SOC Architect
OpenKyber LLC
Washington, DC, United States
1 day ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Amazon Web Services
Microsoft Azure
Cloud Computing Security
Cyber Security
Computer Networks
Digital Forensics
Domain Name System (DNS)
Hypertext Transfer Protocols (HTTP)
Intrusion Detection and Prevention
Intrusion Detection Systems
Python (Programming Language)
Network Security
+14 more
Log Analysis
Performance Tuning
Windows PowerShell
Zero Trust Network Access
Runbook
Security Information and Event Management
TCP/IP
Software Vulnerability Management
Scripting
Google Cloud
Mitre Att&ck
Cyber Threat Analysis
Firewalls (Computer Science)
Information Technology
Job description
OpenKyber is seeking a Cybersecurity Operations Technical Lead (SOC Engineer/SME) to support government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust. Competitive compensation and benefits package offered. The candidate will provide technical leadership and guidance to cybersecurity analysts, supporting the U.S. Small Business Administration (SBA). Responsibilities:
- Lead SOC operations and provide SME guidance on security incident detection and response.
- Coordinate incident response activities to comply with SBA federal guidelines.
- Monitor networks and endpoints using SIEM, IDS/IPS tools to detect threats.
- Develop and tune SIEM use cases and detection rules to enhance threat detection.
- Conduct advanced threat hunting for IOCs and TTPs.
- Analyze security events, network traffic, and endpoint telemetry for malicious activity.
- Develop SOPs, playbooks, and runbooks for SOC and incident response.
- Mentor junior to mid-level SOC analysts.
- Support vulnerability management efforts.
- Prepare technical reports and brief SBA leadership.
- Ensure SOC operations align with NIST, FISMA, DHS/CISA frameworks.
- Coordinate with federal agencies during major cybersecurity incidents.
- Improve SOC processes, tools, and cybersecurity posture.
Requirements
- Bachelor’s degree in Cybersecurity, IT, Computer Science, or related field.
- 8+ years cybersecurity operations, 3+ years technical lead/SME in SOC.
- Experience supporting federal cybersecurity programs.
- Certifications such as CISSP, GSOC, GCIH, GCED, CSA preferred., * Strong SOC operations expertise, incident detection and response.
- Experience with SIEM platforms, use case development, and rule tuning.
- Knowledge of network security concepts, TCP/IP, DNS, HTTP/S, firewalls, IDS/IPS.
- Proficiency in EDR tools and threat intelligence platforms.
- Familiarity with MITRE ATT&CK framework.
- Experience with incident response playbooks and SOPs.
- Understanding of federal cybersecurity compliance and log analysis.
- Leadership and mentorship abilities.
- Public Trust Clearance eligibility.
Desired Skills:
- Prior federal civilian agency cybersecurity experience.
- Cloud security monitoring (AWS, Azure, GCP).
- Experience with SOAR platforms and scripting (Python, PowerShell).
- Knowledge of Zero Trust Architecture and digital forensics.
- Familiarity with CDM program and FedRAMP.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.adzuna.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
about 2 years ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
LM
Luis Minvielle
Is Software Engineering Over-Saturated?
over 2 years ago
KD
Krissy Davis
Best Paying Jobs in Technology
about 3 years ago