HomeSearch › Job

Test Event Cyber Security Lead (Secret)

Aegis Aerospace Inc.

Colorado Springs, CO, US · lead

Job at a glance

Colorado Springs, CO, US
Location
Lead
Seniority
Aegis Aerospace Inc.
Employer

Test Event Cyber Security Lead (Secret) Test Event Cybersecurity Lead Location: Schriever Space Force Base, Colorado Springs, CO Relocation Assistance: None available at this time Remote/Telework: No – Onsite support required Citizenship Requirement: U.S. citizenship required Clearance Required: Active DoD Secret security clearance Work Schedule: Full-Time, Day Shift Travel: Up to 10% Position Summary Aegis Aerospace is seeking a Test Event Cybersecurity Lead to support the Missile Defense Agency (MDA) on the Integrated Research and Development for Enterprise Solutions (IRES) contract at Schriever Space Force Base in Colorado Springs, Colorado.

The Test Event Cybersecurity Lead manages engineers and Information System Security Officers (ISSOs) responsible for defensive cyber operations, vulnerability lifecycle management, and security-posture monitoring across mission environments. This position is responsible for the overall cybersecurity and operational health of test-event packages. The lead assigns work, establishes team goals and priorities, oversees vulnerability scanning through Assured Compliance Assessment Solution (ACAS), manages endpoint-protection activities, and ensures compliance with Department of Defense Risk Management Framework (RMF) requirements.

Primary Responsibilities Architect and manage cybersecurity processes and oversee the development of operational monitoring dashboards. Assist with complex, query-based threat hunting across centralized log repositories. Develop and manage the scheduling and execution of credentialed ACAS vulnerability scans. Correlate vulnerability-scan findings, track remediation timelines, and generate technical remediation tickets.

Implement, verify, and document Defense Information Systems Agency Security Technical Implementation Guides (DISA STIGs). Manage system configurations and enforce Ports, Protocols, and Services Management (PPSM) baselines. Support continuous monitoring and authorization packages throughout the DoD RMF lifecycle in accordance with NIST SP 800-37 and NIST SP 800-53. Triage and contain operational security anomalies, conduct preliminary root-cause forensic analysis, and support defensive cybersecurity reporting.

Oversee engineers using Python, PowerShell, or Bash to automate administrative tasks, parse security logs, and streamline vulnerability-scan analysis. Oversee engineers working with the ELK Stack—Elasticsearch, Logstash, and Kibana—or equivalent centralized log-aggregation platforms. Oversee engineers supporting VMware vSphere and ESXi virtualized infrastructures and automated configuration management using Ansible.

Oversee firewall-rule management, network access control lists, and network-traffic analysis. Respond rapidly to high-priority cybersecurity alerts outside standard operating hours while participating in an on-call rotation. Coordinate directly with system administrators, ISSMs, and network engineers to validate patches and mitigate identified vulnerabilities. Maintain audit readiness for Command Cyber Readiness Inspections and external cybersecurity assessments.

Schedule and manage a team of engineers supporting test events, including support outside core operating hours. Respond to and triage Cyber Tasking Orders applicable to assigned and managed packages. Minimum Qualifications Must be a U.S. Citizen. Must have an active DoD Secret security clearance or higher. Six or more years of general full-time work experience. This requirement may be reduced based on the completion of advanced education.

Four or more years of directly related professional experience. Six or more months of experience in a management or leadership role. Demonstrated hands-on experience with a Security Information and Event Management platform, including managing data ingestion, developing security-monitoring dashboards, and performing query-based analysis of security events. Experience with an Endpoint Detection and Response or Endpoint Protection Platform so

Search all live jobs — free, no account →