Security Operations Center Technical Lead
Job description
Title: Security Operations Center Technical Lead
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Responsibilities:
-
Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOC
-
Lead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertain
-
Perform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidence
-
Establish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practices
-
Serve as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activities
-
Lead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gaps
-
Apply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operations
-
Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber risk
-
Lead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of action
-
Coordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as required
-
Partner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilities
-
Identify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
-
Lead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions
-
Provide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvements
Requirements:
-
Bachelor's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degree
-
Minimum 8 years of directly related cybersecurity experience
-
Must possess a DoD 8570 IAT Level II or IAM Level II certification
-
Experience supporting DoD or Intelligence Community environments is desired
-
Expert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operations
-
Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programs
-
Expert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defense
-
Strong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activities
-
Demonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actions
-
Experience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilities
-
Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
-
Experience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desired
-
TS/SCI with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
More jobs at Invictusic
Collection Operations Manager
Invictusic· Washington, DC, USComputer Scientist
Invictusic· Washington, DC, USBiometrics Analyst
Invictusic· Washington, DC, USSoftware Programmer
Invictusic· Washington, DC, USComputer Scientist - Senior
Invictusic· Washington, DC, US
More jobs in Colorado Springs
Class B Warehouse Associate
Suncoast Drivers· Colorado Springs, United States· $48kSales Consultant - Empire Homes
Precedent Land Company· Colorado Springs, CO, USA· $36kField / Install Technician - Colorado Springs, CO
Lifeway Mobility· Colorado Springs, CO, USATower - Top Hand
Ontivity· Colorado Springs, CO, USALaCroix Sparkling Water – MerchMx Representative
National Beverage· Colorado Springs, CO, USA