Skip to main content
HonestMOS
InvestigationsHow EUCOM shelved a tax break for 9,000 troops in Poland — for five years.
USAF1D7X1

Cyberspace Defense Operations Specialist

Performs network defense operations to protect Air Force information systems from cyber threats. Conducts vulnerability assessments, incident response, and defensive cyber operations.

No reviews yet
Watch this MOSGet pinged when 1D7X1 — Cyberspace Defense Operations Specialist hits an SRB list, cutoff drop, or BAH change. Free account, anonymous as always.
Recruiter vs. Reality
What they tell you

You'll defend Air Force networks from nation-state hackers — the ones with actual resources and patience who would make most civilian IT threats look like amateur hour. Cyber defense experience with a TS/SCI clearance is one of the most valuable combinations you can build in four years of service. The private sector compensation for cleared defensive cyber specialists has been climbing for a decade and shows no signs of stopping. You'll also be stationed somewhere with a gym that has actual equipment, which is not something you should take for granted.

What it's actually like

Network defense means monitoring for threats in environments where the most interesting events happen at 3 AM and the most common events are false positives and compliance documentation updates. You'll develop genuine expertise in an environment where the adversaries are real — nation-state APT groups running sustained campaigns against DoD infrastructure are not a training exercise. The classified constraint means the most interesting stories from your career are the ones you can never tell. The Cyberspace Operations career community is still figuring out its identity, culture, and promotion patterns as the Air Force works out what cyber means for the service long-term. The civilian market is strong and the transition is well-supported.

First-hand intel neededWrite a Review

Execute the Job — By Rank

How you actually run this job at each rank — what you do, what you drill, which manuals you own, and what good looks like. Written for the soldier, sailor, airman, Marine, or Guardian currently in the seat. Each rank deeplinks into the full Playbook deep-dive: time-blocked schedules, unit-type variations, career decisions, and the read on the next rank.

E1-E3AB — A1C (Apprentice)

You are the newest set of eyes on the network — alert queue cannon fodder who is learning, fast, that most alerts are noise and the one that isn't will not announce itself.

What You Actually Do

You work the SIEM queue. Alerts come in; you triage them, correlate them against known-good baselines, and escalate anything that smells wrong. You run vulnerability scans with ACAS/Nessus under supervision and learn to read the output without panicking about every finding. You pull packet captures, read logs, and slowly build a mental model of what normal traffic looks like on the Air Force Information Network — because that map is the only thing that lets you spot the abnormal. You attend every tech talk, you earn your CompTIA Security+ before the AF deadline, and you shadow incident response actions without yet owning them.

Key Skills to Drill
  • 01SIEM alert triage (Splunk, ArcSight, or mission-equivalent)
  • 02Basic log analysis — Windows Event Log, Syslog, firewall logs
  • 03ACAS/Nessus vulnerability scan execution and output reading
  • 04OSI model and TCP/IP fundamentals at packet level
  • 05STIG checklist application on Windows and Linux endpoints
  • 06CompTIA Security+ and Network+ certification
Manuals & References
  • AFI 17-130, Cybersecurity Program Management
  • DoD 8570.01-M / DoD 8140.01 (baseline certification requirements)
  • NIST SP 800-53 (Security and Privacy Controls)
  • MITRE ATT&CK Enterprise Matrix (foundational TTPs)
Standards You Must Hit
  • Triage and disposition every assigned alert within shift window — no ticket ages out without documentation
  • Achieve DoD 8140 IAT Level II certification (Security+) within required timeline
  • Complete all assigned STIG checklists without supervisor prompting
  • Document actions taken on every incident ticket — if it isn't written, it didn't happen
Common Technical Mistakes
  • Closing an incident ticket after containment without completing root cause analysis — isolating the compromised host and removing the malware is containment, not eradication; the threat actor who phished a valid credential still has that credential and will return through the same vector until you invalidate it and find every system it touched.
What Good Looks Like

A good AB/A1C 1D7 looks like someone who treats alert fatigue as a professional failure, not an inevitability. They build runbooks for the alerts they see repeatedly. They ask why a rule fired, not just whether to escalate. They read one MITRE ATT&CK technique write-up every week. By the time they pin on SrA, they know what normal looks like on their network better than some NCOs, and they have documented proof of every incident they touched.

