SECOPS Lead
Job in
Washington, District of Columbia, 20022, USA
Listed on 2026-02-16
Listing for:
AAC
Full Time
position Listed on 2026-02-16
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Network Security
Job Description & How to Apply Below
- Serves as the Lead Cybersecurity Operations (SECOPS) contractor
, providing senior-level technical leadership and operational support to the Agency’s IT Security Program. Supports and coordinates SECOPS activities under government direction and maintains technical inputs to the Agency’s IT Security Program. - Provides senior technical advisory support to the Chief Information Security Officer (CISO) on developments in cybersecurity, information security (INFOSEC), and IT security, including emerging threat vectors, advanced persistent threats (APTs), attack surface analysis, and identified weaknesses. Delivers actionable recommendations for government consideration and decision-making.
- Supports Agency-level technical implementation of approved cybersecurity policies, standards, and directives by developing technical documentation, implementation guidance, and draft procedures for government review and approval.
- Leads day-to-day contractor cybersecurity operations activities within the SECOPS function
, supporting government-led oversight of systems and services that impact the Agency’s mission and critical infrastructure. Executes approved actions in alignment with government priorities and risk decisions. - Implements and administers cybersecurity incident handling (IH) and incident response (IR) capabilities
, including SIEM dashboards, detection inputs, incident response playbooks, and operational metrics, to improve efficiency and effectiveness of security operations. - Facilitates and coordinates SECOPS activities in support of the Agency’s Information Security (INFOSEC) Program
, assisting Agency system security personnel and Information System Security Officers (ISSOs). Provides accurate and timely reporting on SOC performance metrics and submits recommendations for improvement to government leadership. - Serves as the senior technical advisor for threat, vulnerability, and configuration management activities
, providing threat intelligence analysis, mitigation recommendations, and defensive strategy insights to Agency stakeholders. Supports OIT by conveying industry attack trends, mitigations, and active defense techniques for government consideration and approval.
- Demonstrated ability to guide technical discussions and provide expert advisory support to senior government officials, including the CISO, system owners, SOC staff, and executive leadership, while operating under government direction.
- Proven experience as a SOC Lead or Senior Team Lead
, successfully coordinating with managed security service providers (MSSPs) and external cybersecurity partners (e.g., CISA, CYBERCOM) in support of incident response (IR), incident handling (IH), and vulnerability management (VM) activities), including mitigating actions to contain activity and facilitating forensics analysis when necessary. - Documented experience conducting and guiding in-depth technical evaluations of INFOSEC, IT security, and cybersecurity tactics, techniques, and procedures (TTPs), including their impact on baseline system configurations.
- Demonstrated proficiency providing cybersecurity posture assessments, hygiene reporting, and technical input in support of Governance, Risk, and Compliance (GRC) activities and continuous monitoring programs.
- Experience providing incident response support to network subscribers
, including recommending mitigating actions, supporting containment efforts, and facilitating forensic analysis under government oversight. - Demonstrated expertise in log-based and endpoint-based threat detection
, threat hunting, and analysis across multiple threat sources. - Strong technical knowledge of web services security
, Microsoft cloud environments (Azure, M365), and modern enterprise security architectures. - Advanced experience evaluating the security of complex web portals, APIs, and databases (e.g., Java, Ruby, SQL, Oracle) using commercial and open-source security assessment tools such as SQLmap and mongoaudit.
- Near-expert proficiency in:
- Web application security testing frameworks (e.g., NMAP, W3af)
- Continuous monitoring and remediation tools (e.g., Azure Security Center, Defender for…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×