DCO Watch Analyst Tier III Forensics Stuttgart

Vor 6 Tagen


Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 60.000 € - 90.000 € pro Jahr

Cyber Security Analyst III, DCO Watch Analyst Tier III Forensics

Stuttgart, Germany

Secret Clearance, with ability to obtain TS/SCI

As a Tier 3 Defensive Cyber Operations (DCO) Watch Analyst you will be responsible for leading complex incident responses, conducting proactive threat hunting, and enhancing detection capabilities within a Cybersecurity Service Provider (CSSP) environment. You will oversee incident analysis, coordinate with external entities, and drive purple team activities to strengthen security posture. This role requires advanced expertise and compliance with CJCSM B.

Position Requirements and Duties

  • Examine system, software, security, and user hives for evidence of program execution, USB usage, network connections, and user activity
  • Execute forensic imaging of computers and storage media
    • Acquire and analyze digital evidence using industry-standard forensic tools and techniques on Windows and Linux systems including prefetch, jump lists, shellbags, and other operating system specific artifacts.
  • Acquire and analyze memory captures to recover additional artifacts and evidence.
  • Decode and interpret various file formats and digital communications
  • In-depth understanding of digital forensic methodologies, incident response workflows, and forensic tools
  • Lead incident response efforts, including analysis, mitigation, and reporting of significant incidents per CJCSM B
  • Manage incident response campaigns by developing strategies, coordinating multi-team efforts, and ensuring comprehensive resolution and reporting
  • Conduct proactive threat hunting to identify advanced threats and vulnerabilities within the network
  • Lead purple team exercises to evaluate and enhance detection and response capabilities in collaboration with red and blue teams
  • Evaluate and refine detection mechanisms, including IDS/IPS signatures and log correlation rules, to improve accuracy and reduce false positives
  • Perform advanced network and host-based digital forensics on Windows and other operating systems to support incident investigations
  • Coordinate with reporting agencies and subscriber sites to ensure comprehensive analysis and reporting of significant incidents
  • Develop and maintain internal SOP documentation, ensuring alignment with CJCSM B and other directives
  • Provide 24/7 support for incident response during non-core hours, and mentor junior analysts
  • Lead program reviews, product evaluations, and onsite certification evaluations
  • Overtime may be required to support incident response actions (Surge).
  • Operations are conducted 24/7/365 across three regional operation centers (ROC)
  • Each ROC works four ten-hour shifts (Sunday-Wednesday or Wednesday-Saturday)
  • Shift placement is at the discretion of assigned managers

Minimum Qualifications

  • Bachelor's Degree in relevant discipline and 5 years or at least 8 years of experience working in a CSSP, SOC, or similar environment
  • 2+ years of experience performing tactical forensics duties
  • Must be a U.S. Citizen

Desired Qualifications

  • Experience and expertise in incident response forensic activities
  • Proficient programming skills in a common language such as PowerShell, Python, Golang, Rust or C/C++
  • Forensic focused certification such as GCFA, GCFE, etc.
  • Comprehensive knowledge of CJCSM B
  • Deep expertise in IDS/IPS solutions, including signature development and optimization
  • Extensive experience with Digital Forensics across multiple operating systems
  • Demonstrated expert-level knowledge of Incident Response Procedures
  • Advanced proficiency with host-based tools and operating system logging
  • Expertise in log aggregation tools (e.g., Splunk, Elastic, Sentinel) for complex correlation analysis
  • Exceptional logical thinking and analytical ability
  • Superior verbal and written communication skills
  • Proven ability to solve complex problems independently

Required Certifications

  • Must have requisite certifications to fulfill DoD 8570 IAT Level II and CSSP-specific requirements

Company Overview

Adapt Forward is a cybersecurity solutions provider for some of the nation's most valuable information systems. Leveraging advanced threat assessment technology and experience in building high-level information security infrastructure, we develop adaptive solutions uniquely tailored to our customers' business objectives to protect sensitive data against sophisticated threats in an increasingly complex security environment.

Summary of Benefits

  • Comprehensive Physical Wellness Package, including Medical, Dental, Vision Care, plus Flexible Spending Accounts for health- and dependent-care are included in our standard benefits plan.
  • 401k Retirement Plan with Matching Contribution is immediately available and vested.
  • Annual Training Budget to be used for conference attendance, school enrollment, certification programs, and associated travel expenses.
  • Eleven Federal Holidays, plus three weeks of PTO/vacation/sick leave that accrues at a rate of ten hours per month.
  • Employee Assistance Program: Counseling/legal assistance and other employee well-being programs are also offered.

Equal opportunity employer as to all protected groups, including protected veterans and individuals with disabilities.

