Cyber Operations Center (CyOC) Lead Analyst
Charleston, SC
Full Time Senior-level / Expert Clearance required USD 103K - 193K *
Sentar Inc.
Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the small business team where you can build, innovate, and secure your career.
The Cyber Operations Center (CyOC) Lead Analyst is a senior-level cybersecurity professional responsible for leading, coordinating, and integrating key Cybersecurity Service Provider (CSSP) functions within the Defense Health Agency (DHA) Cyber Operations Center (CyOC). This role requires expertise in cyber operations, compliance management, and incident response, with a strong emphasis on leadership, cross-functional collaboration, and strategic coordination across multiple teams and stakeholders.
As a key leader within the CyOC structure, the Lead Analyst will serve as the primary interface between CSSP functional teams, interagency partners, and DHA leadership, ensuring alignment with DHA cybersecurity objectives, USCYBERCOM directives, and federal cybersecurity policies.
Key Responsibilities:
Strategic Leadership & Team Coordination
- Lead and coordinate teams within the DHA Cyber Operations Center, including Incident Response, Continuous Monitoring (ConMon), Threat Intelligence, Vulnerability Management, Digital Forensics, and Compliance.
- Serve as the senior CSSP liaison to DHA leadership, JFHQ-DoDIN, USCYBERCOM, interagency partners, and other stakeholders, ensuring effective communication and alignment of cybersecurity initiatives.
- Oversee the implementation of CSSP functions, ensuring teams execute cyber defense operations, compliance monitoring, and risk assessments in accordance with DoD cybersecurity policies.
- Develop and enforce Standard Operating Procedures (SOPs) to standardize cybersecurity reporting, risk assessments, and information dissemination.
Cybersecurity Operations & Incident Response
- Direct cyber incident response efforts, ensuring timely escalation, coordination, and resolution of cybersecurity threats affecting DHA networks and systems.
- Oversee threat intelligence analysis, working with cyber hunt teams and intelligence units to identify, assess, and mitigate emerging threats.
- Ensure forensic investigations are conducted in alignment with DHA and DoD forensic standards, including proper evidence handling and chain-of-custody documentation.
- Guide the development and enforcement of cyber threat hunting methodologies, Indicators of Compromise (IoCs), and SIEM alerting strategies.
- Supervise the development and execution of Purple Team engagements, testing defensive cyber operations (DCO) and CSSP processes.
Compliance & Vulnerability Management
- Oversee compliance with USCYBERCOM directives, DoD cybersecurity policies (NIST 800-53, RMF, DoDI 8530.01), and federal regulations.
- Lead the vulnerability management team, ensuring identification, assessment, and remediation of cyber vulnerabilities through IAVM, VRAM, CMRS, and ACAS reporting.
- Direct CSSP teams in executing continuous monitoring (ConMon) activities, ensuring adherence to CJCSI 6510.01F and maintaining the cybersecurity posture of DHA networks.
- Ensure compliance with JFHQ-DoDIN and DISA security assessment requirements, maintaining operational readiness for CCRI and DoD audits.
Information Management & Interagency Coordination
- Act as the primary point of contact for cybersecurity directives and information flow, ensuring DHA CyOC receives and disseminates critical updates.
- Oversee cross-functional collaboration between CSSP teams, defensive cyber operations (DCO) teams, and DHA IT security stakeholders.
- Facilitate interagency coordination, ensuring effective collaboration with VA CSOC, USCYBERCOM, DISA, and CISA on cyber incident reporting and threat intelligence sharing.
- Present cybersecurity reports, threat assessments, and risk mitigation strategies to senior DHA leadership and key stakeholders.
Training, Mentorship & Workforce Development
- Mentor and develop CSSP team members, fostering a culture of continuous improvement and cybersecurity excellence.
- Lead cybersecurity training initiatives to enhance workforce capabilities, ensuring alignment with DoD 8570.01-M and NICE Cybersecurity Workforce Framework.
- Ensure CyOC personnel maintain required DoD certifications and participate in professional development opportunities.
Qualifications:
Clearance Level: Active Secret Clearance required (TS/SCI preferred).
Certifications: Active IAT Level III certification (CISSP, CASP+, CISM, or equivalent) required.
Experience:
- Minimum 15 years of experience in cybersecurity operations, risk management, and leadership roles within DoD, CSSP, or Cyber Operations Centers.
- Expertise in incident response, vulnerability management, threat intelligence, and cyber defense operations.
- Hands-on experience with key DoD cybersecurity tools such as Splunk, HBSS, ACAS, VRAM, CMRS, and SIEM platforms.
- Proven ability to lead and coordinate teams in a high-tempo cyber operations environment.
Key Competencies & Soft Skills
- Strategic thinker with the ability to drive cybersecurity initiatives at the enterprise level.
- Strong leadership and interpersonal skills, capable of engaging with senior leaders and technical teams.
- Excellent verbal and written communication skills, including experience in presenting cybersecurity briefings.
- Highly organized and detail-oriented, with a proven ability to manage multiple teams and priorities.
- Proactive problem solver, with a deep understanding of cybersecurity risk mitigation strategies.
Preferred Experience
- Experience leading DoD-accredited CSSP teams or Security Operations Centers (SOC).
- Familiarity with Purple Teaming, Insider Threat Monitoring, and Digital Forensics methodologies.
- Experience supporting DHA cybersecurity initiatives and securing medical IT infrastructure.
- Prior experience with CCRI inspections, JFHQ-DoDIN assessments, and USCYBERCOM tasking orders.
Benefits at Sentar:
In addition to a great culture, Sentar not only fosters an inclusive work environment but also offers an extensive benefits package designed to cater to the well-being of its employees and their families.
- Voluntary Medical, Dental, Vision, with Health Savings or Flexible Spending Plan options
- Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
- Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
- Generous 401(k) match
- Competitive PTO plan that graduates quickly with years of service
- Other leave programs; holiday schedule along with bereavement, jury and military duty
- Mental health awareness programs
- Tuition reimbursement
- Professional development reimbursement
- Recognition and Awards programs
If you are not ready to apply for this position, submit your resume here to join our talent community. We'll keep you updated occasionally on new job opportunities.
Sentar is an Affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities
Our culture is one of inclusivity and support. Sentar is proudly an Equal Opportunity and VEVRAA Federal Contractor Employer M/F/Vets/Persons with Disabilities. Follow these links to learn more about your rights: EEO Is the Law Poster; EEO Is Law Supplement; and Pay Transparency.
We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at recruiting@sentar.com. Please indicate the specifics of the assistance needed. Thank you for considering Sentar in your employment search.
Build, Innovate, Secure Your Career at Sentar.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: ACAS Analytics Audits CASP+ CISA CISM CISSP Clearance Clearance Required Compliance CSOC Cyber defense DCO DISA DoD DoDD 8570 Forensics Incident response IT infrastructure Monitoring NIST NIST 800-53 Risk assessment Risk management RMF Security assessment SIEM SOC Splunk Threat intelligence TS/SCI Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Competitive pay Flex hours Flex vacation Health care Insurance Medical leave Transparency
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.