Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOC. Lead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertain. Perform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidence. Establish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practices. Serve as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activities. Lead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gaps. Apply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operations. Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber risk. Lead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of action. Coordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as required. Partner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilities. Identify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture. Lead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions. Provide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvements.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior