Network Operactions Center Cyber Team Lead

INTRINSIC RESOLUTION LLC
Washington, DC, United States
2 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$166,400.0 - $180,294.0
Working hours
Shift work
Job source

Tech stack

Data Analysis CompTIA Security+ Cyber Security Computer Networks Linux Intrusion Detection and Prevention Intrusion Detection Systems Network Security Ansible Security Information and Event Management Wireshark Software Vulnerability Management
+2 more
Computer Network Operations Splunk

Job description

The NOC Cyber Team Lead plays a pivotal role in managing the Security Operations Center, guiding the SOC team, and ensuring effective detection and response to cybersecurity incidents. Leveraging deep technical expertise, this individual will identify risks, improve methodologies, and protect the organization’s intellectual property from evolving threats. The role demands a combination of leadership, technical skill, and the ability to communicate complex cybersecurity issues to diverse stakeholders., * Lead, manage, and mentor the SOC team, ensuring day-to-day operations run smoothly and efficiently.

  • Provide guidance, feedback, and training to SOC analysts to improve performance and skillset.

  • Ensure 24/7 operational readiness of the SOC, including shift coverage and resource management across the Panama rotation.

Incident Response & Management

  • Lead the SOC team in identifying, analyzing, and responding to cybersecurity incidents - including intrusions, malware, and data breaches.

  • Reconstruct event timelines using network defense data to analyze intrusions and attacks.

  • Serve as the escalation point for complex or high-priority incidents, ensuring proper handling and resolution.

  • Support enterprise-wide incident response in collaboration with IT and cybersecurity teams.

  • Continuously strengthen incident response methodologies to improve response times and effectiveness.

Threat Detection & Mitigation

  • Develop and support threat detection capabilities to proactively identify emerging risks and vulnerabilities.

  • Analyze large volumes of network traffic, system logs, and threat intelligence data to uncover potential threats.

  • Leverage network operations expertise to predict attack vectors and devise proactive defense strategies.

  • Provide recommendations on improving threat data collection and ensuring high-quality data availability for analysis.

Cybersecurity Risk Analysis

  • Analyze cybersecurity risks and communicate findings to key decision-makers in a clear, concise manner.

  • Translate complex technical risks into actionable insights for non-technical stakeholders, including senior leadership.

  • Assist in identifying areas for continuous improvement in the organization’s cybersecurity practices.

Intellectual Property Protection

  • Safeguard the organization’s intellectual property by identifying threats and vulnerabilities that could put sensitive data at risk.

  • Develop and implement strategies to mitigate risks to intellectual property and other sensitive assets.

Collaboration & Communication

  • Collaborate with internal teams - IT, network security, and engineering - to ensure cohesive threat response strategies.

  • Serve as the subject matter expert for security incidents, threat analysis, and response processes within the SOC.

  • Keep organizational leadership and relevant stakeholders informed of critical cybersecurity events and decisions.

Security Tool Management & Optimization

  • Oversee configuration, optimization, and management of security tools including SIEM, IDS/IPS, endpoint protection, and monitoring solutions.

  • Ensure security tools are appropriately tuned to detect relevant threats and provide effective coverage across all systems.

Reporting & Documentation

  • Maintain accurate and detailed documentation of security incidents - analysis, findings, and mitigation steps.

  • Prepare incident reports, post-mortem analyses, and regular updates to senior management on SOC performance and emerging threats.

  • Ensure compliance with industry standards and regulatory requirements in incident documentation and reporting.

Continuous Improvement & Best Practices

  • Foster a culture of continuous improvement by assessing performance metrics, conducting after-action reviews, and implementing process improvements.

  • Stay current with the latest cybersecurity threats, trends, and best practices to ensure SOC alignment with industry standards., * Must be able to work the Panama shift schedule, including 12-hour shifts on a rotating 4-on/3-off and 3-on/4-off cycle, supporting 24x7x365 NOC operations.

  • New hire start dates are the 1st and 16th of each month.

HOW SUCCESS IS MEASURED

Performance in this role will be evaluated across the following key areas:

  • Incident Response Metrics: Speed and effectiveness of threat detection, containment, and resolution.

  • Threat Detection & Prevention: Reduction in false positives, proactive threat identification, and tool improvement.

  • Team Leadership: Team performance, retention, and success in analyst mentoring and training.

  • Collaboration & Communication: Cross-department cooperation, reporting clarity, and stakeholder confidence.

