Cybersecurity Operations Technical Lead (SOC Engineer/SME)

Koniag Government Services

Washington (District of Columbia)

On-site

USD 110,000 - 150,000

Full time

11 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
401(k) retirement plan
Paid time off
Parental leave
Life insurance
Disability insurance
Flexible spending accounts
Commuter benefits
Tuition reimbursement

Job summary

Koniag Operations Services, LLC (KOS), a Koniag Government Services company, seeks a Cybersecurity Operations Technical Lead to support SBA in Washington, DC. The role requires a Public Trust clearance and deep SOC expertise to lead detection, response, and incident handling.

The ideal candidate will manage SIEM, threat hunting, and playbooks, mentor junior staff, and coordinate with SBA stakeholders to protect critical systems and data in a federal environment.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS or related field.
  • 8+ years of progressive cybersecurity operations experience, with at least 3 years in a technical lead, senior analyst, or SME role within a SOC environment.
  • Demonstrated experience supporting federal government cybersecurity programs and operations.
  • Certifications: CISSP, GSOC, GCIH, GCED, CSA.
  • Strong communication in English with the ability to present to senior government leadership.

Responsibilities

  • Serve as the primary technical SME for SOC operations, guiding cybersecurity analysts in detection, analysis, and response to incidents.
  • Lead incident response activities including triage, containment, eradication, recovery, and post-incident review per SBA policies and federal guidelines.
  • Oversee continuous monitoring of SBA networks, systems, and endpoints using SIEM and IDS/IPS tools to detect threats and anomalies.
  • Develop, tune, and maintain SIEM use cases, rules, correlations, and alert thresholds to reduce false positives.
  • Conduct advanced threat hunting to identify IOCs and TTPs used by threat actors targeting SBA systems.
  • Prepare and deliver detailed technical reports and AARs to SBA leadership; maintain SOPs and runbooks for SOC operations.

Skills

SOC operations
SIEM
Threat detection
Incident response
Mentorship
Team leadership
Federal government experience
MITRE ATT&CK
EDR
Log analysis

Education

Bachelor's degree in Cybersecurity, IT, CS

Tools

Splunk
Microsoft Sentinel
ArcSight
Wireshark
IDS/IPS
Threat intelligence platforms

Job description

Koniag Operations Services, LLC (KOS), a Koniag Government Services company is seeking a Cybersecurity Operations Technical Lead (SOC Engineer/SME) to support KOS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.

Benefits include medical, dental, and vision insurance, 401(k) retirement plan, paid time off, paid parental leave, life and disability insurance, flexible spending accounts, commuter benefits, and tuition reimbursement.

We are seeking an experienced Cybersecurity Operations Technical Lead to support the U.S. Small Business Administration (SBA). The ideal candidate is a seasoned cybersecurity professional with deep technical expertise in Security Operations Center (SOC) operations, threat detection, and incident response. This individual will serve as a subject matter expert (SME), providing technical leadership and guidance to a team of cybersecurity analysts while working closely with SBA stakeholders to protect critical government systems and data.

The Cybersecurity Operations Technical Lead will serve as the senior technical expert within the SOC, providing leadership, mentorship, and hands‑on technical support for all cybersecurity operations activities supporting the SBA.

Principal Responsibilities Will Include But Are Not Limited To
  • Serve as the primary technical subject matter expert (SME) for SOC operations, providing guidance and oversight to cybersecurity analysts in the detection, analysis, and response to security incidents.
  • Lead and coordinate incident response activities, including triage, containment, eradication, recovery, and post-incident review in accordance with SBA policies and federal guidelines.
  • Oversee continuous monitoring of SBA networks, systems, and endpoints using SIEM platforms, IDS/IPS tools, and other security technologies to identify and respond to potential threats and anomalies.
  • Develop, tune, and maintain SIEM use cases, detection rules, correlation logic, and alerting thresholds to improve threat detection capabilities and reduce false positives.
  • Conduct advanced threat hunting activities to proactively identify indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs) leveraged by threat actors targeting SBA systems.
  • Perform in-depth analysis of security events, logs, network traffic, and endpoint telemetry to identify malicious activity and provide actionable intelligence to SBA leadership and stakeholders.
  • Collaborate with SBA IT and security teams to develop, refine, and maintain Standard Operating Procedures (SOPs), playbooks, and runbooks for SOC operations and incident response activities.
  • Provide technical mentorship and training to junior and mid-level SOC analysts, fostering professional development and elevating the overall capability of the team.
  • Support vulnerability management activities, including the review and analysis of vulnerability scan results and coordination with system owners on remediation efforts.
  • Prepare and deliver detailed technical reports, briefings, and after-action reviews (AARs) to SBA leadership, documenting incident timelines, findings, and recommended corrective actions.
  • Ensure SOC operations align with federal cybersecurity frameworks, policies, and compliance requirements, including NIST, FISMA, and DHS/CISA guidance.
  • Coordinate with external stakeholders, including US-CERT, CISA, and other federal agencies, as necessary, during significant cybersecurity incidents or threat campaigns.
  • Support the continuous improvement of SOC processes, tools, and technologies to enhance operational efficiency and the overall cybersecurity posture of the SBA.
Required

