SOC Tier 3 and Incident Response Lead

Strategic Operational Solutions, Inc

Fort Bragg (NC)

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Strategic Operational Solutions (STOPSO) seeks a SOC Tier 3 Incident Response Lead to support USARC DCOMS S program at Fort Bragg, NC. You will lead complex intrusion analysis, conduct advanced threat hunts, and guide Tier 1/2 analysts during high-priority investigations.

The role requires active SECRET clearance, DoD experience, and proficiency in detections engineering, SIEM/EDR tools, and advanced forensics.

Qualifications

  • At least 5 years of incident response and cyber defense in DoD or enterprise settings.
  • Familiar with CJCSM 6510.01B; advanced intrusion analysis, hunting and detection engineering.
  • Must meet DoD 8140.03 qualification requirements for each assigned work role.
  • Residential qualification and continuing learning requirements must be maintained.
  • 531 Advanced and 511 Advanced certifications available (CFR, CySA+, GCFA, GCIA, GICSP; CBROPS).

Responsibilities

  • Lead analysis of complex intrusions and APT activity across host and network sources.
  • Direct technical incident investigations, evidence handling, scope assessment and response recommendations.
  • Coordinate containment, eradication, recovery and reporting with Government stakeholders.
  • Plan advanced threat hunts and develop or validate correlation rules and detections.
  • Mentor Tier 1/2 analysts and update playbooks and surge response processes.

Skills

Advanced incident response
Intrusion analysis
Network forensics
Threat hunting
Detection engineering
Incident categorization

Education

DCWF 531 Advanced proficiency
DCWF 511 Advanced proficiency
DoD 8140 qualification
CJCSM 6510.01B familiarity
531/511 Advanced certifications (CFR, CySA+, GCFA, GCIA, GICSP; CBROPS)

Tools

SIEM
EDR
YARA
Suricata/Snort
Forensic tools

Job description

Position Summary

Strategic Operational Solutions (STOPSO) is seeking a SOC Tier 3 and Incident Response Lead to support the U.S. Army Reserve Command (USARC) Defensive Cyberspace Operations Mission Support Services (DCOMSS) program at Fort Bragg, North Carolina. Lead complex intrusion analysis and incident response, conduct advanced threat hunts, and improve detection coverage. This senior technical role guides Tier 1 and Tier 2 analysts during high-priority investigations.

Essential Duties and Responsibilities
  • Lead analysis of complex intrusions and suspected advanced persistent threat activity across host, network, and intelligence sources.
  • Direct technical incident investigation, evidence handling, scope assessment, and response recommendations.
  • Coordinate containment, eradication, recovery, and reporting with authorized Government stakeholders.
  • Plan advanced hunts and develop or validate correlation rules, YARA content, and network or host detections.
  • Review significant incident records and ensure findings, actions, and handoffs are complete and timely.
  • Mentor lower-tier analysts, improve playbooks, and support exercises and surge response.
  • Perform other duties as assigned consistent with the position's responsibilities, qualifications, clearance, and authorized scope.
Required Qualifications
Education and Experience
  • Minimum 5 years of documented relevant experience. Relevant incident response and cyber defense experience in a DoD or enterprise setting, including CJCSM 6510.01B familiarity, advanced intrusion analysis, hunting, and detection engineering.
  • DoD Cyber Workforce Framework (DCWF) 531, Cyber Defense Incident Responder, Advanced proficiency, and DCWF 511, Cyber Defense Analyst, Advanced proficiency.
  • Meet DoDM 8140.03 qualification requirements for every assigned work role and proficiency through an approved education, training, certification, or authorized experience route before independent cyber work. Document work-role appointment and qualification; maintain required residential qualification and continuing learning. A higher-level approved option may qualify the same role at a lower level.
  • Current matrix-listed certification options for 531 Advanced: CFR, CySA+, GCFA, GCIA, GICSP.
  • Current matrix-listed certification options for 511 Advanced: CBROPS, CFR, CySA+, GCFA, GCIA, GICSP.
  • Qualification is needed for both assigned roles.
Knowledge, Skills and Abilities
  • Demonstrated knowledge of Advanced incident response, intrusion analysis, network and host forensics, threat hunting, detection engineering, and incident categorization.
  • Proficiency with SIEM, EDR, packet analysis, YARA, Snort or Suricata, and forensic or malware-analysis tools appropriate to assigned duties and approved access.
  • Ability to produce accurate records, explain findings and decisions, and follow approved procedures and security requirements.
  • Strong written and verbal communication skills and sound judgment when coordinating with technical staff and Government stakeholders.
  • Strong organizational skills, confidentiality, and ability to work independently and collaboratively in a mission-focused environment.
Preferred Qualifications
  • Experience leading major incident response in a DoD or enterprise environment.
  • Relevant DoD or enterprise IT experience with mission tooling and operational reporting.
Security Clearance

Active SECRET clearance and ability to maintain assigned system access. U.S. citizenship is required.

Supervisory Responsibilities

Serves as technical lead for incident investigations and mentors analysts; formal personnel supervision depends on assignment.

Work Environment and Physical Requirements

Work is primarily performed on site in a secure Government facility using computer systems and standard office equipment. The employee must be able to perform sustained computer-based analysis or coordination, communicate effectively, and support operational activities outside standard business hours when assigned. Mission-essential watch roles may include shifts, weekends, and holidays.

Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions of the position.

Travel

Occasional local, CONUS, or OCONUS travel may be required for authorized mission activities, exercises, assessments, or conferences.

Equal Employment Opportunity

STOPSO is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Tier Two Analyst
SOC Tier Two Analyst

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 125,000
Threat Hunter
Threat Hunter

Strategic Operational Solutions, Inc • Fort Bragg (CA)

On-site
USD 120,000 - 165,000
Threat Hunter
Threat Hunter

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 110,000 - 140,000
Blue Team Lead and Senior Cyber Defense Analyst
Blue Team Lead and Senior Cyber Defense Analyst

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 110,000 - 160,000
Senior SOC Lead: Incident Response & Threat Hunting (Secret)
Senior SOC Lead: Incident Response & Threat Hunting (Secret)

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 120,000 - 170,000
Vulnerability Assessment Analyst
Vulnerability Assessment Analyst

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 120,000
SOC Tier II Analyst — Advanced Incident Response
SOC Tier II Analyst — Advanced Incident Response

Strategic Operational Solutions, Inc • Fort Bragg (NC)

On-site
USD 85,000 - 125,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International • Colorado Springs (CO)

On-site
USD 130,000 - 180,000
Cybersecurity Analyst
Cybersecurity Analyst

Saic • Fayetteville (NC)

On-site
USD 110,000 - 150,000
Cybersecurity Analyst
Cybersecurity Analyst

Saic • Fort Bragg (NC)

On-site
USD 110,000 - 150,000