1

Cyber Defense Operator Jobs (NOW HIRING)

Cyber Defense Operator (CDO)

TX · On-site

$75K - $95K/yr

Cyber Defense Operator (CDO ) - TS/SCI Level Clearance Required - Located in San Antonio, Texas The ability of the Cyber Defense Operator (CDO) is to complete its mission dependent upon accurate ...

Helping the nation's cyber operators do their jobs better, faster, and at greater scale * Creating game-changing capabilities for defensive cyberspace operations As an interdisciplinary group, we ...

... operating systems of a network device based on network traffic - Reconstruct a malicious attack or activity based off network traffic - Identify network mapping and operating system (OS ...

... operating systems of a network device based on network traffic - Reconstruct a malicious attack or activity based off network traffic - Identify network mapping and operating system (OS ...

Cyber Defense

New York, NY · Hybrid

$325K - $350K/yr

Managing Director, Cyber Defense - Mizuho Americas The Managing Director, Cyber Defense, is a ... Experience developing and operating a Cyber Fusion Center or similar advanced security operations ...

... operating system (OS) fingerprinting/other baselining activities - Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed ...

... operating system (OS) fingerprinting/other baselining activities - Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed ...

... operating system (OS) fingerprinting/other baselining activities - Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed ...

... operating system (OS) fingerprinting/other baselining activities - Assist in the construction of signatures which can be implemented on cyber defense network tools in response to new or observed ...

next page

Showing results 1-20

Cyber Defense Operator information

See salary details

$34K

$112.9K

$176K

How much do cyber defense operator jobs pay per year?

As of Jun 20, 2026, the average yearly pay for cyber defense operator in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

How much does a cyber defense operator make?

A cyber defense operator's salary typically ranges from $60,000 to $100,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with specialized skills or security clearances can earn higher salaries. The role often requires knowledge of security tools, network protocols, and threat mitigation strategies.

Can you make $500,000 a year in cyber security?

Cyber Defense Operators typically earn salaries below $200,000 annually, with top-tier cybersecurity professionals such as senior analysts or managers reaching higher salaries, especially with specialized skills, certifications, and experience. Achieving a $500,000 annual income in cybersecurity generally requires advanced roles, leadership positions, or consulting work in high-demand environments.

What is the difference between Cyber Defense Operator vs Cyber Security Analyst?

AspectCyber Defense OperatorCyber Security Analyst
CertificationsCompTIA Security+, CEH, CISSP (preferred)CompTIA Security+, CISSP, GIAC certifications
Work EnvironmentOperational security teams, SOCs, incident response centersSecurity teams, risk management departments, consulting firms
Primary FocusMonitoring, detecting, and responding to cyber threats in real-timeAnalyzing security data, assessing vulnerabilities, developing security policies

While both roles focus on cybersecurity, a Cyber Defense Operator primarily handles real-time threat detection and incident response, working within security operations centers. In contrast, a Cyber Security Analyst often focuses on analyzing security data, assessing risks, and developing security strategies. Both roles require similar certifications and work in related environments, but their day-to-day responsibilities differ in scope and focus.

What are the key skills and qualifications needed to thrive as a Cyber Defense Operator, and why are they important?

To thrive as a Cyber Defense Operator, you need expertise in network security, threat analysis, and incident response, often supported by a degree in cybersecurity or computer science and relevant certifications like CompTIA Security+ or CISSP. Familiarity with security information and event management (SIEM) tools, intrusion detection systems (IDS), and malware analysis platforms is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for this role. These skills and qualities are vital for detecting, mitigating, and communicating about cyber threats to protect organizational assets.

What are Cyber Defense Operators?

Cyber Defense Operators are professionals responsible for protecting an organization’s digital infrastructure from cyber threats, such as hacking, malware, and unauthorized access. They monitor network activity, investigate security incidents, and implement measures to prevent cyberattacks. These specialists use various tools and techniques to detect vulnerabilities and respond quickly to security breaches, ensuring the safety and integrity of sensitive information. Cyber Defense Operators often work as part of a larger cybersecurity team and are essential for maintaining robust information security in today’s digital world.

What is a cyber defense operator?

