Security Operations Center Technical Lead

Invictus International

Colorado Springs (CO)

On-site

USD 130,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Invictus International seeks a Security Operations Center Technical Lead in Colorado Springs to serve as the senior technical authority for SOC watch operations, threat hunting, and incident response. You will lead complex investigations, apply MITRE ATT&CK techniques, and coordinate with government stakeholders to mature our DoD SOC capabilities.

The role requires 8+ years in cybersecurity, DoD environment experience, and a DoD 8570 Level II certification.

Qualifications

  • Bachelor's degree in a relevant discipline; four additional years of related experience may substitute for a degree.
  • Minimum 8 years of directly related cybersecurity experience.
  • DoD 8570 IAT Level II or IAM Level II certification required.
  • Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, or threat hunting.
  • Strong knowledge of enterprise networking, network security monitoring, and incident response.
  • Experience with SIEM/SOAR, detection engineering, and vulnerability management.
  • Experience with DoD/Intelligence Community environments is highly desired.

Responsibilities

  • Serve as senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, and incident response.
  • Lead the most complex cyber defense investigations, incident-response activities, and threat-hunting campaigns.
  • Analyze host, network telemetry, firewall/IDS data, and vulnerabilities to identify threats.
  • Establish and improve SOC methodologies, triage standards, and escalation criteria.
  • Mentor SOC analysts and coordinate with government stakeholders as required.
  • Lead threat-hunting campaigns based on threat intelligence and mission priorities.
  • Apply MITRE ATT&CK and threat-informed defense techniques to investigations and proactive operations.
  • Correlate vulnerability, asset, configuration, and incident data to prioritize operational cyber risk.

Skills

SOC operations
Threat hunting
Incident response
MITRE ATT&CK
SIEM/SOAR
DoD environments

Education

Bachelor's degree in a relevant discipline

Tools

SIEM/SOAR
ACAS/Tenable
runZero

Job description

Title:

Security Operations Center Technical Lead

Location:

Colorado Springs, CO

Clearance:

TS/SCI with the ability to obtain and maintain a CI polygraph

Responsibilities:
  • Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOC
  • Lead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertain
  • Perform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidence
  • Establish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practices
  • Serve as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activities
  • Lead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gaps
  • Apply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operations
  • Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber risk
  • Lead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of action
  • Coordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as required
  • Partner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilities
  • Identify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
  • Lead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions
  • Provide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvements
Requirements:
  • Bachelor's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degree
  • Minimum 8 years of directly related cybersecurity experience
  • Must possess a DoD 8570 IAT Level II or IAM Level II certification
  • Experience supporting DoD or Intelligence Community environments is desired
  • Expert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operations
  • Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programs
  • Expert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defense
  • Strong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activities
  • Demonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actions
  • Experience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilities
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
  • Experience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desired
  • TS/SCI with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC. • Colorado Springs (CO)

On-site
USD 120,000 - 170,000
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC
SITEC - Cyber Defense Incident Responder (SR)- Fort Bragg, NC

Peraton • North Carolina

Hybrid
USD 120,000 - 180,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Jobtailor • California (MO)

On-site
USD 95,000 - 125,000
Security Operation Center (SOC) Analyst – Level II
Security Operation Center (SOC) Analyst – Level II

TAC Integrated Solutions • United States

On-site
USD 90,000 - 130,000
Senior Cyber Manager
Senior Cyber Manager

Peraton • Washington

On-site
USD 120,000 - 170,000
Senior SOC Lead: Threat Hunting & Incident Response
Senior SOC Lead: Threat Hunting & Incident Response

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
Local Defender Cybersecurity SOC Analyst Threat Analyst
Local Defender Cybersecurity SOC Analyst Threat Analyst

COLSA Corporation • California

On-site
USD 180,000 - 230,000