Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC

Colorado Springs (CO)

On-site

USD 145,000 - 196,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Invictus International Consulting, LLC in Colorado Springs is seeking a Cybersecurity Watch Operations Subject Matter Expert IV to serve as the senior technical authority for SOC watch operations and to contribute to the maturation of a new DoD SOC.

The role requires leading advanced investigations, directing incident response, and mentoring staff, with TS/SCI clearance and CI polygraph eligibility, and hands-on expertise across networking, SIEM/SOAR, and defense-in-depth strategies.

Qualifications

  • Bachelor's degree in a technical field; 4 years may substitute.
  • Minimum eight years of relevant experience.
  • Expert-level hands-on SOC operations and incident response.
  • Experience leading complex investigations and establishing procedures.
  • Strong knowledge of enterprise networking, SIEM/SOAR, and network security.
  • Current DoD 8570 IAT II or IAM II certification.
  • Active TS/SCI clearance with CI polygraph ability.

Responsibilities

  • Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC.
  • Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain.
  • Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence.
  • Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices.
  • Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations.
  • Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises.
  • Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required.
  • Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities.
  • Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture.
  • Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.
  • Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defenses
  • Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities
  • Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required

Education

Bachelor's degree

Job description

Title: Cybersecurity Watch Operations Subject Matter Expert IV

Location: Colorado Springs, CO

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

Job Details
  • Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC
  • Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain
  • Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence
  • Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices
  • Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations
  • Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises
  • Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required
  • Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities
  • Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
  • Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.
  • Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defenses
  • Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities
  • Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required
Requirements
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum of eight (8) years of relevant experience in addition to education level
  • Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environments
  • Demonstrated experience leading complex investigations while remaining technically hands-on.
  • Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programs
  • Strong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPs
  • Experience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teams
  • Experience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Salary: $170000 per year

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International • Colorado Springs (CO)

On-site
USD 140,000 - 190,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

invictusic • Colorado Springs (CO)

On-site
USD 130,000 - 170,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC • Alexandria (VA)

On-site
USD 145,000 - 196,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 150,000 - 190,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

invictusic • Alexandria (VA)

On-site
USD 150,000 - 210,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International • Alexandria (VA)

On-site
USD 140,000 - 180,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 200,000 - 230,000
Cybersecurity Watch Operations Subject Matter Expert IV
Cybersecurity Watch Operations Subject Matter Expert IV

Invictus International Consulting, LLC. • Alexandria (VA)

On-site
USD 150,000 - 190,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000