1

Dod Soc Operations Lead Jobs (NOW HIRING)

... DoD cybersecurity policies and standards. Responsibilities * Lead enterprise cybersecurity ... Oversee SOC operations * Manage incident response * Support penetration testing * Lead ...

The SOC Lead / Incident Manager will oversee 24x7x365 Security Operations Center (SOC) functions for the Congressional Budget Office vSOC program. This role requires strong leadership in incident ...

... DoD cybersecurity policies and standards. Responsibilities * Lead enterprise cybersecurity ... Oversee SOC operations * Manage incident response * Support penetration testing * Lead ...

... DoD cybersecurity policies and standards. Responsibilities * Lead enterprise cybersecurity ... Oversee SOC operations * Manage incident response * Support penetration testing * Lead ...

Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security Operations Center (SOC) while actively participating in threat detection, investigation, and response ...

Job Summary The Lead SOC Analyst is responsible for leading the daily operations of the Security Operations Center (SOC) while actively participating in threat detection, investigation, and response ...

Showing results 41-60

Dod Soc Operations Lead information

See salary details

$12

$27

$64

How much do dod soc operations lead jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for dod soc operations lead in the United States is $27.95, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $31.01 per hour, depending on experience, location, and employer.

What is a DoD SOC Operations Lead?

DoD SOC Operations Leads are professionals responsible for managing and overseeing the day-to-day operations of Security Operations Centers (SOCs) within the U.S. Department of Defense (DoD). They coordinate cybersecurity monitoring, incident response, and threat analysis activities to protect DoD networks and systems. These leads supervise SOC analysts, ensure the implementation of security protocols, and maintain compliance with federal security standards. Their role is crucial in swiftly detecting and mitigating cyber threats to safeguard national security.

What are the key skills and qualifications needed to thrive as a DoD SOC Operations Lead?

To thrive as a DoD SOC Operations Lead, you need expertise in cybersecurity operations, incident response, and a comprehensive understanding of security frameworks, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or Security+. Proficiency with SIEM tools (such as Splunk or ArcSight), intrusion detection systems, and DoD-specific security platforms is typically required. Leadership, strong communication, and decision-making skills are essential for coordinating teams and managing high-pressure security incidents. These skills ensure effective threat detection, incident management, and mission-critical protection of Department of Defense information systems.

How does a DoD SOC Operations Lead typically collaborate with other teams to ensure effective threat response?

As a DoD SOC Operations Lead, you will regularly coordinate with incident response teams, IT departments, and external stakeholders to streamline communication during security events. Collaboration often involves leading cross-functional meetings, sharing intelligence on emerging threats, and ensuring that playbooks and response protocols are up-to-date. Strong interpersonal and leadership skills are crucial, as you’ll be responsible for aligning SOC activities with broader organizational security strategies and ensuring rapid, unified responses to incidents.

What are popular job titles related to Dod Soc Operations Lead jobs?

For Dod Soc Operations Lead jobs, the most frequently searched job titles are:

Infographic showing various Dod Soc Operations Lead job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $58,139 per year, or $28 per hour.

Operations Lead / Active Top Secret

Beltsville, MD • On-site

Peraton
IT Services • 10K+ employees

Other

Posted 13 days ago


Peraton rating

8.3

Company rating: 8.3 out of 10

Based on 56 frontline employees who took The Breakroom Quiz


Job description

Responsibilities

Peraton is currently seeking to hire an experienced Operations Lead - Engineering for its' Federal Strategic Cyber programs.

Location: Beltsville, MD

OverviewThe Operations Lead – Engineering serves as the senior technical and operational authority for the Engineering division of the Security Operations Center (SOC). In this role, you will oversee the full lifecycle of SOC engineering operations, including systems administration, physical and virtual network engineering, 24x7x365 shift coverage, and direct supervision of all engineering staff. You will ensure that critical systems, tools, and services remain secure, available, compliant, and fully operational to support mission requirements.

