> Markdown version of [/jobs/ext/2793323-cybersecurity-watch-operations-subject-matter-expert-iv](https://www.wearedevelopers.com/jobs/ext/2793323-cybersecurity-watch-operations-subject-matter-expert-iv). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Watch Operations Subject Matter Expert IV - **Company:** Invictus Inc. - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Digital Data, Identity and Access Management, Intrusion Detection Systems, Network Security, Network Forensics, Network Monitoring, Reverse Engineering, Security Information and Event Management, Malware, Firewalls (Computer Science), Cyber Warfare - **Published:** September 8, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18225439?backUrl=%2Fcareer%2F18225439%2FCybersecurity-Watch-Operations-Subject-Matter-Expert-Iv-Colorado-Colorado-Springs ## About the Role Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph, * Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree * Minimum of eight (8) years of relevant experience in addition to education level * Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environments * Demonstrated experience leading complex investigations while remaining technically hands-on. * Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programs * Strong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPs * Experience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teams * Experience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desired * Must possess current DoD 8570 IAT II or IAM II certification * Experience working in a DoD or IC environment * Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph ## Description * Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC * Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain * Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence * Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices * Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations * Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises * Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required * Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities * Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture * Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions. * Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defenses * Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities * Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Harnessing the Power of Open Source's Newest Technologies](https://www.wearedevelopers.com/videos/1448-harnessing-the-power-of-open-source-s-newest-technologies) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [The Agentic Enterprise: Orchestrating People, AI, and European Sovereignty](https://www.wearedevelopers.com/videos/100273-the-agentic-enterprise-orchestrating-people-ai-and-european-sovereignty) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)