×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Watch Operations Subject Matter Expert IV Security Clearance

Job in Alexandria, Fairfax County, Virginia, 22306, USA
Listing for: Invictus International Consulting
Full Time position
Listed on 2026-09-08
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations, Network Security
Job Description & How to Apply Below
Position: Cybersecurity Watch Operations Subject Matter Expert IV with Security Clearance
Title:

Cybersecurity Watch Operations Subject Matter Expert IV

Location:

Alexandria, VA  Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details:
* Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC
* Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain
* Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence
* Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices
* Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations
* Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises
* Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required
* Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities
* Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
* Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.
* Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defenses
* Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities
* Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required Requirements:
* Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
* Minimum of eight (8) years of relevant experience in addition to education level
* Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environments
* Demonstrated experience leading complex investigations while remaining technically hands-on.
* Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programs
* Strong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPs
* Experience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teams
* Experience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desired
* Must possess current DoD 8570 IAT II or IAM II certification
* Experience working in a DoD or IC environment
* Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph Equal Opportunity Employer/Veteran/Disabled
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary