Cybersecurity Operations Technical Lead (SOC Engineer/SME
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Security Management & Operations
Cybersecurity Operations Technical Lead (SOC Engineer/SME)
Washington, DC, USA
Job DescriptionPosted Wednesday, July 15, 2026 at 4:00 AM
Koniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Cybersecurity Operations Technical Lead (SOC Engineer/SME) to support KDS and our government customer in Washington, DC. This position requires the candidate to be able to obtain a Public Trust.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
Koniag Data Solutions, a Koniag Government Services company, is seeking an experienced Cybersecurity Operations Technical Lead to support the U.S. Small Business Administration (SBA). The ideal candidate is a seasoned cybersecurity professional with deep technical expertise in Security Operations Center (SOC) operations, threat detection, and incident response. This individual will serve as a subject matter expert (SME), providing technical leadership and guidance to a team of cybersecurity analysts while working closely with SBA stakeholders to protect critical government systems and data.
The Cybersecurity Operations Technical Lead will serve as the senior technical expert within the SOC, providing leadership, mentorship, and hands‑on technical support for all cybersecurity operations activities supporting the SBA.
Principal responsibilities will include but are not limited to:- Serve as the primary technical subject matter expert (SME) for SOC operations, providing guidance and oversight to cybersecurity analysts in the detection, analysis, and response to security incidents.
- Lead and coordinate incident response activities, including triage, containment, eradication, recovery, and post‑incident review in accordance with SBA policies and federal guidelines.
- Oversee continuous monitoring of SBA networks, systems, and endpoints using SIEM platforms, IDS/IPS tools, and other security technologies to identify and respond to potential threats and anomalies.
- Develop, tune, and maintain SIEM use cases, detection rules, correlation logic, and alerting thresholds to improve threat detection capabilities and reduce false positives.
- Conduct advanced threat hunting activities to proactively identify indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs) leveraged by threat actors targeting SBA systems.
- Perform in‑depth analysis of security events, logs, network traffic, and endpoint telemetry to identify malicious activity and provide actionable intelligence to SBA leadership and stakeholders.
- Collaborate with SBA IT and security teams to develop, refine, and maintain Standard Operating Procedures (SOPs), playbooks, and runbooks for SOC operations and incident response activities.
- Provide technical mentorship and training to junior and mid‑level SOC analysts, fostering professional development and elevating the overall capability of the team.
- Support vulnerability management activities, including the review and analysis of vulnerability scan results and coordination with system owners on remediation efforts.
- Prepare and deliver detailed technical reports, briefings, and after‑action reviews (AARs) to SBA leadership, documenting incident timelines, findings, and recommended corrective actions.
- Ensure SOC operations align with federal cybersecurity frameworks, policies, and compliance requirements, including NIST, FISMA, and DHS/CISA guidance.
- Coordinate with external stakeholders, including US‑CERT, CISA, and other federal agencies, as necessary, during significant cybersecurity incidents or threat campaigns.
- Support the continuous improvement of SOC processes, tools, and technologies to enhance operational efficiency and the overall cybersecurity posture of the SBA.
Required:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field from an accredited college or university.
- 8+ years of progressive experience in cybersecurity operations, with at least 3 years in a technical lead, senior analyst, or SME role…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).