  • Continuous Improvement: Process optimization, post-incident review outcomes, and enhanced security posture.

  • Compliance & Audit: Adherence to regulatory requirements and favorable audit results.

Requirements

Do you have experience in Vulnerability management?, * Experience: 10+ years in cybersecurity, with at least 4 years in a leadership role within a SOC or security operations environment.

  • Certifications: CISSP, CISM, GCIH, GCIA, or equivalent cybersecurity certifications strongly preferred.

  • Technical Expertise: Proven expertise in network defense, incident response, threat detection, vulnerability management, and security operations.

  • Incident Response: Strong experience leading incident response efforts - network intrusions, malware infections, and data breaches.

  • Data Analysis: Experience analyzing large data volumes (network traffic, logs, threat intelligence) to identify and respond to cybersecurity risks.

  • Leadership Skills: Demonstrated ability to lead and mentor a team, manage operations, and communicate complex security issues to both technical and non-technical stakeholders.

  • Communication: Exceptional written and verbal communication skills; able to present technical information clearly to senior leadership.

ADDITIONAL QUALIFICATIONS

  • Strong understanding of network operations and how adversaries exploit network environments.

  • Ability to predict potential attack vectors based on current threat intelligence and historical data.

  • Strong analytical skills - able to translate complex data into actionable insights for decision-makers.

  • Experience with intellectual property protection strategies and threat data collection methodologies.

TECHNICAL ENVIRONMENT

Microsoft · Linux · Splunk · Ansible · Tenable · Wireshark

NON-NEGOTIABLE REQUIREMENTS

  • Active Top Secret clearance with investigation current within the last 5 years.

  • Hybrid work mode is temporary; position transitions to 100% on-site at the Manassas, VA location once that facility is accredited and cleared., * Cybersecurity: 10 years (Required)
  • Splunk: 3 years (Required)
  • Wireshark: 3 years (Required)
  • Data Analysis: 5 years (Required)
  • Leadership: 4 years (Required)

License/Certification:

  • CISSP, CISM, GCIH, GCIA or equivalent (Preferred)

Security clearance:

  • Top Secret (Required)

Benefits & conditions

1000 Independence Avenue SW, Washington, DC 20585 Hybrid work $80.00 - $86.68 an hour - Full-time, Contract, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Dental insurance, Panama Shift Schedule - Work just 15 days a month. 12-hour shifts on a rotating 4-on/3-off, then 3-on/4-off cadence - meaning every other weekend is a 4-day weekend, with built-in long stretches of time off.

Temporary Hybrid Flexibility - Until the Manassas facility is accredited and cleared, you’ll split each workday: half remote from home, half on-site at 1000 Independence Ave SW. A rare hybrid option for a cleared SOC leadership role., The NOC operates 24x7x365 on a Panama shift schedule built around 12-hour shifts and a rotating, balanced work/rest cycle. Across a two-week rotation, you work only 15 days per month and enjoy frequent multi-day stretches off - including a recurring four-day weekend.

Week Pattern

Week A

Work 4 days / Off 3 days (12-hour shifts)

Week B

Work 3 days / Off 4 days (12-hour shifts)

Net result: predictable scheduling, half the commute days, and substantially more time off than a standard Monday-Friday role., Prospective applicants are hereby notified that reviews and tests for the absence of any illegal drug as defined in 10 CFR 707.4 will be conducted by the employer. A background investigation by the Federal government may be required to obtain an access authorization prior to employment, and subsequent reinvestigations may be required. This position is covered by the Counterintelligence Evaluation Program regulations at 10 CFR Part 709. Applicants are advised that successful completion of a counterintelligence evaluation may include a counterintelligence-scope polygraph examination.

This position and all hiring decisions will be made without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

As a federal contractor, Intrinsic Resolution, LLC complies with Section 503 of the Rehabilitation Act and VEVRAA. No disability-related inquiries will be made prior to a conditional offer of employment, except as permitted by applicable law.

Employee Rights Under the National Labor Relations Act (NLRA): As a federal contractor, the Company complies with Executive Order 13496 and informs employees of their rights under the NLRA. Information is available at the workplace and from the National Labor Relations Board.

This position is covered by the Service Contract Labor Standards (SCLS). Compensation and fringe benefits will be provided in accordance with the applicable U.S. Department of Labor wage determination and any applicable collective bargaining agreement.

Pay: $80.00 - $86.68 per hour, * 401(k) matching

  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · World Congress 2025

Videos

See all

Related articles

See all