Adapt Forward's Veteran/Disability Affirmative Action Plan narrative section is available for inspection upon request during normal business hours at the Human Resources office and may be requested by contacting Human Resources at

pArx8H6oP8



  • Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 60.000 € - 90.000 € pro Jahr

    Cyber Security Analyst III, DCO Watch Analyst Tier III Forensics Stuttgart, Germany Secret Clearance, with ability to obtain TS/SCI As a Tier 3 Defensive Cyber Operations (DCO) Watch Analyst you will be responsible for leading complex incident responses, conducting proactive threat hunting, and enhancing detection capabilities within a Cybersecurity...


  • Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 75.000 € - 95.000 € pro Jahr

    Cyber Security Analyst III, DCO Watch Analyst Tier 3 MalwareStuttgart, GermanySecret Clearance, with ability to obtain TS/SCI Position DescriptionThe Tier 3 Defensive Cyber Operations (DCO) Watch Analyst is a senior-level role responsible for leading complex incident response, conducting proactive threat hunting, and enhancing detection capabilities within...


  • Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 60.000 € - 120.000 € pro Jahr

    Cyber Security Analyst I, DCO Watch Analyst Tier II Stuttgart, DESecret Required to Start, TS SCI Required The Tier 2 Defensive Cyber Operations (DCO) Watch Analyst is an intermediate role responsible for analyzing and responding to security incidents within a Cybersecurity Service Provider (CSSP) environment. You will  investigate validated events,...


  • Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 700.000 € - 1.300.000 € pro Jahr

    Cyber Security Analyst I, DCO Watch Analyst Tier IIStuttgart, DESecret Required to Start, TS SCI Required The Tier 2 Defensive Cyber Operations (DCO) Watch Analyst is an intermediate role responsible for analyzing and responding to security incidents within a Cybersecurity Service Provider (CSSP) environment. You will investigate validated events,...


  • Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 60.000 € - 80.000 € pro Jahr

    DCO Watch Analyst Tier II Stuttgart, DESecret Required to Start, TS SCI Required The Tier 2 Defensive Cyber Operations (DCO) Watch Analyst is an intermediate role responsible for analyzing and responding to security incidents within a Cybersecurity Service Provider (CSSP) environment. You will  investigate validated events, coordinates with stakeholders,...


  • Stuttgart, Baden-Württemberg, Deutschland Adapt Forward Vollzeit 80.000 € - 120.000 € pro Jahr

    Cyber Security Analyst III, DCO Watch Analyst Tier 3 Malware Stuttgart, Germany Secret Clearance, with ability to obtain TS/SCI Position DescriptionThe Tier 3 Defensive Cyber Operations (DCO) Watch Analyst is a senior-level role responsible for leading complex incident response, conducting proactive threat hunting, and enhancing detection capabilities...

  • Cybersecurity Analyst

    vor 2 Wochen


    Stuttgart, Baden-Württemberg, Deutschland 3 Reasons Consulting, LLC Vollzeit 45.000 € - 80.000 € pro Jahr

    Cybersecurity Analyst – Operations Watch AnalystLocation: Stuttgart, GermanyClearance Level: Minimum Secret (TS/SCI eligibility required)Summary:3 Reasons Consulting is seeking a skilled Cybersecurity Analyst – Operations Watch Analyst to join our cybersecurity operations team in Stuttgart, Germany. This position is responsible for isolating,...


  • Stuttgart, Baden-Württemberg, Deutschland Bucherer AG Vollzeit 60.000 € - 80.000 € pro Jahr

    Bucherer Deutschland GmbH eröffnet im April 2026 seinen neuen Store in Stuttgart – ein weiterer Meilenstein auf unserem Expansionskurs in Deutschland. Mit einem einzigartigen Portfolio aus renommierten Uhrenmarken und unserer exklusiven Schmucklinie Bucherer Fine Jewellery bieten wir unseren Kund:innen ein unvergleichliches Luxuserlebnis.Für unseren...

  • Data Analyst

    Vor 4 Tagen


    Stuttgart, Baden-Württemberg, Deutschland Arsenault Vollzeit 40.000 € - 80.000 € pro Jahr

    I'm hiring a 100% Remote Data Analyst for an InsurTech SaaS. Offices in Stuttgart but can work remotely from Germany. Good to have: 1-2 years of professional experience as a Data Analyst or in a comparable position Good analytical skills and a solution-oriented approach Passioned to work into a business model and insurance sector Expertise in the use of BI...


  • Stuttgart, Baden-Württemberg, Deutschland GLADTOBE Vollzeit 40.000 € - 80.000 € pro Jahr

    Praktikant/Werkstudent Data Analyst – Media (m/w/d)Befähige Marken, ihr volles Potenzial zu entfalten. Werde Teil unseres Teams als leidenschaftlicher Data Analyst Media (Praktikant/Werkstudent) und mache einen echten Unterschied.Über GLADTOBEGLADTOBE ist eine innovative und schnell wachsende Medienagentur mit Sitz in Stuttgart und Berlin und globaler...