> Markdown version of [/jobs/ext/220787-security-operations-center-soc-lead](https://www.wearedevelopers.com/jobs/ext/220787-security-operations-center-soc-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SECURITY OPERATIONS CENTER (SOC) LEAD - **Company:** Peraton Inc - **Location:** Herndon, VA, United States - **Experience:** Expert - **Salary:** $86,000.0 - $138,000.0 - **Contract:** Permanent contract - **Skills:** Multitier Architecture, Cyber Security, Information Systems, Intrusion Detection and Prevention, Security Information and Event Management, Software Engineering, Mitre Att&ck, Mttr, Information Technology, Cybercrime, Purple Team (Cyber Security), Cyber Warfare, Security Orchestration, Automation & Response - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=cdb1956eb97524b1 ## About the Role * Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD * Clearance: TS/SCI (active) * Education/Training/Certification: Candidate must meet ONE: + Master's or Ph.D. in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering; OR + Relevant DoD/Military training (e.g., 4C-255N/4C-255S/4C-255A, Cyber Defense Analyst Advanced Playlist); OR + Relevant certifications (see list below). * Experience: Progressive cybersecurity experience with3 years managing SOC operations or equivalent operational leadership in DoD/enterprise SOC environments. * Demonstrated skills: SOC toolsets (SIEM, SOAR, EDR/XDR), incident handling, threat analysis, detection engineering, COOP operations, RMF/RMF-related reporting, and senior-level briefings. Acceptable Certifications (one or more preferred) * CBROPS, CFR, CySA+, GCFA, GCIA, GICSP, or equivalent advanced SOC/forensics/cyber operations certifications Desired / Preferred * Prior DoD/Army/ARNG SOC or NOSC experience * Experience coordinating notifications to ARCYBER/USCYBERCOM and supporting classified enclave monitoring * Familiarity with automation, SOAR playbooks, threat hunting, and purple team exercises ## Description We are seeking a highly skilled and innovative Security Operations Center (SOC) Lead to join our team in the greater DMV area, supporting the Army National Guard., * Manage day-to-day SOC operations: staffing, shift coverage, case handling, escalation, and incident lifecycle management. * Oversee incident coordination with CIRT, NOSC, ARCYBER, USCYBERCOM, and engineering teams; implement playbooks and countermeasures during incidents. * Ensure investigative quality: review cases, validate threat analysis, enforce documentation/runbook standards, and oversee evidence preservation. * Lead detection engineering efforts: rule/signature/content development, tuning, enrichment, and mapping to MITRE ATT&CK. * Maintain continuous monitoring aligned with STIG/IAVM/RMF requirements and ensure SOC support for defensive cyber operations. * Develop and maintain SOC SOPs, playbooks, escalation matrices, COOP procedures, and communications plans. * Coordinate SOC reporting and notifications to RCC-NG, ARCYBER, USCYBERCOM, and other stakeholders; produce situational awareness products and executive briefings. * Drive analyst training, exercises, purple teaming, and tool adoption; mentor Tier II/III analysts and refine workflows/automation. * Support audits, inspections, accreditation activities, and evidence preparation for RMF/ATO and related reviews. * Monitor SOC KPIs (MTTD, MTTR, case quality, false positive rates) and implement continuous improvement actions. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf)