CSOS III/Tier 3
Company: CACI
Location: Springfield
Posted on: April 1, 2026
|
|
|
Job Description:
Job Title: CSOS III/Tier 3 Job Category: Information Technology
Time Type: Full time Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular Percentage of Travel Required: Up to 10%
Type of Travel: Local * * * The Opportunity Candidate will provide
CSOC Tier 3 services, which is 24x7x365 coordination, execution,
and implementation of all actions required for the containment,
eradication, and recovery measures for events and incidents. CSOC
Tier 3 services includes malware and implant analysis, and forensic
artifact handling and analysis. All Contractor personnel performing
CSOC Tier 3 services shall have or obtain, within six months of
start, a certification that is compliant with DoDD 8140.01 and DoD
8570.01-M IAT Level III and CSSP Incident Responder.
Responsibilities • Coordinate and implement tasks, performing
analysis, and building/documenting response activities required
during cyber security incident response, to include but not limited
to actions such as implementing containment measures, IP blocks,
domain blocks, and disabling user accounts on direction of the
Government. • Coordinates with Security and Installations
Directorate (SI) Office of Counterintelligence (SIC), Insider
Threat Office (SIII), in addition to other law enforcement and
counter intelligence personnel as required to perform advanced
investigation and triage of incidents; • Collaborates with
appropriate authorities in the production of security incident
reports; Categorizes incidents and events • Coordinates with other
contracts, organizations, activities, and services to ensure NGA
recovers from an incident/event; • Builds timelines, documents,
briefings, and other products as required to inform stakeholders of
incident response actions, analysis, and the impact of both
adversary activity and blue force response actions. • Develops and
when approved by the Government generates and updates reports in
the Joint Incident Management System (JIMS), Incident Case
Management System (ICMS), and/or other authorized reporting systems
as directed; • Performs digital media analysis on host, server, and
network data as required to analyze and respond to an incident, to
include but not limited to volatile and non-volatile memory and/or
system artifact collection and analysis; • Performs malware
analysis and signature development; • Coordinate with CSOC Tier 1
and 2 services to remediate all discrepancies and provide
recommendations to prevent reoccurrence. Qualifications Required: •
Bachelors Degree and or 6 years’ experience in Cyber Security
(CSOS) • Active TS/SCI, ability to obtain a polygraph • DoDD
8140.01 and DoD 8570.01-M IAT Level II and CSSP Incident Responder.
Provides input to and coordinates with all applicable stakeholders
to develop and deliver the daily CSOC Significant Activity Report,
the daily CSOC Operations Update, and the Weekly CSOC Status
Report; • Serve as C-IRT members as required and serve under the
direct control of, and take direction from, the Government C-IRT
Commander; • Develop and coordinate courses of action with various
Government and contract stakeholders, and when properly authorized
by the Government, execute Defensive Cyberspace Operations-Internal
Defensive Measures on behalf of the NGA on NGA networks and
systems; • Performs digital media analysis and malware reverse
engineering on host, server, and network data as required to
analyze and respond to an incident, to include but not limited to
volatile and non-volatile memory and/or system artifact collection
and analysis. • When properly authorized by the Government, execute
custom scripts, tools, and capabilities to collect and analyze
data, and to respond to incidents/events; • Develops, documents,
and provides to the Government incident investigation reports which
include sufficient information to document the entire lifecycle of
the incident and the response, including but not limited to
adversary and friendly forces activity, host and network analysis,
timelines, and recommendations for corrective actions,
recommendations for new Tactics, Techniques, and Procedures (TTP)
and other recommendations as appropriate, within 30 days of C-IRT
stand-down; • Conduct Quality Control reviews - What You Can
Expect: A culture of integrity. At CACI, we place character and
innovation at the center of everything we do. As a valued team
member, you’ll be part of a high-performing group dedicated to our
customer’s missions and driven by a higher purpose – to ensure the
safety of our nation. An environment of trust. CACI values the
unique contributions that every employee brings to our company and
our customers - every day. You’ll have the autonomy to take the
time you need through a unique flexible time off benefit and have
access to robust learning resources to make your ambitions a
reality. A focus on continuous growth. Together, we will advance
our nation's most critical missions, build on our lengthy track
record of business success, and find opportunities to break new
ground — in your career and in our legacy. Pay Range : There are a
host of factors that can influence final salary including, but not
limited to, geographic location, Federal Government contract labor
categories and contract wage rates, relevant prior work experience,
specific skills and competencies, education, and certifications.
Our employees value the flexibility at CACI that allows them to
balance quality work and their personal lives. We offer competitive
compensation, benefits and learning and development opportunities.
Our broad and competitive mix of benefits options is designed to
support and protect employees and their families. At CACI, you will
receive comprehensive benefits such as; healthcare, wellness,
financial, retirement, family support, continuing education, and
time off benefits. The proposed salary range for this position is:
$86,600 - $181,800 CACI is an Equal Opportunity Employer. All
qualified applicants will receive consideration for employment
without regard to race, color, religion, sex, pregnancy, sexual
orientation, age, national origin, disability, status as a
protected veteran, or any other protected characteristic.
Keywords: CACI, Annandale , CSOS III/Tier 3, IT / Software / Systems , Springfield, Virginia