Full-Time

Defensive Cyber Operations Analyst

DCO

Posted on 8/20/2026

Dark Wolf Solutions

Dark Wolf Solutions

201-500 employees

DevSecOps, security testing, and incident response.

Compensation Overview

$90k - $145k/yr

No H1B Sponsorship

Ogden, UT, USA

In Person

Fully on-site at Hill Air Force Base.

US Citizenship, US Top Secret Clearance Required

Bachelor's

Category
IT & Security (1)
Required Skills
Incident Response
Logstash
Microsoft Windows
Machine Learning
Cybersecurity
Vulnerability Analysis
Elasticsearch
Terraform
Ansible
DevOps
Kibana

Get referred to Dark Wolf Solutions

See people who can refer or advise you

Requirements
  • At least 4 years of relevant cybersecurity experience, including direct security operations center, virtual security operations center, or Cybersecurity Service Provider incident response experience.
  • At least 2 years of hands-on experience using Splunk Enterprise and the ELK Stack, including Elasticsearch, Logstash, and Kibana, for event correlation and threat detection.
  • Direct experience monitoring, ingesting, and analyzing security telemetry within AWS GovCloud environments, including CloudTrail, VPC Flow Logs, or AWS GuardDuty.
  • Hands-on experience utilizing GitLab for source control, continuous integration and continuous delivery pipelines, issue tracking, or DevSecOps workflows.
  • At least 2 years of experience applying Department of Defense cybersecurity requirements, policies, and procedures, including assessment and authorization activities.
  • A Department of Defense Directive 8140 / 8570 IAT CSSP certification must be obtained prior to hire, such as CEH, Security+, GCIH, CySA+, or an equivalent certification.
  • A bachelor's degree in Computer Science, Information Technology, or a related field is required.
  • U.S. citizenship and an active Top Secret/SCI security clearance are required.
Responsibilities
  • Continuously monitor systems to identify malicious cyberattacks and support containment and remediation of information technology threats.
  • Perform hands-on incident response, event correlation, and threat detection across on-premises ELK environments and AWS GovCloud environments using Splunk Enterprise.
  • Monitor, detect, and analyze activity across on-premises ELK and cloud-hosted AWS GovCloud environments.
  • Use artificial intelligence-assisted analysis, automation, and data correlation from various log sources to triage security events, detect anomalies, and reduce response times for complex threats.
  • Perform vulnerability management actions, including providing recommendations and implementing mitigations.
  • Conduct intrusion analysis and correlate unauthorized activities; provide and implement recommendations to improve detection and customer mitigation processes.
  • Participate in root cause analysis and document efforts taken to mitigate unauthorized actions.
  • Participate in developing Defensive Cyber Operations tactics, techniques, procedures, and supporting documentation.
  • Identify security discrepancies and report and respond to security incidents.
  • Provide research and analysis to support expanding programs and areas of responsibility.
  • Draft documentation for briefings, reports, and informational analyses.
  • Participate in customer exercises, including after-duty-hours activities when required.
  • Adhere to defined policies, master plans, and schedules.
  • Complete all initial and annual training requirements and disclosures outlined by BSTG.
  • Perform other duties consistent with the department's goals, objectives, and responsibilities.
Desired Qualifications
  • Experience with artificial intelligence and machine learning security tools, such as generative artificial intelligence for query generation, automated threat intelligence, or artificial-intelligence-driven behavioral analytics.
  • AWS Certified Security – Specialty certification.
  • Splunk Core Certified Power User or Administrator certification, or Elastic Certified Analyst certification.
  • Experience writing search queries using SPL (Splunk Processing Language) and KQL/Lucene (Kibana Query Language).
  • Experience with SentinelOne or similar endpoint detection and response platforms for endpoint detection, threat hunting, and automated remediation.
  • Familiarity with Infrastructure-as-Code tools such as Terraform or Ansible within a DevSecOps environment.
  • Experience performing cybersecurity activities supporting software and system requirements, design, development, testing, and sustainment.
  • Experience with HBSS, ACAS, SCAP Compliance Checker, and DISA STIGs.
  • Working knowledge of NIST 800-53 Security and Privacy Controls.
  • Experience with operating systems such as RHEL and Windows.
  • Experience performing post-incident computer forensics without destroying critical data.
  • Ability to provide guidance on Department of Defense cyber regulations and requirements to engineering and software development staff.

Dark Wolf Solutions provides DevSecOps agile software development, information operations, penetration testing and incident response, applied research and rapid prototyping, machine learning, and mission support for the Intelligence Community, national security, and Fortune 500 customers. They integrate secure development, security testing, rapid prototyping, ML, and operations support to deliver secure software and cyber capabilities aligned with specific mission needs. They combine deep federal domain expertise with emerging technologies to offer end-to-end capabilities from development to ongoing operations. Their goal is to help security-focused organizations advance their missions while keeping systems secure and resilient.

Company Size

201-500

Company Stage

N/A

Total Funding

N/A

Headquarters

Herndon, Virginia

Founded

2009

Get referred to Dark Wolf Solutions

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • On June 11, 2026, Dark Wolf won a Navy IDIQ worth $178.4 million.
  • On February 2, 2026, the Air Force awarded a $67.2 million cyber contract.
  • January 2026 reorganization added BrickStor products, broadening mission data and ransomware defenses.

What critics are saying

  • GSA MAS option ends September 1, 2026, exposing renewal risk across federal sales.
  • Herndon hiring data shows 28 openings, signaling execution pressure during aggressive contract growth.
  • Dark Wolf depends on DoD sole-source and set-aside vehicles; one protest starves revenue.

What makes Dark Wolf Solutions unique

  • Dark Wolf is sole awardee on Air Force Cyberspace Innovation IDIQ, announced February 2026.
  • Its Platform One marketplace lists seven awardable accelerators, including DARK MASS and Data Den.
  • The company spans GSA MAS, SeaPort-NxG, and Navy IDIQs, deepening federal buying access.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

18%

1 year growth

18%

2 year growth

18%
JoBlo.com
Feb 9th, 2024
The Terminal List: Dark Wolf adds Luke Hemsworth to the season's cast

The Terminal List: Dark Wolf adds Luke Hemsworth to the season's cast.

PR Newswire
May 17th, 2022
At-Impact And Dark Wolf Enterprise Toolchain To Support Kessel Run

FALLS CHURCH, Va., May 17, 2022 /PRNewswire/ -- At-Impact, in partnership with Dark Wolf, was awarded the Kessel Run's Enterprise Toolchain contract (Kessel ET), a $41M CIO-SP3 SB award to provide Commercial IT services and the integrated support team needed to enhance Kessel Run's...