SOC Tier 3 and Incident Response Lead

Strategic Operational Solutions•Fort Liberty, NC
•Onsite

About The Position

Strategic Operational Solutions (STOPSO) is seeking a SOC Tier 3 and Incident Response Lead to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Lead complex intrusion analysis and incident response, conduct advanced threat hunts, and improve detection coverage. This senior technical role guides Tier 1 and Tier 2 analysts during high-priority investigations.

Requirements

  • Minimum 5 years of documented relevant experience.
  • Relevant incident response and cyber defense experience in a DoD or enterprise setting, including CJCSM 6510.01B familiarity, advanced intrusion analysis, hunting, and detection engineering.
  • DoD Cyber Workforce Framework (DCWF) 531, Cyber Defense Incident Responder, Advanced proficiency, and DCWF 511, Cyber Defense Analyst, Advanced proficiency.
  • Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.
  • Current matrix-listed certification options for 531 Advanced: CFR, CySA+, GCFA, GCIA, GICSP.
  • Current matrix-listed certification options for 511 Advanced: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP.
  • Qualification is needed for both assigned roles.
  • Demonstrated knowledge of Advanced incident response, intrusion analysis, network and host forensics, threat hunting, detection engineering, and incident categorization.
  • Proficiency with SIEM, EDR, packet analysis, YARA, Snort or Suricata, and forensic or malware-analysis tools appropriate to assigned duties and approved access.
  • Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.
  • Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.
  • Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.
  • Active SECRET clearance and ability to maintain assigned system access.
  • U.S. citizenship is required.

Nice To Haves

  • Experience leading major incident response in a DoD or enterprise environment.
  • Relevant DoD or enterprise IT experience with mission tooling and operational reporting.

Responsibilities

  • Lead analysis of complex intrusions and suspected advanced persistent threat activity across host, network, and intelligence sources.
  • Direct technical incident investigation, evidence handling, scope assessment, and response recommendations.
  • Coordinate containment, eradication, recovery, and reporting with authorized Government stakeholders.
  • Plan advanced hunts and develop or validate correlation rules, YARA content, and network or host detections.
  • Review significant incident records and ensure findings, actions, and handoffs are complete and timely.
  • Mentor lower-tier analysts, improve playbooks, and support exercises and surge response.
  • Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service