SECURITY OPERATIONS CENTER (SOC) LEAD
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
We are seeking a highly skilled and innovative Security Operations Center (SOC) Lead to join our team in the greater DMV area, supporting the Army National Guard., * Manage day-to-day SOC operations: staffing, shift coverage, case handling, escalation, and incident lifecycle management.
- Oversee incident coordination with CIRT, NOSC, ARCYBER, USCYBERCOM, and engineering teams; implement playbooks and countermeasures during incidents.
- Ensure investigative quality: review cases, validate threat analysis, enforce documentation/runbook standards, and oversee evidence preservation.
- Lead detection engineering efforts: rule/signature/content development, tuning, enrichment, and mapping to MITRE ATT&CK.
- Maintain continuous monitoring aligned with STIG/IAVM/RMF requirements and ensure SOC support for defensive cyber operations.
- Develop and maintain SOC SOPs, playbooks, escalation matrices, COOP procedures, and communications plans.
- Coordinate SOC reporting and notifications to RCC-NG, ARCYBER, USCYBERCOM, and other stakeholders; produce situational awareness products and executive briefings.
- Drive analyst training, exercises, purple teaming, and tool adoption; mentor Tier II/III analysts and refine workflows/automation.
- Support audits, inspections, accreditation activities, and evidence preparation for RMF/ATO and related reviews.
- Monitor SOC KPIs (MTTD, MTTR, case quality, false positive rates) and implement continuous improvement actions.
Requirements
- Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD
- Clearance: TS/SCI (active)
- Education/Training/Certification: Candidate must meet ONE:
- Master’s or Ph.D. in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering; OR
- Relevant DoD/Military training (e.g., 4C-255N/4C-255S/4C-255A, Cyber Defense Analyst Advanced Playlist); OR
- Relevant certifications (see list below).
- Experience: Progressive cybersecurity experience with3 years managing SOC operations or equivalent operational leadership in DoD/enterprise SOC environments.
- Demonstrated skills: SOC toolsets (SIEM, SOAR, EDR/XDR), incident handling, threat analysis, detection engineering, COOP operations, RMF/RMF-related reporting, and senior-level briefings.
Acceptable Certifications (one or more preferred)
- CBROPS, CFR, CySA+, GCFA, GCIA, GICSP, or equivalent advanced SOC/forensics/cyber operations certifications
Desired / Preferred
- Prior DoD/Army/ARNG SOC or NOSC experience
- Experience coordinating notifications to ARCYBER/USCYBERCOM and supporting classified enclave monitoring
- Familiarity with automation, SOAR playbooks, threat hunting, and purple team exercises
Benefits & conditions
Parental leave, 401(k), Health insurance, Paid time off, Vision insurance, Health savings account, Dental insurance, Life insurance, Target Salary Range: $86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at https://www.careers.peraton.com/benefits.
About the company
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology
Understanding and Mitigating Common Web Vulnerabilities