NCO (National Cybersecurity Operations) Technical Lead

OCH Technologies, LLC

Leesburg (VA)

Hybrid

USD 180,000 - 240,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Paid time off
Health Insurance
Parental Leave
Disability insurance
401(k)
Life Insurance
Tuition Reimbursement

Job summary

OCH Technologies, LLC seeks an NCO Technical Lead to oversee day-to-day operational cybersecurity and threat intelligence for FAA networks. You will monitor threat feeds, coordinate incident response, and provide expert guidance to the cybersecurity team, with travel up to 20% to Leesburg, VA or DC.

This role supports a proposal effort and requires the ability to obtain and maintain a Public Trust. Strong leadership and communication are essential for coordinating with federal agencies and

Qualifications

  • 15+ years in cybersecurity with 5+ years in management overseeing operational cybersecurity or SOC/CIRT teams.

Responsibilities

  • Provide day-to-day technical oversight and guidance to contractor personnel.
  • Lead activities supporting the NCO mission including threat intel collection, analysis, hunting, and incident response coordination.
  • Monitor and analyze cyber threat intel for FAA and NAS systems; produce actionable intelligence.
  • Coordinate incident response actions and document procedures.
  • Brief FAA leadership on threat trends and defensive actions; report on NCO activities and issues.

Skills

Cybersecurity leadership
Incident response
Threat intelligence
SIEM
EDR tools
Threat hunting
Policy and compliance
Communication

Education

Bachelor's degree in CS/related field

Tools

SIEM platforms
Threat intelligence platforms
EDR tools
OpenCTI/MISP
Cortex XSOAR/Splunk SOAR

Job description

Description

OCH Technologies is seeking an NCO Technical Lead responsible for leading day‑to‑day operational cybersecurity and threat intelligence functions supporting the FAA's National Cybersecurity Operations mission. The lead will run the operational side: monitor threat intelligence feeds, coordinate incident response, analyze emerging threats against NAS infrastructure, and provide technical guidance to the broader cybersecurity team.

This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements.

Location

Hybrid – Air Traffic Control System Command Center (ATCSCC) Washington, DC or Leesburg, VA (potential to travel up to 20%).

Core Responsibilities & Duties
  • Provide day‑to‑day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions.
  • Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination.
  • Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems. Produce actionable intelligence products that inform assessment priorities and defensive posture decisions.
  • Coordinate incident response activities when potential security events are identified. Ensure response actions follow established procedures and are documented.
  • Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues.
  • Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks. Brief FAA leadership on threat trends and recommended defensive actions.
  • Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape.
  • Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols.
  • Manage and oversee contractor staff performing NCO functions. Ensure personnel maintain required qualifications and training.
Requirements
Minimum Qualifications
  • At least fifteen (15+) years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions. At least 2 years of relevant experience must be recent (performed within the last 3 years).
  • Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment.
  • Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products.
  • Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools.
  • Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi‑segment network environments.
Security Clearance Requirement

Candidate must have the ability to obtain and maintain a Public Trust. Active Secret clearance preferred.

Certifications
  • Security certification such as CISSP, CISM, or CASP required.
  • GCIH (GIAC Certified Incident Handler) or GCTI (GIAC Cyber Threat Intelligence) strongly preferred.
  • GCFA, GNFA, or GCIA preferred for forensics/network analysis depth.
  • CND, CNDA, GDAT, GDSA, GCED, GCFA are directly relevant.
Preferred Qualifications
  • Prior experience supporting FAA, DoD, or other critical infrastructure cybersecurity operations.
  • Experience with aviation‑specific cyber threats or operational technology (OT/ICS) threat analysis.
  • Familiarity with FAA Security Operations Center (SOC) operations.
  • Experience coordinating with federal threat intelligence sharing organizations (US‑CERT, CISA, sector ISACs).
  • Modern threat intelligence platforms (MISP, OpenCTI) for structured threat data management and sharing.
  • SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines) for automated incident response workflows and playbook execution.
  • EDR/XDR tools (CrowdStrike Falcon, SentinelOne, Carbon Black) for endpoint‑level detection and response in operational environments.
  • AI/ML‑based anomaly detection and threat hunting tools for identifying novel attack patterns across complex, multi‑segment network environments.
  • Attack surface management platforms for continuous external exposure monitoring of NAS‑connected assets.
Other Required Skills And Abilities
  • Understanding of federal cybersecurity policy (FISMA, NIST CSF, CDM program) and how operational cybersecurity functions support broader agency security objectives.
  • Strong written and verbal communication skills. Ability to brief senior leadership on threat landscape and operational status.
Benefits
  • Paid time off and Holidays
  • Medical, Dental, and Vision Insurance
  • Paid Parental Leave
  • Short‑term disability, long‑term disability, and life insurance – Employer Paid!
  • 401(k)
  • Additional Voluntary Life Insurance
  • Tuition Reimbursement
E‑Verify Participation

OCH Technologies, LLC is a participant of E‑Verify to verify the identity and employment eligibility of newly hired employees.

Veteran’s Preference and Accessibility Statement

At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here. We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at hiring@ochtec.com.

Equal Employment Opportunity

OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 150,000
Medical, Dental, Vision Insurance
Paid time off & holidays
Parental Leave
+3
Cybersecurity Engineer
Cybersecurity Engineer

Ochtec • Washington (NJ)

Hybrid
USD 130,000 - 180,000
Medical, Dental, Vision Insurance
401(k)
Paid time off and holidays
+2
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Ochtec • Washington (NJ)

On-site
USD 120,000 - 160,000
Paid time off and Holidays
Medical, Dental, and Vision Insurance
401(k)
+3
Program Manager
Program Manager

Ochtec • Herndon (VA)

Hybrid
USD 150,000 - 210,000
Paid time off
Medical, Dental, Vision Insurance
401(k) plan
+2
Program Manager
Program Manager

OCH Technologies, LLC • Leesburg (VA)

Hybrid
USD 120,000 - 180,000
Paid time off and holidays
Medical, dental, and vision insurance
Paid parental leave
+2
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

OCH Technologies, LLC • Leesburg (VA)

On-site
USD 120,000 - 150,000
Medical, Dental, and Vision Insurance
Paid Time Off
401(k)
+1
Mid-I Technical Support Analyst
Mid-I Technical Support Analyst

OCH Technologies • Warrenton (VA), Northern (KY)

Hybrid
USD 70,000 - 110,000
Paid time off
Medical, Dental, and Vision Insurance
401(k)
+4
Mid-I Technical Support Analyst
Mid-I Technical Support Analyst

OCH Technologies LLC • Warrenton (VA)

On-site
USD 70,000 - 100,000
Paid time off & holidays
Medical, Dental, Vision Insurance
401(k)
+2
Penetration Testing Lead
Penetration Testing Lead

Ochtec • Washington

Hybrid
USD 180,000 - 240,000
Paid time off and Holidays
Medical, Dental, Vision Insurance
401(k)
+1
Mid-I Technical Support Analyst
Mid-I Technical Support Analyst

OCH Technologies, LLC • Warrenton (VA)

On-site
USD 70,000 - 95,000
Paid time off
Medical Insurance
Dental Insurance
+3