Action Officer
On-siteCharleston, South Carolina, United States
Job Summary
Receive, assess, and triage incoming Requests for Information (RFIs) from Defense Health Agency subscribers regarding cybersecurity threats and incidents. Conduct detailed research and threat analysis on cyber incidents, indicators, and adversary activity to develop actionable intelligence reports. Collaborate with internal analysts, incident responders, and threat intelligence teams to ensure comprehensive responses while maintaining situational awareness of emerging threats. Support the development of RFI processing workflows and standard operating procedures, providing technical guidance on threat mitigation and security best practices. Track RFI status, metrics, and trends to support operational reporting and performance improvement within a high-tempo environment.
Required Qualifications
- Top Secret/SCI clearance
- DoD 8140 (Formerly 8570) baseline certification
- 5+ years of experience in cybersecurity, threat intelligence analysis, or related cyber defense roles supporting DoD or federal agencies
- Strong understanding of DoD cybersecurity policies, including DoD 8500-series, DoDI 8510.01 (RMF), and CJCSM 6510.01 (Cyber Incident Handling)
- 5+ years of experience conducting cyber threat research, analysis, and reporting in support of SOC, IR, or cyber threat intel teams
- Proficiency in analyzing cyber threats across the MITRE ATT&CK framework, including TTPs and IOCs
- Experience with threat intelligence platforms (TIPs), SIEM tools (e.g., Splunk, ELK, QRadar), and open-source intelligence (OSINT) research tools
- Familiarity with malware analysis, DDoS patterns, phishing campaign forensics, and adversarial behavior
- Strong written and verbal communication skills, including the ability to draft and present technical intelligence reports to varied audience
- Ability to manage and prioritize multiple concurrent RFIs in a high-tempo operations environment
- Working knowledge of network architecture and protocols, including TCP/IP, DNS, HTTP/S, SMTP, and common intrusion methods
- Hands-on experience with collaboration and tracking tools such as JIRA, Confluence, MS Teams, and SharePoint
- Demonstrated ability to work collaboratively in a cross-functional environment under minimal supervision
Desired Qualifications
- Security+
- CISM
- CISSP
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.