> Markdown version of [/jobs/ext/1793054-cybersecurity-operations-technical-lead-soc-engineer-sme](https://www.wearedevelopers.com/jobs/ext/1793054-cybersecurity-operations-technical-lead-soc-engineer-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Operations Technical Lead (SOC Engineer/SME) - **Company:** Koniag Services, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Data Analysis, Microsoft Azure, Cloud Computing Security, Cyber Security, Computer Networks, Digital Forensics, Domain Name System (DNS), Event Logging, Hypertext Transfer Protocols (HTTP), Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Log Analysis, Network Forensics, Performance Tuning, Windows PowerShell, ArcSight SIEM Tool, Zero Trust Network Access, Reverse Engineering, Runbook, Security Information and Event Management, Syslog, TCP/IP, Wireshark, Software Vulnerability Management, Scripting, Cloud Platform System, Mitre Att&ck, Malware, Firewalls (Computer Science), Information Technology, Cybercrime, Microsoft Sentinel, Splunk, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 16, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9033376/cybersecurity-operations-technical-lead-soc-engineersme ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university. * 8+ years of progressive experience in cybersecurity operations, with at least 3 years in a technical lead, senior analyst, or SME role within a SOC environment. * Demonstrated experience supporting federal government cybersecurity programs and operations. * One or more of the following certifications: * Certified Information Systems Security Professional (CISSP) * GIAC Security Operations Certified (GSOC) * GIAC Certified Incident Handler (GCIH) * GIAC Certified Enterprise Defender (GCED) * Certified SOC Analyst (CSA) Desired: * Master's degree in Cybersecurity, Information Assurance, or a related field. * 10+ years of cybersecurity operations experience within a federal government or defense contracting environment., * Exceptional communication skills in English - both written and oral - with the ability to convey complex technical information clearly to both technical and non-technical audiences, including senior government leadership. * Deep technical expertise in SOC operations, including security event monitoring, incident detection, triage, and response. * Extensive hands-on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, ArcSight, or similar) including use case development, rule tuning, and dashboard creation. * Strong knowledge of network security concepts, including TCP/IP, DNS, HTTP/S, firewalls, IDS/IPS, and network traffic analysis tools such as Wireshark or Zeek. * Proficiency in endpoint detection and response (EDR) tools and methodologies for investigating host-based threats and anomalies. * Experience with threat intelligence platforms and the ability to operationalize threat intelligence to improve detection and response capabilities. * Strong understanding of the MITRE ATT&CK framework and its application to threat detection, threat hunting, and incident response. * Demonstrated experience developing and maintaining incident response playbooks, SOPs, and runbooks. * Knowledge of federal cybersecurity frameworks and compliance requirements, including NIST SP 800-53, NIST SP 800-61, FISMA, and CISA guidance. * Experience conducting log analysis across diverse data sources, including Windows Event Logs, Syslog, cloud platform logs, and application logs. * Ability to lead and mentor a team of cybersecurity analysts in a fast-paced operational environment. * Ability to obtain and maintain a Public Trust Clearance. Desired Skills and Competencies: * Prior experience supporting SBA or other federal civilian agency cybersecurity programs. * Experience with cloud security monitoring and operations in AWS, Azure, or GCP environments. * Familiarity with Security Orchestration, Automation, and Response (SOAR) platforms and scripting languages (e.g., Python, PowerShell) for automation of SOC workflows. * Knowledge of Zero Trust Architecture principles and implementation within a federal environment. * Experience with digital forensics and malware analysis techniques. * Familiarity with CDM (Continuous Diagnostics and Mitigation) program tools and requirements. * GIAC Certified Forensic Analyst (GCFA) or GIAC Reverse Engineering Malware (GREM) certification. * Experience supporting FedRAMP authorized cloud environments. ## Description The Cybersecurity Operations Technical Lead will serve as the senior technical expert within the SOC, providing leadership, mentorship, and hands-on technical support for all cybersecurity operations activities supporting the SBA. Principal responsibilities will include but are not limited to: * Serve as the primary technical subject matter expert (SME) for SOC operations, providing guidance and oversight to cybersecurity analysts in the detection, analysis, and response to security incidents. * Lead and coordinate incident response activities, including triage, containment, eradication, recovery, and post-incident review in accordance with SBA policies and federal guidelines. * Oversee continuous monitoring of SBA networks, systems, and endpoints using SIEM platforms, IDS/IPS tools, and other security technologies to identify and respond to potential threats and anomalies. * Develop, tune, and maintain SIEM use cases, detection rules, correlation logic, and alerting thresholds to improve threat detection capabilities and reduce false positives. * Conduct advanced threat hunting activities to proactively identify indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs) leveraged by threat actors targeting SBA systems. * Perform in-depth analysis of security events, logs, network traffic, and endpoint telemetry to identify malicious activity and provide actionable intelligence to SBA leadership and stakeholders. * Collaborate with SBA IT and security teams to develop, refine, and maintain Standard Operating Procedures (SOPs), playbooks, and runbooks for SOC operations and incident response activities. * Provide technical mentorship and training to junior and mid-level SOC analysts, fostering professional development and elevating the overall capability of the team. * Support vulnerability management activities, including the review and analysis of vulnerability scan results and coordination with system owners on remediation efforts. * Prepare and deliver detailed technical reports, briefings, and after-action reviews (AARs) to SBA leadership, documenting incident timelines, findings, and recommended corrective actions. * Ensure SOC operations align with federal cybersecurity frameworks, policies, and compliance requirements, including NIST, FISMA, and DHS/CISA guidance. * Coordinate with external stakeholders, including US-CERT, CISA, and other federal agencies, as necessary, during significant cybersecurity incidents or threat campaigns. * Support the continuous improvement of SOC processes, tools, and technologies to enhance operational efficiency and the overall cybersecurity posture of the SBA. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)