Go Deeper at E1-E3
Time-blocked daily schedule, unit-type variations, career decisions, full reading list with chapters — written for the soldier in this seat.
Full E1-E3 Playbook →
E4SrA (Journeyman)

You own your lane now. Triage isn't something you watch anymore — you run it, mentor the new ABs, and start doing the threat hunting that the alert queue doesn't show you.

What You Actually Do

You lead incident response actions for low-to-medium severity events from detection through recovery. You write the after-action report and brief the flight chief on what happened, what you did, and what the network looks like now. You run threat hunting missions using MITRE ATT&CK as your playbook — you pick a technique, pull the relevant telemetry, and determine whether you have evidence of it on the network. You manage STIG compliance for a defined system set and track remediation through closure. You mentor ABs on alert triage, log analysis, and the difference between a misconfigured endpoint and an actual intrusion. You start building toward GIAC certifications or CEH — not because the AF mandates it yet, but because the NCOs who advance fast all have them.

Key Skills to Drill
  • 01Incident response lifecycle — detection, containment, eradication, recovery, lessons learned
  • 02Threat hunting using MITRE ATT&CK TTPs against SIEM and EDR telemetry
  • 03Digital forensics basics — disk imaging, chain of custody, Autopsy or equivalent
  • 04Packet analysis with Wireshark — identify C2 beaconing, lateral movement, exfiltration patterns
  • 05Scripting for automation — PowerShell or Python for log parsing and triage acceleration
  • 06Vulnerability management lifecycle — scan, track, remediate, verify closure
Manuals & References
  • NIST SP 800-61 Rev 2, Computer Security Incident Handling Guide
  • AFI 17-130, Cybersecurity Program Management
  • MITRE ATT&CK Navigator — hunt hypothesis documentation
  • CJCSI 6510.01F, Information Assurance and Support to Computer Network Defense
Standards You Must Hit
  • Own low-to-medium severity incident response end-to-end, including written after-action report
  • Complete at least one proactive threat hunt per quarter with documented hypothesis, methodology, and findings
  • Maintain zero unmitigated critical STIGs on assigned system set
  • Mentor at least one AB through first 90-day alert triage qualification
Common Technical Mistakes
  • Treating threat hunting as a SIEM query exercise — real hunting starts with a hypothesis about adversary behavior drawn from intelligence, not from looking for alerts the detection rules already cover. If your hunt only finds what the rules would have found anyway, you haven't hunted anything.
What Good Looks Like

A good SrA 1D7 owns their incidents instead of escalating them reflexively. They write after-action reports that go beyond "we found it and fixed it" to explain the full attack chain and what detection capability gaps it revealed. They have a GIAC cert or a clear plan to earn one. They are the person in the flight who built the Splunk dashboard that saves everyone an hour a shift, and they documented it so the next person can maintain it.

Go Deeper at E4
Time-blocked daily schedule, unit-type variations, career decisions, full reading list with chapters — written for the soldier in this seat.
Full E4 Playbook →
E5SSgt (Craftsman)

You are the technical backbone of the defensive cyber flight — the person who runs complex incidents, trains the junior Airmen, and translates threat intelligence into actionable detection rules.

What You Actually Do

You lead the response to high-severity incidents and coordinate with wing leadership, the Communications Squadron commander, and mission partners when the event warrants it. You write and tune SIEM detection rules based on threat intelligence reporting from 16th Air Force and CYBERCOM — you take a MITRE ATT&CK technique, find the telemetry gap, and build the rule that closes it. You own the vulnerability management program for the unit and brief leadership on risk posture monthly. You conduct digital forensics on compromised systems and preserve evidence in ways that survive legal scrutiny. You develop training plans for junior Airmen and run the flight's 5-level upgrade training. You start preparing yourself for functional management — understanding budget cycles, personnel actions, and what it means to be responsible for people, not just systems.