Education and Experience:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university.
  • 8+ years of progressive experience in cybersecurity operations, with at least 3 years in a technical lead, senior analyst, or SME role within a SOC environment.
  • Demonstrated experience supporting federal government cybersecurity programs and operations.
  • One or more of the following certifications:
  • Certified Information Systems Security Professional (CISSP)
  • GIAC Security Operations Certified (GSOC)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Enterprise Defender (GCED)
  • Certified SOC Analyst (CSA)
Desired
  • Master's degree in Cybersecurity, Information Assurance, or a related field.
  • 10+ years of cybersecurity operations experience within a federal government or defense contracting environment.
Required Skills And Competencies
  • Exceptional communication skills in English – both written and oral – with the ability to convey complex technical information clearly to both technical and non-technical audiences, including senior government leadership.
  • Deep technical expertise in SOC operations, including security event monitoring, incident detection, triage, and response.
  • Extensive hands‑on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or similar) including use case development, rule tuning, and dashboard creation.
  • Strong knowledge of network security concepts, including TCP/IP, DNS, HTTP/S, firewalls, IDS/IPS, and network traffic analysis tools such as Wireshark or Zeek.
  • Proficiency in endpoint detection and response (EDR) tools and methodologies for investigating host‑based threats and anomalies.
  • Experience with threat intelligence platforms and the ability to operationalize threat intelligence to improve detection and response capabilities.
  • Strong understanding of the MITRE ATT&CK framework and its application to threat detection, threat hunting, and incident response.
  • Demonstrated experience developing and maintaining incident response playbooks, SOPs, and runbooks.
  • Knowledge of federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, NIST SP 800-61, FISMA, and CISA guidance.
  • Experience conducting log analysis across diverse data sources, including Windows Event Logs, Syslog, cloud platform logs, and application logs.
  • Ability to lead and mentor a team of cybersecurity analysts in a fast‑paced operational environment.
  • Ability to obtain and maintain a Public Trust Clearance.
Desired Skills And Competencies
  • Prior experience supporting SBA or other federal civilian agency cybersecurity programs.
  • Experience with cloud security monitoring and operations in AWS, Azure, or GCP environments.
  • Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms and scripting languages (e.g., Python, PowerShell) for automation of SOC workflows.
  • Knowledge of Zero Trust Architecture principles and implementation within a federal environment.
  • Experience with digital forensics and malware analysis techniques.
  • Familiarity with CDM (Continuous Diagnostics and Mitigation) program tools and requirements.
  • GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) certification.
  • Experience supporting FedRAMP authorized cloud environments.
Our Equal Employment Opportunity Policy

The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.

The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e‑mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.

Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of KGS, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long‑term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Defense Analysts – Senior
Cyber Defense Analysts – Senior

Koniag Government Services • Washington

On-site
USD 140,000 - 190,000
Medical, dental, vision insurance
401(k) retirement plan
Paid time off
Security Operations Center Analyst - Low
Security Operations Center Analyst - Low

Koniag Government Services • Washington

On-site
USD 60,000 - 85,000
Medical insurance
Dental insurance
Vision insurance
+7
Program Manager
Program Manager

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+7
Security Engineer
Security Engineer

Koniag Government Services • Washington

On-site
USD 140,000 - 190,000
Medical, dental, and vision insurance
401(k) retirement plan
Paid time off
Deputy Program Manager
Deputy Program Manager

Koniag Government Services • Washington

Hybrid
USD 120,000 - 170,000
Medical
Dental
Vision
+8
Senior Security Manager
Senior Security Manager

Koniag Government Services • Smyrna (GA)

On-site
USD 120,000 - 170,000
Health insurance
401K with company matching
Flexible spending accounts
+2
Security Engineer
Security Engineer

Koniag Services, Inc. • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
Health insurance
401K with company matching
Paid holidays
+1
Jr SIEM/UEBA Engineer
Jr SIEM/UEBA Engineer

Koniag Government Services • Washington

On-site
USD 70,000 - 90,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Security Manager
Senior Security Manager

Koniag Services, Inc. • Smyrna (GA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Health, dental and vision insurance
401K with company matching
Flexible spending accounts
+1
Program Manager
Program Manager

Koniag Government Services • Washington

On-site
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+8