> Markdown version of [/jobs/ext/3029938-nco-national-cybersecurity-operations-technical-lead](https://www.wearedevelopers.com/jobs/ext/3029938-nco-national-cybersecurity-operations-technical-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NCO (National Cybersecurity Operations) Technical Lead - **Company:** OCH Technologies LLC - **Location:** Leesburg, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Network Analysis, Cyber Security, Network Security, Log Analysis, NetCDF, Security Information and Event Management, Mitre Att&ck, Cyber Threat Analysis, SC Clearance, Information Technology, Cybercrime, Cortex XSOAR Platform, Data Management, Splunk, SentinelOne Expertise - **Published:** September 22, 2026 - **Apply:** https://www.thejobnetwork.com/job/d16bc435-be14-42d4-8426-c766b2cba14f/nco-national-cybersecurity-operations-technical-lead ## About the Role Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution, * At least fifteen (15)+ years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions. At least 2 years of relevant experience must be recent (performed within the last 3 years). * Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment. * Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products. * Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools. * Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi-segment network environments. Security Clearance Requirement Candidate must have the ability to obtain and maintain a Public Trust Active Secret clearance preferred Certifications Security certification such as CISSP, CISM, or CASP required GCIH (GIAC Certified Incident Handler) or GCTI (GIAC Cyber Threat Intelligence) strongly preferred GCFA, GNFA, or GCIA preferred for forensics/network analysis depth CND, CNDA, GDAT, GDSA, GCED, GCFA are directly relevant, * Prior experience supporting FAA, DoD, or other critical infrastructure cybersecurity operations. * Experience with aviation-specific cyber threats or operational technology (OT/ICS) threat analysis. * Familiarity with FAA Security Operations Center (SOC) operations. * Experience coordinating with federal threat intelligence sharing organizations (US-CERT, CISA, sector ISACs). * Modern threat intelligence platforms (MISP, OpenCTI) for structured threat data management and sharing. * SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines) for automated incident response workflows and playbook execution. * EDR/XDR tools (CrowdStrike Falcon, SentinelOne, Carbon Black) for endpoint-level detection and response in operational environments. * AI/ML-based anomaly detection and threat hunting tools for identifying novel attack patterns across complex, multi-segment network environments. * Attack surface management platforms for continuous external exposure monitoring of NAS-connected assets. Other Required Skills and Abilities * Understanding of federal cybersecurity policy (FISMA, NIST CSF, CDM program) and how operational cybersecurity functions support broader agency security objectives. * Strong written and verbal communication skills. Ability to brief senior leadership on threat landscape and operational status. ## Description OCH Technologies is seeking an NCO Technical Lead responsible for leading the day-to-day operational cybersecurity and threat intelligence functions supporting the FAA's National Cybersecurity Operations mission. The lead will run the operational side: monitor threat intelligence feeds, coordinate incident response, analyze emerging threats against NAS infrastructure, and provide technical guidance to the broader cybersecurity team. This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements. Location Hybrid - Air Traffic Control System Command Center (ATCSCC) Washington, DC OR Leesburg, VA This position has the potential to travel up to 20%. Core Responsibilities & Duties * Provide day-to-day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions. * Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination. * Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems. Produce actionable intelligence products that inform assessment priorities and defensive posture decisions. * Coordinate incident response activities when potential security events are identified. Ensure response actions follow established procedures and are documented. * Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues. * Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks. Brief FAA leadership on threat trends and recommended defensive actions. * Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape. * Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols. * Manage and oversee contractor staff performing NCO functions. Ensure personnel maintain required qualifications and training. Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role., * Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically. * Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. * People-Focused - We prioritize relationships, championing growth and mutual success. * Accountable - We own our outcomes, striving for excellence through continuous improvement. * Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)