Cybersecurity Operations Technical Lead (SOC Engineer/SME)
$170,000–$197,024 year
On-siteWashington, District of Columbia, United States or Washington, United States
Job Summary
Lead SOC operations and serve as the primary technical SME for SBA cybersecurity analysts, guiding detection, analysis, and incident response activities. Oversee continuous monitoring of networks and endpoints using SIEM platforms, IDS/IPS, and EDR tools to identify threats and anomalies. Develop, tune, and maintain detection rules, use cases, and alerting thresholds to reduce false positives while conducting advanced threat hunting for indicators of compromise. Perform in-depth log analysis across diverse data sources, collaborate on incident response playbooks and SOPs, and provide technical mentorship to junior analysts. Prepare detailed technical reports and after-action reviews for leadership, ensuring SOC alignment with federal frameworks like NIST and FISMA. Coordinate with external stakeholders including US-CERT and CISA during significant incidents. Requires a Public Trust clearance, 8+ years of SOC experience, and certifications such as CISSP or GIAC.
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university
- 8+ years of progressive experience in cybersecurity operations, with at least 3 years in a technical lead, senior analyst, or SME role within a SOC environment
- Demonstrated experience supporting federal government cybersecurity programs and operations
- Certified Information Systems Security Professional (CISSP)
- GIAC Security Operations Certified (GSOC)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Enterprise Defender (GCED)
- Certified SOC Analyst (CSA)
- Exceptional communication skills in English – both written and oral – with the ability to convey complex technical information clearly to both technical and non-technical audiences, including senior government leadership
- Deep technical expertise in SOC operations, including security event monitoring, incident detection, triage, and response
- Extensive hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or similar) including use case development, rule tuning, and dashboard creation
- Strong knowledge of network security concepts, including TCP/IP, DNS, HTTP/S, firewalls, IDS/IPS, and network traffic analysis tools such as Wireshark or Zeek
- Proficiency in endpoint detection and response (EDR) tools and methodologies for investigating host-based threats and anomalies
- Experience with threat intelligence platforms and the ability to operationalize threat intelligence to improve detection and response capabilities
- Strong understanding of the MITRE ATT&CK framework and its application to threat detection, threat hunting, and incident response
- Demonstrated experience developing and maintaining incident response playbooks, SOPs, and runbooks
- Knowledge of federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, NIST SP 800-61, FISMA, and CISA guidance
- Experience conducting log analysis across diverse data sources, including Windows Event Logs, Syslog, cloud platform logs, and application logs
- Ability to lead and mentor a team of cybersecurity analysts in a fast-paced operational environment
- Ability to obtain and maintain a Public Trust Clearance
Desired Qualifications
- Master's degree in Cybersecurity, Information Assurance, or a related field
- 10+ years of cybersecurity operations experience within a federal government or defense contracting environment
- Prior experience supporting SBA or other federal civilian agency cybersecurity programs
- Experience with cloud security monitoring and operations in AWS, Azure, or GCP environments
- Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms and scripting languages (e.g., Python, PowerShell) for automation of SOC workflows
- Knowledge of Zero Trust Architecture principles and implementation within a federal environment
- Experience with digital forensics and malware analysis techniques
- Familiarity with CDM (Continuous Diagnostics and Mitigation) program tools and requirements
- GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) certification
- Experience supporting FedRAMP authorized cloud environments
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.