NOC/SOC Lead

Leidos

Hampton (VA)

On-site

USD 116,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Leidos is seeking a cleared NOC/SOC Lead to direct combined network and security operations for DoD information systems, focusing on RMF and ATO lifecycles. You will partner with ISSMs/ISSOs and the AO to ensure evidence, compliance posture, and continuous monitoring outputs for authorization sustainment.

You will lead multi-shift NOC/SOC staff, drive incident response, and supervise analysts, shaping SOPs, runbooks, and staff certification readiness.

Qualifications

  • Clearance: active TS/SCI w/ ability to obtain SCI
  • RW v RMF/ATO lifecycle experience across DoD systems
  • Lead multi-shift NOC/SOC operations teams

Responsibilities

  • Lead RMF steps from categorization to continuous monitoring.
  • Maintain ATO packages in eMASS with SSPs and artifacts.
  • Direct NOC/SOC monitoring, incident response, and remediation.

Skills

RMF/ATO leadership
DoD RMF knowledge
Incident response
Vulnerability management
Executive-level communication

Education

Bachelor’s Degree (12+ yrs)
Master’s Degree (10+ yrs)

Tools

ACAS/Nessus
STIG Viewer
SCAP Compliance Checker
Evaluate-STIG

Job description

Description

The Defense Sector at Leidos is seeking a cleared NOC/SOC Lead to direct combined network and security operations supporting Department of Defense (DoD) information systems, with primary emphasis on the Risk Management Framework (RMF) and the Authorization to Operate (ATO) lifecycle. This individual will lead operations staff across monitoring, incident response, and vulnerability management while ensuring daily operations produce the evidence, compliance posture, and continuous monitoring outputs required to obtain and sustain system authorizations. The NOC/SOC Lead will serve as the operational bridge between engineering teams, ISSMs/ISSOs, and the Authorizing Official (AO).