A cyber defense operator is a cybersecurity professional responsible for monitoring, analyzing, and responding to security threats and incidents within an organization's network. They use tools like intrusion detection systems and firewalls, often working in shifts to ensure continuous protection, and typically require knowledge of security protocols and certifications such as CompTIA Security+ or CISSP.

What are some common challenges a Cyber Defense Operator faces when responding to security incidents?

Cyber Defense Operators often navigate challenges such as rapidly evolving threats, incomplete or ambiguous data, and the need to coordinate with multiple teams under time pressure. Responding effectively requires balancing thorough investigation with swift action to contain threats and minimize damage. Clear communication with IT, management, and sometimes external stakeholders is essential, as is the ability to adapt to new attack vectors and technologies. Continual learning and staying updated on the latest threat intelligence are key to success in this dynamic environment.

How much do cyber operators make?

Cyber Defense Operators typically earn between $60,000 and $100,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with specialized skills or security clearances can earn higher salaries. The role often requires knowledge of security tools, network protocols, and threat analysis.
More about Cyber Defense Operator jobs
Infographic showing various Cyber Defense Operator job openings in the United States as of June 2026, with employment types broken down into 56% Full Time, 42% Part Time, 1% Contract, and 1% Nights. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.
Cyber Defense Operator (CDO)

Cyber Defense Operator (CDO)

IPSecure, Inc.

San Antonio, TX

$75K - $95K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Job description

Cyber Defense Operator (CDO) - TS/SCI Level Clearance Required - Located in San Antonio, Texas
Job Description
The ability of the Cyber Defense Operator (CDO) is to complete its mission dependent upon accurate, timely and thorough event analysis in order to identify intruder or potential intruder activities utilizing host and network monitoring and system logs. The CDO shall correlate information gathered to provide effective methods to protect Air Force (AF) systems. Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
Responsibilities
  • When CAT events are escalated to incident response, complete incident response process, including: preparation, identification and scoping, containment, eradication and remediation, recovery, and lessons learned.
  • Upon identification of suspicious activity on AF networks, open network intrusion investigation(s) to validate the unauthorized activity and determine the type and extent of activity.
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‐intelligence agencies and activities if required.
  • Participate and contribute to lessons learned meetings and briefings.
  • Support planned and same‐day Incident Response deployments.
  • Comply with 3rd party MOU/MOA monitoring and reporting requirements. Analyze host DCO events to determine the necessity for higher level analysis and conduct an initial assessment of type and extent of intruder activities.
  • Conduct cyber investigations in order to determine the initial vector and overall timeline of intrusion, accurately identify the threat, determine the full scope of impact, and develop containment and remediation actions for approval.
  • Author and review incident report forms (IRF) for security incidents within JEMS. Ensure the document is accurate and provides the correct amount of technical detail needed. (CDRL A008)
  • Provide AF Office of Special Investigations (OSI) DCO technical support to law enforcement and counter‐intelligence agencies and activities if required.
  • Generate end of mission reports (MISREPS) and provide pass‐on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc. with no more than a 5% error rate.
  • Generate end of mission reports (MISREPS) and provide pass‐on information for knowledge transfer to subsequent /crews of analysts on duty regarding the latest suspicious traffic seen from a given port, Internet Protocol (IP), etc.
  • Provide computer security‐related support to AF field units as directed by CCC, in countering vulnerabilities, minimizing risk, and improving the security posture of AF computers networks and systems within the scope of AFIN SOC operational requirements and mission execution.
  • Participate in planning, briefing, and debriefing tasks as directed by CDO Mission Lead or Crew Commander.
  • Provide feedback on detection mechanisms that are both true and false positive events to ESM and Content Development as applicable.
  • Design incident response plans (IRP) as directed by the Crew Commander. Ensure CDOs are briefed on objectives, ROEs, plans, contingencies, and applicable TTPs.
  • Accomplish assigned weapon system access, ORM, Go/No Go, reports, TTP updates, and TAR submissions.
Basic Qualifications
  • Active TS/SCI Level Clearance.
  • Active IAT Level II Cert (ex: CompTIA Security+)
  • Ability to gain the CSSP Incident Responder Certification (GCFA) Certification requirement within 120-days of hire date.
Preferred Qualifications
  • 3+ years of relevant technical, cyber security, and business work experience
Benefits
Medical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid legal plan and ID protection plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.
EEOC Statement
IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability or status as a protected veteran.