Cybersecurity Watch Operations Subject Matter Expert IV with Security Clearance
Why This Role Stands Out
This hybrid role offers an exceptional opportunity to shape and lead cutting-edge cybersecurity watch operations as a foundational SME, leveraging your expertise in complex investigations and incident response. You'll thrive here if you possess advanced forensic skills and a passion for mentoring others while driving significant improvements to enterprise security posture within a highly reputable organization. If you're ready to be a senior technical authority and have a TS/SCI clearance, this is an exciting chance to advance your career.
Quick Overview
Job Description
Title: Cybersecurity Watch Operations Subject Matter Expert IV Location: Alexandria, VA Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:
- Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC
- Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain
- Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence
- Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices
- Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations
- Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises
- Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required
- Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities
- Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
- Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.
- Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated contr ols and to validate the effectiveness of existing defenses
- Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities
- Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required Requirements:
- Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
- Minimum of eight (8) years of relevant experience in addition to education level
- Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environments
- Demonstrated experience leading complex investigations while remaining technically hands-on.
- Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programs
- Strong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPs
- Experience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teams
- Experience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desired
- Must possess current DoD 8570 IAT II or IAM II certification
- Experience working in a DoD or IC environment
- Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
Similar jobs
- AT
Android Developer
NewAdidev Technologies Inc
Matthews, North Carolina🇺🇸On-site2 minutes agoSQLiteAndroid SDKCSS+7Technology - AI
Senior Configuration Manager
NewASR INTERNATIONAL
Tampa, Florida🇺🇸Hybrid2 minutes agoComplianceConstruction ManagementContinuous Improvement+4Technology - TA
Senior Security Engineer - Product Security
NewTaxSlayer
Charlotte, North Carolina🇺🇸Remote2 minutes agoOWASPPCI DSSSOC 2+1Technology - HA
Security Operations Engineer III
NewHyundai Autoever America
Savannah, Georgia🇺🇸$79.8k - $108k/yrHybrid2 minutes agoEncryptionAgileDNS+1Technology - ST
Documentation Specialist
NewSolvere Technical Group
Elizabeth City, North Carolina🇺🇸Hybrid2 minutes ago401kComplianceData Entry+1Technology - AI
Configuration Manager
NewASR INTERNATIONAL
Tampa, Florida🇺🇸Hybrid2 minutes agoComplianceConstruction ManagementProcess Improvement+3Technology