1

Dod Soc Operations Lead Jobs (NOW HIRING)

The Program Manager - CBO vSOC will lead delivery of cybersecurity and SOC operations programs in support of the Congressional Budget Office. This role requires proven expertise in managing 24x7x365 ...

Lead daily SOC operations and serve as an escalation point for complex security incidents. * Develop and maintain SOC runbooks, playbooks, and incident response procedures. * Mentor SOC analysts and ...

Consult with security operations regarding cybersecurity communications and deliver or request ... Experience with NIWC and/or a DOD SOC. #EverforthECS1 ECS Federal LLC is an equal opportunity ...

Showing results 21-40

Dod Soc Operations Lead information

See salary details

$12

$27

$64

How much do dod soc operations lead jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for dod soc operations lead in the United States is $27.95, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $31.01 per hour, depending on experience, location, and employer.

What is a DoD SOC Operations Lead?

DoD SOC Operations Leads are professionals responsible for managing and overseeing the day-to-day operations of Security Operations Centers (SOCs) within the U.S. Department of Defense (DoD). They coordinate cybersecurity monitoring, incident response, and threat analysis activities to protect DoD networks and systems. These leads supervise SOC analysts, ensure the implementation of security protocols, and maintain compliance with federal security standards. Their role is crucial in swiftly detecting and mitigating cyber threats to safeguard national security.

What are the key skills and qualifications needed to thrive as a DoD SOC Operations Lead?

To thrive as a DoD SOC Operations Lead, you need expertise in cybersecurity operations, incident response, and a comprehensive understanding of security frameworks, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or Security+. Proficiency with SIEM tools (such as Splunk or ArcSight), intrusion detection systems, and DoD-specific security platforms is typically required. Leadership, strong communication, and decision-making skills are essential for coordinating teams and managing high-pressure security incidents. These skills ensure effective threat detection, incident management, and mission-critical protection of Department of Defense information systems.

How does a DoD SOC Operations Lead typically collaborate with other teams to ensure effective threat response?

As a DoD SOC Operations Lead, you will regularly coordinate with incident response teams, IT departments, and external stakeholders to streamline communication during security events. Collaboration often involves leading cross-functional meetings, sharing intelligence on emerging threats, and ensuring that playbooks and response protocols are up-to-date. Strong interpersonal and leadership skills are crucial, as you’ll be responsible for aligning SOC activities with broader organizational security strategies and ensuring rapid, unified responses to incidents.

What are popular job titles related to Dod Soc Operations Lead jobs?

For Dod Soc Operations Lead jobs, the most frequently searched job titles are:

Infographic showing various Dod Soc Operations Lead job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $58,139 per year, or $28 per hour.

Cybersecurity Watch Operations Subject Matter Expert IV

Colorado Springs, CO • On-site

Invictus International Consulting, LLC
Guided Missile and Space Vehicle Manufacturing • 11 - 50 employees

$170K/yr

Full-time

Posted 7 days ago


Job description

Title: Cybersecurity Watch Operations Subject Matter Expert IV
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
  • Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC
  • Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain
  • Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence
  • Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices
  • Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations
  • Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises
  • Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required
  • Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities
  • Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
  • Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.
  • Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defenses
  • Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities
  • Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required

Requirements:
  • Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
  • Minimum of eight (8) years of relevant experience in addition to education level
  • Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environments
  • Demonstrated experience leading complex investigations while remaining technically hands-on.
  • Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programs
  • Strong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPs
  • Experience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teams
  • Experience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desired
  • Must possess current DoD 8570 IAT II or IAM II certification
  • Experience working in a DoD or IC environment
  • Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph

Equal Opportunity Employer/Veteran/Disabled