Twenty four people, and the machines they are required to build.
Governments are routinely sold tools and left to find the people. This design starts from the other end, and specifies both: the expertise each operator must hold, and the system they must build so that expertise covers a country rather than a building.
- A specialist who writes reports scales with their own hours. A specialist who writes systems scales with the fleet those systems run on. Every role below carries a build mandate for that reason.
- Twenty four is an output, not a target. It is what remains after removing every role whose absence would leave a layer of the national estate with no owner.
- The twenty four cannot hold a watch floor, and should never be asked to. They are a nucleus above an operations tier and a retained surge tier.
Three tiers, and what each is for
The most common failure in national cyber programs is to hire excellent people and then bury them in alert triage, at which point the country is paying researcher salaries for work that automation should absorb. The tier structure exists to prevent exactly that.
| Tier | Holds | Never does |
|---|---|---|
| Nucleus | Builds the platforms, authors detections, runs deep response on the hardest incidents, holds the research edge and the authorization decisions | Routine triage |
| Operations | Runs the platforms around the clock, handles everything automation escalates, executes the playbooks the nucleus writes | Platform engineering |
| Surge | Absorbs the second and third concurrent incident, and the weeks of forensic labor a national ransomware event demands | Hold standing access |
Nine divisions
Divisions are drawn so that every layer an adversary can touch has exactly one owner. Where two divisions share a platform, one of them is named accountable for it.
| Code | Division | Holds | Staff |
|---|---|---|---|
| HW | Hardware and Embedded | Silicon, firmware, boot chains, industrial devices | 2 |
| NET | Network Defense | Backbone, routing, protocols, traffic visibility | 3 |
| OS | Systems and Endpoint | Kernels, endpoints, low level vulnerability research | 3 |
| CLD | Cloud and Identity | Control planes, directories, privilege, workloads | 2 |
| APP | Application and Offensive | Software security, authorized red team, supply chain | 3 |
| AI | AI and Autonomous Defense | Model security, detection engineering, automated response | 3 |
| MAL | Malware and Capability | Sample analysis, adversary emulation, authorized tooling | 3 |
| INT | Intelligence and Response | Threat intelligence, incident command, digital forensics | 3 |
| CMD | Command and Platform | Mission command, the grid itself, resilience | 2 |
The roster
Each role is written as a hiring standard and an engineering mandate at the same time. A candidate who can do the first but not the second is a good analyst and the wrong hire for this structure.
| Code | Role | Must build |
|---|---|---|
| HW-01 | Hardware Security Engineer | Continuous firmware attestation across the national hardware inventory, flagging any board that boots something it has never booted before |
| HW-02 | Embedded Reverse Engineer | Automated rehosting and fuzzing of every firmware image entering the inventory, without a human opening it first |
| NET-03 | Network Security Architect | A live map of national traffic with a placement optimizer that names the paths still dark, turning visibility into a measured percentage |
| NET-04 | Detection and Response Engineer | A line rate sensor that takes a detection from one author to the whole national fleet in minutes, with automatic rollback |
| NET-05 | Protocol Security Researcher | Differential fuzzing that runs several implementations of a protocol side by side and reports where they disagree |
| OS-06 | Windows Internals Engineer | A kernel grade sensor that judges behavior locally and keeps enforcing when the console is unreachable |
| OS-07 | Linux Systems Engineer | eBPF sensing with runtime enforcement that cannot be disabled by the workload it is watching |
| OS-08 | Vulnerability Researcher | Autonomous discovery that grades exploitability and checks prior art, so a human reads only what is real and unreported |
| CLD-09 | Cloud Security Architect | Agentless posture joined to admission time enforcement, blocking a misconfiguration as it deploys rather than reporting it monthly |
| CLD-10 | Identity and Access Engineer | Continuous attack path computation across the national directory estate, with the highest value privilege edges cut automatically |
| APP-11 | Application Security Lead | A learned baseline per government service, so anything the application has never legitimately done is refused |
| APP-12 | Red Team Operator | Continuous authorized assessment that demonstrates exploitation inside a cryptographically scoped engagement |
| APP-13 | Supply Chain Engineer | Attestation from source commit to running binary, answering "where else is this component" in seconds during an incident |
| AI-14 | AI Security Researcher | A learned baseline of each agent's legitimate tool calls and data flows, treating a compromised model like a compromised process |
| AI-15 | Detection Engineering Lead | Write once, compile to every sensor type, test against recorded intrusions, ship to the fleet, roll back when precision drops |
| AI-16 | Autonomous Defense Engineer | Triage, enrichment and containment for the overwhelming majority of alerts, with irreversible actions held behind human approval |
| MAL-17 | Malware Reverse Engineer | Analysis that ends in artifacts rather than a report: a detection, an indicator set and a family signature the same day |
| MAL-18 | Automated Analysis Engineer | Sample intake at national volume, triaged, clustered and converted to deployed detection without an analyst in the loop |
| MAL-19 | Capability Development Engineer | An armory where every authorized capability is serialized, scoped by signed authorization, logged in use and retired on command |
| INT-20 | Threat Intelligence Analyst | Collection that reaches a sensor automatically, because intelligence that never reaches a sensor is a newsletter |
| INT-21 | Incident Response Lead | Fleet wide scoping and containment sequencing, so an intrusion is bounded in hours rather than chased for weeks |
| INT-22 | Digital Forensics Lead | AI assisted investigation that reconstructs an intrusion into a defensible narrative, with chain of custody intact for court and for allies |
| CMD-23 | Mission Commander | One national readiness picture and an authorization workflow where every consequential action carries a named approver and a timestamp |
| CMD-24 | Platform Architect | A substrate designed to lose a region and keep running, because the defense platform is itself a primary target |
Table 6. Where a country cannot recruit a role at the start, the design names which engagement covers it in the interim and which local institution is expected to grow it.
Why forensics is its own seat
Most organizations fold forensics into incident response, and then discover during a real event that the person coordinating containment across a ministry at three in the morning is also the person who should be carving a memory image. Those two jobs compete, and forensics loses. That is how a country contains an intrusion without ever learning how it began, which makes the next one identical.
Evidentiary forensics is also a distinct discipline in its own right. Chain of custody, defensible tooling, admissibility rules that differ by jurisdiction, and the ability to testify. Anything that will be used publicly, shared with an ally, or taken to court rests on it. Separating the seat is what makes attribution survivable when it is challenged.
The design adapts. The structure does not bend.
Every country arrives with different institutions, a different labor market and a different budget. Which roles are grown locally and which are contracted at the start changes. Which layers have an owner does not.
Autogon Inc.. Staffing figures are design outputs for planning and assume a national estate of moderate complexity. Tier sizing should be recalculated against sector count, population and the number of separately governed institutions in scope.
