The Cyber Defense & Vulnerability Operations Analyst supports Navy ERP through continuous security monitoring, alert analysis, and enterprise vulnerability management. This role investigates and responds to indicators of compromise across databases, operating systems, and middleware. The specialist oversees required scanning, tracks compliance, and submits data to DoD repositories, including VRAM and CMRS. They also lead remediation meetings with database, application, and infrastructure subject matter experts to address identified vulnerabilities.
Responsibilities:
The following reflects management’s definition of essential functions for this job but does not restrict the tasks that may be assigned.
Security Operations & Alert Monitoring:
Monitor real-time security alerts from Splunk, Tripwire, and HBSS in accordance with SOPs.
Triage, analyze, and escalate suspicious events, anomalous behaviors, and security incidents.
Conduct deep-dive activity monitoring across core Navy ERP architecture:
Databases: SAP HANA, Oracle, and Sybase.
Operating Systems: Windows Server and Linux host activities.
Applications & Middleware: Tripwire, webMethods, IBM Tivoli, and integration layers.
SIEM Content & Correlation Rule Engineering:
Develop, refine, and optimize correlation searches within Splunk Enterprise Security.
Tune detection logic to eliminate false positives and enhance detection fidelity.
Design custom Splunk dashboards, scheduled alerts, and compliance tracking metrics.
Define data requirements and logging standards for new inbound data sources.
Vulnerability Scanning & Asset Coverage:
Schedule, execute, and validate weekly and ad-hoc ACAS (Tenable) vulnerability scans.
Schedule, execute, and review weekly and ad-hoc Onapsis scans across SAP instances.
Ensure 100% of Navy ERP assets receive required policy scans.
Monitor HBSS/ESS agent coverage across all endpoints; coordinate with NAWC-AD data center HBSS admins.
Compliance Reporting & DoD Systems of Record:
Export verified ACAS scan results and upload directly into VRAM.
Consolidate vulnerability data and HBSS status metrics for regular submission into CMRS.
Generate and distribute detailed vulnerability assessment reports to technical SMEs.
Cross-Team Collaboration & Stakeholder Reviews:
Lead or back up weekly vulnerability review meetings with system, database, and platform SMEs.
Track remediation milestones and validate post-remediation re-scans.
Documentation & Governance:
Maintain and update threat response playbooks, scanning schedules, and operational SOPs.
Qualifications:
Required Qualifications
Experience: 4+ years in SOC analysis, cyber defense, or vulnerability assessment within DoD/Navy environments.
DoD HBSS/ESS (Trellix ePO, agent verification, module status).
Compliance Systems: Direct experience uploading and tracking vulnerability data in VRAM and CMRS.
Technical Breadth: Foundational understanding of enterprise databases (SAP HANA, Oracle) and OS security.
Certifications:
DoD 8570/8140 CSSP Analyst or IAT II/III baseline (e.g., CySA+, CEH, CASP+ CE, CISSP).
Preferred Qualifications
Splunk Certified Cybersecurity Defense Analyst or Splunk Core Certified Advanced Power User.
DISA HBSS 201/301 Administrator training or Tenable ACAS certification.
Prior experience coordinating with NAWC-AD or Navy program office cyber teams.
Physical Requirements: The ideal candidate must at a minimum be able to meet the following physical requirements of the job with or without a reasonable accommodation:
Ability to perform repetitive motions with the hands, wrists, and fingers.
Ability to engage in and follow audible communications in emergency situations.
Ability to sit for prolonged periods at a desk and working on a computer.
Numbers & Facts
Location
Charleston, South Carolina
Skills
Analysis Skillsunmatched
CISSP - Certified Information Systems Security Professionalunmatched
Computer Securityunmatched
Database Programming Languagesunmatched
Defense Information Systems Agency (DISA)unmatched
DoD Directive 8140unmatched
DoD Directive 8570unmatched
ERP (Enterprise Resource Planning)unmatched
Enterprise Protectionunmatched
IAT - Information Assurance Technicalunmatched
IBM Tivoliunmatched
Internet Securityunmatched
Linux Operating Systemunmatched
Machine Toolunmatched
Maintain Complianceunmatched
Metricsunmatched
Microsoft Windows Operating Systemunmatched
Middlewareunmatched
Nessusunmatched
Network Operations Centerunmatched
Operating Systemsunmatched
Operational Auditunmatched
Operational Supportunmatched
Oracleunmatched
Physical Demandsunmatched
Reporting Dashboardsunmatched
Requirements Managementunmatched
SAPunmatched
Search Engine Optimization (SEO)unmatched
Security Analysisunmatched
Security Information and Event Management (SIEM)unmatched
Security Monitoringunmatched
Splunkunmatched
Standard Operating Procedures (SOP)unmatched
Sybase Product Familyunmatched
Time Trackingunmatched
United States Department of Defense (DoD)unmatched
VRAMunmatched
Vulnerability Scannersunmatched
webMethodsunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.