Key Skills to Drill
  • 01SIEM detection engineering — rule writing, tuning, false-positive reduction
  • 02Malware analysis basics — static and behavioral analysis in sandbox environments
  • 03Threat intelligence integration — translating ISAC feeds and IC reporting into detection content
  • 04Digital forensics and evidence preservation to legal/UCMJ standard
  • 05Vulnerability risk prioritization — CVSS scoring in operational context, not just raw score
  • 06Training program development — writing 5-level upgrade task qualification checklists
Manuals & References
  • AFI 17-101, Risk Management Framework for Air Force Information Technology
  • DoDI 8500.01, Cybersecurity
  • NIST SP 800-137, Information Security Continuous Monitoring
  • MITRE ATT&CK Defender (MAD) detection guidance
Standards You Must Hit
  • Lead all high-severity incident responses and produce executive summary brief within 24 hours of containment
  • Maintain current threat intelligence feed integration — no detection content older than 90 days without review
  • Zero Airmen under your supervision miss DoD 8140 certification milestones
  • Monthly vulnerability posture brief to flight chief with trend analysis, not just raw numbers
Common Technical Mistakes
  • Writing detection rules against indicators (specific IPs, hashes, domains) instead of behaviors — indicators rotate in hours; an adversary who burned one domain has ten more. Rules built on TTPs survive; IOC-based rules are obsolete before the shift ends.
What Good Looks Like

A good SSgt 1D7 has a detection library they built and maintain. When a threat intelligence report drops about a new adversary TTP, they read it the day it arrives and have a hunt or a new rule in the queue by end of week. They brief the flight on what they found. Their Airmen pass upgrade training on schedule because the SSgt treated training as a primary duty, not a paperwork formality. They are the person that the flight chief sends to the hard problem.

Go Deeper at E5
Time-blocked daily schedule, unit-type variations, career decisions, full reading list with chapters — written for the soldier in this seat.
Full E5 Playbook →
E6TSgt (Superintendent)

You run the flight's day-to-day defensive cyber operations — you are the technical authority, the shift supervisor, the trainer of SSgts, and the person who briefs the DO when something important happens on the network.

What You Actually Do

You supervise the defensive cyber flight operations — you ensure the alert queue is staffed, incidents are being worked to standard, and the vulnerability management program is producing meaningful risk reduction, not just compliance checkmarks. You brief the squadron DO and Wing/CC on significant cyber events. You coordinate with 16th Air Force, JFHQ-DODIN, and USCYBERCOM during major incidents. You build and maintain the flight's metrics program — you know your mean time to detect and mean time to respond, and you brief those numbers honestly, including when they are bad. You mentor SSgts on the transition to NCO leadership and you ensure the flight's training program actually prepares Airmen for the mission. You represent the unit at Wing Cybersecurity Working Groups and advocate for the resources — personnel, tools, training — the mission requires.

Key Skills to Drill
  • 01Cyber operations metrics — MTTD, MTTR, detection coverage mapping against ATT&CK
  • 02Cross-functional coordination — working with network ops, system admins, and mission owners during incidents
  • 03Briefing senior leadership — translating technical events into operational and mission risk language
  • 04Flight-level resource management — tool licensing, training budget, personnel assignment advocacy
  • 05Continuity of operations planning for cyber defense capability
  • 06Advanced threat hunting — multi-stage campaign reconstruction across weeks of telemetry
Manuals & References
  • CJCSI 6510.01F, Information Assurance and Support to Computer Network Defense
  • AFI 17-130 Chapter 5, Incident Management
  • NIST SP 800-61 Rev 2, incident response program structure
  • DoD Cyber Strategy (current version) — force posture and defend forward context
Standards You Must Hit
  • Flight maintains documented MTTD and MTTR metrics updated monthly
  • Every significant incident produces a lessons-learned brief that updates detection rules or playbooks
  • All NCOs under supervision have current Individual Development Plans with certification goals
  • Zero compliance-only vulnerability management — every remediation priority justified by actual risk
Common Technical Mistakes
  • Managing to compliance metrics instead of detection effectiveness — a unit that closes 100% of STIG findings and misses a 45-day dwell time intrusion has failed the mission. Teach the flight that the question is always "would we have caught a real adversary this week," not "are our dashboards green."
What Good Looks Like

A good TSgt 1D7 runs a flight where the junior Airmen know why they are doing what they are doing, not just how to do it. The metrics are honest — when MTTD is worse this quarter, they say so and explain the cause. They have personal relationships with the 16th AF and JFHQ-DODIN contacts who matter when a real event happens, because they built those relationships before they needed them. Their SSgts are ready to be TSgts.

Go Deeper at E6
Time-blocked daily schedule, unit-type variations, career decisions, full reading list with chapters — written for the soldier in this seat.
Full E6 Playbook →
E7MSgt / 1stSgt

You are the functional manager and force developer for the cyber defense career field at the unit level — you own the people, the program health, and the pipeline that produces the next generation of 1D7s.

What You Actually Do

As flight chief or senior functional, you oversee the entire defensive cyber operations program — not individual incidents, but the health of the capability itself. You assess whether the unit's detection architecture can actually see the threats the IC says are targeting AF networks. You brief the Group CC and Wing CC on cyber risk posture in terms they act on. You manage EPR rack-and-stack for the flight and ensure the best performers are nominated for schoolhouse tours, advanced training, and the assignments that build their careers. You advocate for the 1D7 career field at the wing level — when the manpower document is wrong, you fix it; when the AFSC is hemorrhaging talent to the private sector, you write the retention analysis that goes up the chain. As 1stSgt, you own the health, morale, and welfare of every Airman in the unit and you run them toward both mission excellence and life stability.

Key Skills to Drill
  • 01Cyber risk communication to non-technical senior leaders
  • 02Manpower and personnel program management for a technical AFSC
  • 03Career field health analysis — retention trends, fill rates, certification pipeline
  • 04Advanced cyber operations program assessment — red team/blue team exercise design
  • 05AETC coordination — schoolhouse feedback loop on training currency vs. mission requirements
  • 06Congressional/IG response preparation for cyber incidents with public visibility
Manuals & References
  • AFI 36-2618, The Enlisted Force Structure (rank responsibilities)
  • AF Cyberspace Operations career field education and training plan (CFETP) for 1D7X1
  • DoD Cyber Workforce Framework (DCWF)
  • HAF/A6 annual cyber workforce reporting requirements
Standards You Must Hit
  • Every Airman in the flight has a documented career vector with a certification and assignment plan
  • Unit cyber capability self-assessment conducted annually with honest findings briefed to Wing CC
  • Retention data tracked and analyzed — every voluntary separation from the career field generates an exit analysis
  • Schoolhouse feedback submitted annually on training gaps between initial skills and mission requirements
Common Technical Mistakes
  • Letting the best technical performers stagnate in the same billet because their technical skills are too valuable to move — the 1D7 who never leaves their home unit becomes the world's best local expert and a career field liability. The mission needs leaders who have seen multiple networks, multiple threat environments, and multiple unit cultures. Move your best people even when it hurts.
What Good Looks Like

A good MSgt 1D7 is the person who can walk into a Wing CC brief and explain in three sentences why the network is more or less defensible than it was six months ago, and what it would take to close the gap. They have Airmen at every base who call them when something goes sideways, because they invested in those relationships when they were TSgts. Their unit has a lower-than-average attrition rate, and when you ask their Airmen why they stayed, they name the MSgt.

Go Deeper at E7
Time-blocked daily schedule, unit-type variations, career decisions, full reading list with chapters — written for the soldier in this seat.
Full E7 Playbook →
E8-E9SMSgt / CMSgt

You are the senior enlisted voice for defensive cyber operations across the Air Force — you shape the career field, set the standards, and ensure the AFSC is producing the defenders the nation needs against the threat that exists now, not the threat from ten years ago.

What You Actually Do

At SMSgt and CMSgt, you operate at command, MAJCOM, AFSC, or joint staff level. You advise commanders on cyber workforce posture across entire commands — not individual units. You shape the 1D7 CFETP and initial skills training at Keesler AFB, ensuring the schoolhouse produces Airmen who can defend a network the day they arrive at their first unit rather than spending two years catching up. You represent the 1D7 career field in joint forums — USCYBERCOM, JFHQ-DODIN, NSA/CSS — and you ensure Air Force defensive cyber equities are understood and resourced in joint planning. You advise the HAF/A6 and MAJCOM/A6 on manning requirements, tooling investments, and whether the force structure matches the threat. CMSgts in this AFSC often serve as the senior enlisted advisor for entire cyber wings or numbered air forces, and many serve at NSA/CSS as senior civilian or enlisted leaders in national-level cyber defense operations.

Key Skills to Drill
  • 01AFSC-level career field management — CFETP revision, training pipeline oversight, fill rate strategy
  • 02Joint cyber operations — USCYBERCOM, JFHQ-DODIN, NSA/CSS coordination and representation
  • 03Senior leader cyber risk advising — translating operational cyber risk to resourcing decisions
  • 04Congressional and OSD engagement on cyber workforce legislation and policy
  • 05Cyber exercise program design at MAJCOM and joint command level
  • 06Retention and accession program design for a technically competitive career field
Manuals & References
  • National Cyber Strategy (current) — workforce and defense priorities
  • DoD Cyber Strategy and Implementation Plan
  • AF Cyberspace Superiority (AFDD 3-12 successor documents)
  • HAF/A6 Cyberspace Operations Division program guidance
  • USCYBERCOM Campaign Plan — defended asset list and priority network defense requirements
Standards You Must Hit
  • CFETP reviewed and updated on minimum 2-year cycle with schoolhouse, major commands, and CYBERCOM input
  • Career field fill rate, retention rate, and certification attainment briefed to CSAF/CMSAF chain annually
  • Joint cyber workforce interoperability maintained — 1D7 Airmen can integrate into CYBERCOM and NSA billets on day one
  • Honest career field health assessment — if the AFSC is losing to the private sector, the senior enlisted say so loudly and publicly
Common Technical Mistakes
  • Letting the career field define its own success by compliance measures because compliance is easy to count — if the 1D7 community can recite every STIG and still miss a nation-state intrusion that lived on AF networks for six months, the training pipeline and the performance standards failed. The measure is whether adversaries find AF networks hard. Everything else is supporting evidence.
What Good Looks Like

A CMSgt 1D7 who did it right leaves a career field that is harder to hollow out after they retire. The schoolhouse produces Airmen who can hunt. The retention rate ticked up because the senior enlisted fought for the authorities and the pay supplements that made staying rational. The joint partners trust the 1D7s who show up in their billets. And somewhere, a TSgt who was a struggling A1C eight years ago is running a flight because the CMSgt saw something in them and refused to let them leave the Air Force.

Go Deeper at E8-E9
Time-blocked daily schedule, unit-type variations, career decisions, full reading list with chapters — written for the soldier in this seat.
Full E8-E9 Playbook →
On the Outside

What this actually is in the real world

Your skills translate. Here's what civilian employers call this job — and what they pay.

Information Security Analysts

Strong match
$120,360$75,100$187,490/yr median
Job market: Much faster than average (33%)

Network and Computer Systems Administrators

Strong match
$95,360$58,050$158,970/yr median
Job market: Average (3%)

Computer and Information Systems Managers

Related field
$169,510$109,820$239,200/yr median
Job market: Much faster than average (15%)

Salary data from the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics program, retrieved Feb 2026. BLS.gov cannot vouch for the data or analyses derived from these data after the data have been retrieved from BLS.gov.

MOS Pulse

Anonymous · One tap · No account

Three seconds of your time, zero of your identity. This is how the honest picture of 1D7X1 gets built — one tap at a time.

Knowing what you know now — would you pick 1D7X1 again?

Did your recruiter describe this job accurately?

Hours per week this job actually takes in garrison?

That tap took 3 seconds. A full review takes 10 minutes — and does about 100x more for the next person staring at this contract.

Write the Full Review →
Reviews
Founding ReviewUnclaimed

Nobody’s gone first. Yet.

Zero reviews for 1D7X1. Not because nobody has opinions — anyone who’s actually done Cyberspace Defense Operations Specialist is carrying a full magazine of them — but because nobody’s put theirs on the record.

So here’s the deal: the first approved review of every MOS becomes its Founding Review. Permanently badged, permanently first. Every person who looks up 1D7X1 from now on reads it before anything else — including the recruiter’s version.

We could fill this page with fake reviews tonight. Plenty of sites do. We never will — which means this space stays exactly this empty until someone who lived it goes first.

Sign Up & Claim ItFree account · takes two minutes

Anonymous by default — no name, no unit, fuzzy timestamps. Your chain of command never knows it was you.

FAQ

1D7X1 Cyberspace Defense Operations Specialist — FAQ

Q01What does a 1D7X1 do in the Air Force?
You work the SIEM queue.
Q02How long is 1D7X1 training and where is it held?
1D7X1 training is approximately 16 weeks of Advanced Individual Training (AIT) after Basic Combat Training, held at Keesler AFB, MS.
Q03What does a day in the life of a 1D7X1 look like?
A typical junior-enlisted 1D7X1 day: 0530 PT, accountability, and the first reminder that cyber Airmen still belong to the Air Force, 0700 Hygiene, chow, commute, and a quick scan of messages for schedule changes, overnight incidents, and anything the section chief or watch supervisor needs before first formation, 0800 Cyber squadron admin and shift turnover. You read the log before you talk,…
Q04What are the most common career-ending mistakes for a 1D7X1?
Letting Sec+ lapse. Recertification required every 3 years (or via CEUs); a lapsed Sec+ removes you from DoD 8140-compliant billets; Clearance behaviors at junior airman tier: financial irresponsibility, undisclosed foreign contacts, drug use, security-incident reports — clearance issues at E-3/E-4 follow you for the entire career and the cyber post-service market depends entirely on the clearance; DUI / drug pop — separation under DAFMAN 36-3211 (Administrative Separations),…
Q05What civilian jobs does 1D7X1 translate to?
1D7X1 maps most directly to civilian occupations including Information Security Analysts, Network and Computer Systems Administrators. Translation quality varies by skill — see the Honest MOS Civilian Translation block for full O*NET matches and salary data.
Q06What's the career progression for a 1D7X1?
BMT at Lackland (~8.5 weeks); Tech school at Keesler AFB (81st Training Wing) — ~6 months for 1D7X1, varies by shred (verify current course catalog); CompTIA Security+ certification — DoD 8140 baseline
Q07What's the recruiter not telling me about 1D7X1?
Network defense means monitoring for threats in environments where the most interesting events happen at 3 AM and the most common events are false positives and compliance documentation updates.
How does 1D7X1 compare?
See side-by-side ratings, quality of life, and community takes.
Published by the Honest MOS Editorial DeskVerified against DoD/.gov sourcesUpdated May 2026Editorial standards

Sources:Branch MOS catalog · DTMO pay tables · DoD/.gov benefits references · O*NET civilian career mapping · verified service-member reviews