticsearch, Logstash, and Kibana-or equivalent centralized log-aggregation platforms.
  • Oversee engineers supporting VMware vSphere and ESXi virtualized infrastructures and automated configuration management using Ansible.
  • Oversee firewall-rule management, network access control lists, and network-traffic analysis.
  • Respond rapidly to high-priority cybersecurity alerts outside standard operating hours while participating in an on-call rotation.
  • Coordinate directly with system administrators, ISSMs, and network engineers to validate patches and mitigate identified vulnerabilities.
  • Maintain audit readiness for Command Cyber Readiness Inspections and external cybersecurity assessments.
  • Schedule and manage a team of engineers supporting test events, including support outside core operating hours.
  • Respond to and triage Cyber Tasking Orders applicable to assigned and managed packages.

Minimum Qualifications
  • Must be a U.S. Citizen.
  • Must have an active DoD Secret security clearance or higher.
  • Six or more years of general full-time work experience. This requirement may be reduced based on the completion of advanced education.
  • Four or more years of directly related professional experience.
  • Six or more months of experience in a management or leadership role.
  • Demonstrated hands-on experience with a Security Information and Event Management platform, including managing data ingestion, developing security-monitoring dashboards, and performing query-based analysis of security events.
  • Experience with an Endpoint Detection and Response or Endpoint Protection Platform solution, such as Trellix Endpoint Security or Microsoft Defender for Endpoint.
  • Current ACAS certificate and experience performing vulnerability scans using ACAS, including Tenable SecurityCenter and Nessus.
  • Experience with both Windows and Linux operating systems.
  • Ability to participate in an on-call rotation and respond to cybersecurity incidents outside standard business hours as required.
  • Compliance with DoD 8570/8140 Information Assurance Technical Level II requirements at a minimum, such as CompTIA Security+ CE, CySA+, or GSEC.

Preferred Qualifications
  • Strong working knowledge of the DoD Risk Management Framework lifecycle.
  • Experience with the ELK Stack-Elasticsearch, Logstash, and Kibana-or similar log-aggregation and monitoring tools.
  • Experience applying and verifying DISA STIGs and familiarity with Ports, Protocols, and Services Management.
  • Proficiency with Python, PowerShell, Bash, or a similar scripting language used to automate administrative and cybersecurity tasks.
  • Experience with virtualization and automation platforms, particularly VMware vSphere, VMware ESXi, and Ansible.
  • Current DoD 8570/8140 Information Assurance Technical Level III certification.

Compensation:
Salary Range: $150,000 - $170,000 annually. Final compensation is based on experience, education, location, and applicable certifications.

Application Instructions:
  • Resumes must be submitted in month/year format with clearance level clearly listed to be considered.
  • Candidates must be fully truthful in their application and resume. Dishonesty, omission of required information, or misrepresentation may result in disqualification.
  • Only U.S. citizens with an active DoD Secret security clearance will be considered.
  • Applications are reviewed for compliance prior to technical qualification. Submissions that do not meet the stated requirements or instructions will not be reviewed.

To learn more about Aegis Aerospace, please visit our website: http://www.AegisAero.com

Similar Jobs

More Jobs at Aegis Aerospace

More Aerospace & Defense Jobs

Find similar Test Event Cyber Security Lead (Secret) jobs: