Job Description
Job Description Job Description Title: Cybersecurity Watch Operations Subject Matter Expert IVLocation: Colorado Springs, COClearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOCLead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertainPerform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidenceEstablish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practicesProvide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerationsServe as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercisesCoordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as requiredPartner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilitiesIdentify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security postureLead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defensesAnalyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive prioritiesApply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required Requirements:Bachelor 's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree Minimum of eight (8) years of relevant experience in addition to education level Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environmentsDemonstrated experience leading complex investigations while remaining technically hands-on.Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programsStrong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPsExperience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teamsExperience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desiredMust possess current DoD 8570 IAT II or IAM II certification Experience working in a DoD or IC environment Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled
Job Posted by ApplicantPro