1

Defensive Cyber Operations Jobs (NOW HIRING)

ORA_ON_SITE Description SAIC is seeking a Defensive Cyber Operations Analyst to support the Portsmouth Naval Shipyard (PNSY) Information Technology Programs for the Dept of the Navy. This initiative ...

ORA_ON_SITE Description SAIC is seeking a Senior Defensive Cyber Operations Analyst to support the Portsmouth Naval Shipyard (PNSY) Information Technology Programs for the Dept of the Navy. This ...

Creating game-changing capabilities for defensive cyberspace operations As an interdisciplinary group, we innovate by drawing insights from computer science, software engineering, data engineering ...

next page

Showing results 1-20

Defensive Cyber Operations information

See salary details

$38.5K

$58.2K

$87K

How much do defensive cyber operations jobs pay per year?

As of Jul 25, 2026, the average yearly pay for defensive cyber operations in the United States is $58,171.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $64,500.00 per year, depending on experience, location, and employer.

Can you make $500,000 a year in cyber security?

In defensive cyber operations, reaching a salary of $500,000 annually is uncommon but possible for senior roles such as Chief Information Security Officer (CISO) or cybersecurity executive with extensive experience, advanced certifications, and leadership responsibilities. Most cybersecurity professionals earn lower salaries, but high-level executives with strategic oversight and specialized skills can achieve this level of compensation, often including bonuses and stock options.

What are Defensive Cyber Operations?

Defensive Cyber Operations (DCO) refer to activities and strategies designed to protect computer networks, systems, and data from unauthorized access, attacks, and other cyber threats. These operations involve monitoring, detecting, analyzing, and responding to cyber incidents to ensure the security and integrity of information systems. Professionals in this field implement security measures, conduct risk assessments, and develop incident response plans to minimize damage from potential cyberattacks. DCO is essential for government, military, and private sector organizations to safeguard critical infrastructure and sensitive data.

What are the defensive operations of cyber security?

Defensive cyber operations involve protecting computer systems and networks from cyber threats through activities such as monitoring for intrusions, implementing firewalls and intrusion detection systems, applying security patches, and conducting vulnerability assessments. Cybersecurity professionals in this field use tools like SIEMs and threat intelligence to identify and mitigate risks proactively.

What are the key skills and qualifications needed to thrive in Defensive Cyber Operations, and why are they important?

To thrive in Defensive Cyber Operations, you need a solid grounding in network security, threat analysis, and incident response, often backed by a degree in cybersecurity or related fields. Familiarity with security information and event management (SIEM) tools, intrusion detection/prevention systems, and certifications like CompTIA Security+ or CISSP are typically required. Strong problem-solving skills, attention to detail, and effective communication help professionals excel when mitigating threats and collaborating with teams. These skills and qualifications are crucial for proactively defending organizational assets and ensuring robust cyber resilience.

What is the difference between Defensive Cyber Operations vs Cybersecurity Analyst?

AspectDefensive Cyber OperationsCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, CISSP, CEH
Work EnvironmentMilitary, government, or specialized security teamsCorporate, government, or consulting firms
Primary FocusProactive defense, threat hunting, incident responseMonitoring, analyzing, and responding to security threats
Industry UsagePrimarily in government and military sectorsWidely in private and public sectors

Defensive Cyber Operations and Cybersecurity Analysts share similar certifications and work environments, but Defensive Cyber Operations focus more on proactive defense and threat hunting within specialized teams, often in government or military settings. Cybersecurity Analysts typically monitor and respond to threats across various industries, emphasizing analysis and incident response.

What are some typical challenges faced by professionals in Defensive Cyber Operations, and how can new team members prepare for them?

Professionals in Defensive Cyber Operations often encounter challenges such as rapidly evolving threats, high-pressure incident response situations, and the need to coordinate across multiple departments. New team members can prepare by staying current with the latest threat intelligence, practicing effective communication skills, and familiarizing themselves with the organization's security tools and protocols. Building strong relationships with IT, legal, and management teams also helps ensure smooth collaboration during security events.

What do cyber defense operations do?

Cyber defense operations involve monitoring, analyzing, and responding to security threats to protect computer networks and systems. Professionals in this field use tools like intrusion detection systems and firewalls, and often hold certifications such as CISSP or CEH to identify and mitigate cyber attacks effectively.

How much does a cyber defense operator make?

A cyber defense operator typically earns between $60,000 and $100,000 annually, depending on experience, certifications, and location. Entry-level positions may start lower, while experienced professionals with specialized skills or security clearances can earn higher salaries. The role often requires knowledge of security tools, network protocols, and threat mitigation strategies.
More about Defensive Cyber Operations jobs
What cities are hiring for Defensive Cyber Operations jobs? Cities with the most Defensive Cyber Operations job openings:
Infographic showing various Defensive Cyber Operations job openings in the United States as of July 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $58,171 per year, or $28 per hour.
Defensive Cyber Operations SME

Defensive Cyber Operations SME

Tyto Athene, LLC

Colorado Springs, CO • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Job description

Description

Tyto Athene is searching for a Defensive Cyber Operations (DCO) SME to support the United States Space Force (USSF).  The DCO SME supports support development, improve proficiency, and increase operational effectiveness of USSF Cyber Squadron personnel by providing/ employing DCO capabilities, conducting intrusion detection monitoring and analysis, identifying malicious cyber activity and determining attack vectors, executing cyber response activities, developing defensive countermeasures, and providing Subject Matter Expertise to the United States Space Force Cyber Guardians.

Responsibilities:

  • Develop operational and technical materials to aid in increasing proficiency of the crews
  • Provide cyber defense remediation and mitigation implementation recommendations in support of all incidents/events
  • Provide support for all Operational Planning Teams (OPTs) and crew shift planning processes. Support includes participating in the planning process, recommending course of action (COAs), and validating the technical approach to meet mission objectives
  • Draft and validate accuracy of squadron level DCO Tactics, Techniques, and Procedures (TTPs); Standard Operating Procedures (SOPs); Operational Instructions (OIs); as well as DCO Crew operations products, evaluation and material, and other related materials
  • Conduct analysis on new DCO-Space capability releases to assess new functionality and inform employment for mission execution
  • Attend meetings, teleconferences, and Video Teleconferences (VTCs) at the Unclassified, Secret, and TS/SCI level (as required)
  • Provide recommendations for exercises and mission rehearsals
  • Maintain proficiency by performing DCO crew operation for assigned space mission systems
  • Provide expertise for DCO-Space capabilities, to include Security Incident and Event Management (SIEM); Intrusion Detection and Prevention Systems; ELK (Elasticsearch, Logstash, and Kibana) Stack; Endpoint Protection Systems; Security Orchestration, Automation and Response (SOAR); Firewalls; Log Aggregator; Protocol Analyzers; Vulnerability Assessment Tools
  • Augment and advise the crews performing intrusion detection monitoring and analysis
  • Provide input and review Cyber 9-Line; and review accuracy of cyber incident inputs for SITREP and MISREP
  • Advise and assist with cyber incident response processes IAW squadron policies and procedures, to include:
  • Assist in providing in-depth analysis of incidents by determining the incident's nature, formulating recommended response actions, correlating event and incident data across assigned space mission systems, determining actions to be taken, and assessing possible effects on assigned mission systems
  • Participate in Government-established Cyber Incident Response Teams (CIRTs) and provide technical assistance in determining the cyber events/incident's nature and impact to space mission systems; develop and recommend mitigation and/or remediation COAs; ensure mission system owners/operators and leadership have situational awareness of active response activities via recurring status reports and/or update briefs
  • Provide technical expertise in the creation of recommendation of Courses of Action (COA) along with suggested timing and sequencing of actions to mitigate and/or remediate cyber threats to space mission systems
  • Participate in post-incident hot washes and lessons learned processes as required by the Government
  • Recommend cyber incident response best practices to improve TTPs, processes, and policies
  • Provide recommendations on how to best optimize DCO-Space capabilities, to include countermeasure development (i.e., signatures, rules, policies, etc.) for defensive sensors and capabilities deployed on space mission system networks and endpoints to eliminate false positives; prioritize actionable alerts; and to provide enhanced correlation accuracy for cyber incidents, events, trends, and behaviors
  • Assist and support CYS Government personnel on how to identify, document, and track normal baseline activity for assigned space mission systems by monitoring, collecting, and analyzing space mission system data traffic; and reviewing, auditing, and analyzing network and endpoint logs
  • Assist and support CYS Government personnel on performing Mission Relevant Terrain - Cyber (MRT-C) identification and mapping, leveraging Functional Mission Analysis - Cyber (FMA-C) concepts for assigned space mission systems
  • Assist and support CYS Government personnel on how to conduct cyber missions, to include Survey, Recon, Escort, Hunt, Strike, Recover and others on assigned space mission systems to detect, track, and disrupt Advanced Persistent Threats (APTs) that evade existing cybersecurity controls and detection capabilities
  • Provide inputs to post-mission analysis process for Cyber missions as required by the Government
  • Recommend cyber mission best practices to improve TTPs, processes, and policies
Qualifications

Required:

  • Minimum of one (1) active DoD 8570.07-M Cyber Security Services Provider (CSSP) "Analyst" or "Incident Responder" certifications: 
  • CEH, CySA+, GCIH, GCIA, CFR, CCNA Cyber Ops, CCNA-Security, GICSP, Cloud+, SCYBER, PenTest+, CHFI or GCFA
  • Six (6) years of Cyber Security Analyst work experience (or equivalent).
  • Experience includes Cybersecurity Monitoring; Cybersecurity Analyst; Intrusion Detection and/or Cyber Incident Response.
  • Experience performing Continuous Cybersecurity Monitoring, Intrusion Detection and Cyber Incident Response.
  • Experience with the following tools:
  • ELK Stack, Kibana, Suricata, Splunk, Snort, Wireshark, Bro/Zeek logs, tcpdump, editcap, LogRhythm, ePo/HBSS, ACAS, SolarWinds, Microsoft Office 365, Active Directory WMIC commands.
  • Cybersecurity Service Provider (CSSP) experience is preferred.

Desired:

  • Eight (8)+ years of relevant cybersecurity experience
  • IAT Level III Certification required IAW DoD 8570.07-M. Qualifying certifications include: CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP
  • Familiarity with Space Operations is highly desired

Clearance:

  • Active DoD TS/SCI clearance

Location:

  • Schriever Space Force Base (SFB), CO

Schedule: 

  • Mon-Fri, day shift
About Tyto Athene

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $115,000-$130,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  • Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.
Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains-Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT-empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly support Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide.  At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto?  Tyto Athene, LLC is an Equal Opportunity Employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, [sexual orientation, gender identity,] national origin, disability, status as a protected veteran, or any characteristic protected by applicable law.Employment Type: FULL_TIME