Roles and Responsibilities:
RMF & ATO Lifecycle
  • Lead operational support for all RMF steps, from categorization and control selection through assessment, authorization, and continuous monitoring.
  • Coordinate with ISSMs/ISSOs to build, update, and maintain ATO packages in eMASS, ensuring artifacts reflect the current operational state of the system.
  • Own the POA&Ms process for operations-related findings: track remediation, validate closure evidence, and elevate overdue items.
  • Prepare operations teams for ATO assessments, reauthorizations, and cyber inspections (e.g., CCORI), and lead the remediation of resulting findings.
  • Assess the security impact of proposed changes and ensure Configuration Control Board (CCB) decisions are reflected in authorization documentation.
Continuous Monitoring & Compliance
  • Execute the system ConMon strategy, ensuring scheduled vulnerability scans, STIG checks, and audit log reviews are completed and documented.
  • Oversee ACAS scanning cadence and vulnerability remediation timelines in accordance with IAVM, TASKORD, and OPORD directives.
  • Produce compliance metrics and risk posture reporting for government leadership and the AO.
Operations Leadership
  • Direct day-to-day NOC and SOC operations, including network health monitoring, security event triage, and service restoration.
  • Lead incident response activities, coordinate with the CSSP, and ensure timely and accurate incident reporting.
  • Develop and maintain SOPs, runbooks, shift turnover procedures, and escalation matrices.
  • Supervise, schedule, and mentor NOC/SOC analysts and technicians; identify training needs and support staff certification compliance.
Coordination & Governance
  • Serve as the primary operations liaison to ISSMs, ISSOs, SCAs, engineering teams, and government stakeholders.
  • Participate in CCB meetings and security reviews, representing operational risk and supportability considerations.
  • Drive continuous improvement of operational processes, tooling, and automation to reduce compliance burden and response times.
Required Qualifications:
  • Clearance: US Citizen with at least an active Top Secret clearance and the ability to obtain a SCI prior to your start date.
  • Education: Bachelor’s Degree with 12+ years of experience or a Master’s degree with 10+ years of experience. Additional experience may be considered in lieu of a degree.
  • Certifications: DoD 8570/8140 IAT Level III or IAM Level II certification.
  • Experience: 10+ years of combined IT/IS experience, including substantial hands-on RMF and ATO work and at least 3 years leading cybersecurity operations teams.
  • RMF & ATO Expertise:
    • Thorough working knowledge of DoDI 8510.01 (RMF for DoD Systems), NIST SP 800-37, and NIST SP 800-53 security and privacy controls.
    • Proven experience developing and maintaining ATO packages in eMASS, including System Security Plans (SSPs), control implementation statements, and artifacts.
    • Demonstrated ability to manage Plans of Action and Milestones (POA&Ms), risk acceptance documentation, and continuous monitoring (ConMon) strategies.
    • Experience supporting ATO assessments, reauthorizations, and Security Control Assessor (SCA) validation activities.
  • Operations Expertise:
    • Experience with enterprise monitoring and SIEM platforms and incident response workflows.
    • Hands-on familiarity with DoD compliance tooling, including ACAS/Nessus, STIG Viewer, SCAP Compliance Checker, and Evaluate-STIG.
    • Working knowledge of DoD incident handling and reporting requirements.
  • Leadership: Demonstrated ability to supervise multi-shift operations staff, manage escalations, and communicate risk clearly to technical and senior government audiences.
Preferred Qualifications:
  • Clearance: US Citizen with an active TS/SCI
  • RMF Certification: ISC2 CGRC or equivalent governance, risk, and compliance credential.
  • CSSP Certification: DoD 8570/8140 CSSP Analyst or Incident Responder certification (e.g., CySA+, GCIH, GCIA).
  • Classified Authorization: Experience authorizing classified systems under ICD 503 (IC) or the Joint SAP Implementation Guide (JSIG).
  • Continuous ATO: Exposure to continuous ATO (cATO) initiatives, DevSecOps pipelines, or automated control inheritance.
  • Zero Trust: Familiarity with the DoD Zero Trust Strategy and mapping ZT capabilities to RMF controls.
  • Endpoint & Security Tools: Experience with Trellix/HBSS, Tanium, or comparable endpoint security and asset management platforms.
  • ITSM: Experience with ITIL-based service management and ticketing platforms.

DABAOPP1

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Pay Range:

Pay Range $116,350.00 - $210,325.00

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Securing Your Data

Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.

If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

NOC/SOC Lead
NOC/SOC Lead

Leidos Inc • Hampton (VA)

On-site
USD 116,000 - 210,000
NOC/SOC Lead
NOC/SOC Lead

Society of Defense Financial Management • Hampton (VA)

On-site
USD 116,000 - 210,000
None
NOC/SOC Lead
NOC/SOC Lead

Koitecc Solutions • Hampton (VA)

On-site
USD 116,000 - 210,000
NOC/SOC Lead
NOC/SOC Lead

Via Logic LLC • Hampton (VA)

On-site
USD 116,000 - 210,000
Cyber Infrastructure Support Lead
Cyber Infrastructure Support Lead

Leidos Inc • Concord (MA)

On-site
USD 108,000 - 195,000
Senior Security Engineer
Senior Security Engineer

Leidos Inc • Bethesda (MD)

On-site
USD 108,000 - 195,000
Senior Security Engineer
Senior Security Engineer

Leidos • Bethesda (MD)

On-site
USD 108,000 - 195,000
DMDC SOC Manager - Deputy Program Manager
DMDC SOC Manager - Deputy Program Manager

Leidos • Alexandria (VA)

On-site
USD 131,000 - 237,000
Information System Security Engineer
Information System Security Engineer

Via Logic LLC • Norfolk (VA)

On-site
USD 87,000 - 157,000
DMDC SOC Manager - Deputy Program Manager
DMDC SOC Manager - Deputy Program Manager

Leidos • Seaside (CA)

On-site
USD 131,000 - 237,000