Key Responsibilities

Technical & Operational Leadership

  • Provide senior-level direction to system administrators, network engineers, and cybersecurity engineers supporting 24x7x365 SOC operations.
  • Oversee systems administration activities, including configuration, patching, hardening, lifecycle management, and operational readiness of servers, endpoints, and security appliances.
  • Lead and maintain SOC virtualization platforms (VMware, Hyper‑V) and cloud environments (AWS GovCloud, Azure Government).
  • Recommend and implement solutions to address security issues, system outages, and network disruptions.
  • Apply deep technical infrastructure expertise to ensure compliance with service-level agreements (SLAs) and operational performance metrics.
  • Lead or participate in security tests, evaluations, studies, and experiments that directly impact SOC readiness.

Engineering Governance & Documentation

  • Develop, maintain, and enforce SOC engineering SOPs, runbooks, knowledge base content, and technical documentation.
  • Conduct technical and management briefings for senior leadership, government stakeholders, and program management.
  • Maintain a centralized service catalog leveraging ITIL practices to improve delivery, accountability, and efficiency.

Team Management & Staffing

  • Lead, supervise, and mentor systems administrators, network engineers, and SOC engineering personnel.
  • Manage shift coverage, scheduling, on‑call rotations, contingency plans, and surge support for a 24x7x365 environment.
  • Provide hands‑on engineering support during staffing gaps or high-demand events.
  • Develop staffing and continuity plans for weather events, absences, emergencies, and other mission‑impacting situations.

Cross‑Functional Coordination

  • Integrate and sustain SOC security tools including SIEM, IDS/IPS, EDR/XDR, firewalls, proxies, and logging solutions.
  • Coordinate with SOC Analysts, Incident Responders, and Threat Intelligence teams to ensure engineering infrastructure meets mission requirements.
  • Collaborate with system owners, IT teams, and stakeholders to assess cybersecurity needs and translate them into actionable solutions.
  • Facilitate working groups to identify issues, define requirements, and prioritize technical improvements.

Operational Excellence & Compliance

  • Manage asset inventory, capacity planning, and technology refresh cycles for all SOC engineering assets.
  • Support Continuity of Operations (COOP) planning and execution for critical SOC infrastructure.
  • Interface with Contracting Officer Representatives (CORs), program managers, and technical leads on engineering matters.
  • Ensure compliance with NIST SP 800‑53, FISMA, DISA STIGs, DoS policies, and O&M contractual requirements.
  • Oversee daily operations ensuring system availability, security, and operational readiness.
  • Coordinate remediation activities supporting Authority to Operate (ATO) compliance across multiple networks and classifications.

Incident Response & Operational Reporting

  • Provide leadership during high‑severity cybersecurity incidents, including response coordination, client communication, and recovery.
  • Lead after‑action reviews, ensuring corrective actions are documented, assigned, tracked, and completed.
  • Monitor global infrastructure for vulnerabilities, disruptions, performance issues, and operational risks.
  • Coordinate with third‑party providers to resolve failures, elevate critical issues, and minimize downtime.
  • Oversee patching and vulnerability remediation across multiple enclaves and security levels.
  • Monitor incident, request, change, and problem management processes to identify trends and improve service delivery.
  • Identify opportunities to automate recurring cybersecurity tasks such as reporting, ticket validation, policy enforcement, monitoring, and patching.
  • Audit ServiceNow tickets to ensure accuracy, completeness, and compliance.
  • Track key cybersecurity metrics, SLAs, performance indicators, and operational trends.
  • Ensure quality, accuracy, and timely delivery of all cybersecurity operational products and services.

Additional Responsibilities

  • Maintain operational readiness plans, escalation procedures, contact rosters, and continuity documentation.
  • Drive continual service improvement across engineering, operations, monitoring, and support functions.
  • Provide guidance and mentorship to engineering leads, analysts, and O&M support personnel.
  • Perform additional cybersecurity operations and service‑management duties as assigned.

#DSCM

Qualifications

Minimum Qualifications Are:

  • Bachelor's degree in Computer Science, Mathematics, Physics, Engineering, Information Technology, or other related scientific or technical discipline.
  • Four (4) additional years of experience may be substituted in lieu of the bachelor's degree requirement.
  • 12 years of experience in IT, cybersecurity, and/or projects related to critical network infrastructure protection.
  • Minimum of five (5) years of experience in IT cloud‑based security infrastructure protection.
  • Minimum of five (5) years of experience in IT infrastructure support. Demonstrated oral and written communications skills.
  • Minimum of eight (8) years of specialized experience that is current in cybersecurity system or solution design, engineering, evaluation, integration, and/or deployment. Demonstrated ability to provide cybersecurity guidance at the authoritative level.
  • Systems: Demonstrated hands‑on experience administering Windows Server and/or Linux/Unix environments in an enterprise or government setting, including Active Directory, Group Policy, DNS, DHCP, and PKI.
  • Network:Demonstrated experience designing, configuring, and troubleshooting physical and virtual network infrastructure, including routing protocols (BGP, OSPF), switching, firewalls, load balancers, and VPN technologies.
  • Virtualization & Cloud:Demonstrated experience managing virtualization platforms (VMware vSphere/ESXi, Hyper‑V) and government cloud environments (AWS GovCloud, Azure Government, or equivalent).
  • Security Tools:Experience deploying and managing enterprise security tools including SIEM (e.g., Splunk, ArcSight, Microsoft Sentinel), IDS/IPS, EDR/XDR, and network monitoring platforms.
  • Must either possess and maintain, or obtain prior to starting date, one of the following professional certifications: ITIL Foundation (or higher).
  • Demonstrated technical task management and supervisory experience, including shift scheduling and personnel management in a 24x7 operational environment.
  • Experience managing cybersecurity or information assurance support programs of similar size, complexity, and scope as the DSCM Program.
  • Experience managing 24x7x365 operational environments, including shift rotation planning and surge staffing.
  • Experience in network technology, management, or operations with increasing responsibilities.
  • Experience managing network security monitoring and incident response capability.
  • Experience with IT service management platforms, specifically ServiceNow, including ticket auditing, metrics tracking, and reporting.
  • Demonstrated experience leading after‑action reviews, documenting lessons learned, and driving corrective action to closure.
  • Experience with vulnerability remediation and patch management across multi‑enclave or multi‑classification environments.
  • U.S. citizenship is required.
  • Active Top Secret security clearance.

Preferred Qualifications:

  • One or more of the following certifications: CISSP, CISM, CEH, CompTIA Security+, CCNP Security, CCNA, AWS Certified Solutions Architect, Microsoft Certified: Azure Administrator, VMware VCP, or GIAC GCED/GCIA/GCIH.
  • Experience supporting U.S. Department of State or other federal civilian agency IT/cybersecurity programs.
  • Familiarity with DoS IT Security policies, FISMA reporting requirements, and ATO/RMF processes.
  • Experience with Zero Trust Architecture (ZTA) design and implementation.
  • Experience with SD-WAN, MPLS, and global WAN environments supporting diplomatic or government missions.
  • Deep familiarity with ITIL service management practices, including service catalog design, continual service improvement, and ITSM toolset implementation (e.g., ServiceNow).
  • Prior experience in a SOC leadership role with direct responsibility for engineering infrastructure and O&M contractual performance.
  • Experience developing and managing centralized knowledge bases, runbook libraries, and lessons‑learned repositories.
  • Experience with process automation tools and scripting (e.g., Python, PowerShell, Ansible, PowerAutomate ) to reduce manual operational burden.
Peraton Overview

Peraton is a next‑generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
#J-18808-Ljbffr

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017