Demo

Security Operations Center Technical Lead

Invictus International Consulting, LLC
Colorado, CO Full Time
POSTED ON 8/29/2026
AVAILABLE BEFORE 8/28/2031

Title: Security Operations Center Technical Lead

Location: Colorado Springs, CO

Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph

 

Responsibilities:

  • Serve as the senior technical authority for SOC watch operations, cyber defense analysis, threat hunting, incident response, and operational cyber risk supporting the establishment and maturation of a new DoD SOC
  • Lead the most complex cyber defense investigations, incident-response activities, threat-hunting campaigns, and exposure assessments while providing technical direction when scope, impact, evidence, or response options are uncertain
  • Perform advanced analysis of host and network telemetry, firewall and IDS/IPS data, authentication activity, endpoint data, intrusion artifacts, vulnerabilities, configurations, and other relevant security evidence
  • Establish and continuously improve SOC investigative methodologies, triage standards, severity and escalation criteria, evidence requirements, incident workflows, threat-hunting processes, case-quality standards, and shift-turnover practices
  • Serve as the highest-level operational escalation point for SOC personnel and mentor senior and developing analysts through complex investigations, threat hunts, exercises, and defensive activities
  • Lead advanced threat-hunting campaigns based on threat intelligence, adversary TTPs, mission priorities, incidents, environmental changes, and identified detection gaps
  • Apply MITRE ATT&CK, threat intelligence, network forensics, host analysis, vulnerability context, adversary analysis, and threat-informed defense techniques to complex investigations and proactive defensive operations
  • Establish methodologies for correlating vulnerability, asset, configuration, network reachability, system criticality, security-control, threat, and incident data to identify and prioritize operational cyber risk
  • Lead complex cyber exposure and impact assessments, including exploitation scenarios, attack paths, affected-system analysis, compensating controls, and risk-informed courses of action
  • Coordinate significant incidents, cyber findings, and operational risks with government stakeholders, ISSOs/ISSMs, system owners, administrators, engineers, incident-response organizations, and other agencies as required
  • Partner with cybersecurity engineering teams to translate operational requirements into actionable SIEM/SOAR, network monitoring, endpoint, telemetry, analytics, enrichment, automation, and detection capabilities
  • Identify systemic visibility, detection, tooling, workflow, exposure, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
  • Lead development and validation of SOPs, runbooks, incident-response and threat-hunting playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions
  • Provide senior technical guidance to SOC leadership through risk assessments, threat assessments, metrics, briefings, and recommendations addressing watch readiness, threat activity, high-risk exposures, capability gaps, remediation priorities, and defensive improvements

 

Requirements:

  • Bachelor's degree in a relevant discipline; four additional years of relevant experience may be substituted in lieu of a degree
  • Minimum 8 years of directly related cybersecurity experience
  • Must possess a DoD 8570 IAT Level II or IAM Level II certification
  • Experience supporting DoD or Intelligence Community environments is desired
  • Expert-level, hands-on experience in SOC operations, cyber defense analysis, incident investigation, incident response, threat hunting, adversary analysis, or closely related cybersecurity operations
  • Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, threat-hunting methodologies, incident workflows, or analyst qualification/training programs
  • Expert knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, adversary TTPs, threat intelligence, vulnerability/exposure management, and threat-informed defense
  • Strong knowledge of MITRE ATT&CK and experience operationalizing threat intelligence in SOC, threat-hunting, or cyber defense activities
  • Demonstrated experience correlating vulnerability, asset, configuration, threat, incident, and security-control data to assess operational risk and prioritize remediation or defensive actions
  • Experience with SIEM/SOAR, detection engineering, network-security monitoring, endpoint security, vulnerability management, asset discovery, and continuous monitoring capabilities
  • Experience with ACAS/Tenable, runZero or comparable exposure/asset-discovery tools, DoD STIG/STIG Viewer, SCAP, POA&M processes, and integration of SOC/incident-response findings with ISSO/ISSM or RMF functions is highly desired
  • Experience helping establish, transform, or mature a SOC, CSIRT, threat-hunting, or cyber defense capability is highly desired
  • TS/SCI with the ability to obtain and maintain a CI polygraph

 

 

 

Equal Opportunity Employer/Veteran/Disabled

Salary : $200,000 - $230,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security Operations Center Technical Lead?

Sign up to receive alerts about other jobs on the Security Operations Center Technical Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$100,915 - $131,460
Income Estimation: 
$121,073 - $161,329
Income Estimation: 
$142,618 - $183,267
Income Estimation: 
$173,252 - $220,888
Income Estimation: 
$115,647 - $153,495
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Invictus International Consulting, LLC

  • Invictus International Consulting, LLC Washington, DC
  • Title: Business Intelligence Data Visualization Location: National Capital Region Clearance: TS/SCI with CI Poly Responsibilities: As part of a multidiscip... more
  • Just Posted

  • Invictus International Consulting, LLC Omaha, NE
  • Title: Counterintelligence Specialist Location: Omaha, NE Clearance: TS/SCI Responsibilities: Identifies, monitors, and assesses foreign intelligence effor... more
  • Just Posted

  • Invictus International Consulting, LLC Washington, DC
  • Title: SATCOM RF Engineer IV Location: Washington, D.C. Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details: Experience in... more
  • 1 Day Ago

  • Invictus International Consulting, LLC Hawaii, HI
  • Title: Network Administrator Location: Pearl Harbor, HI Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph Job Details: Responsible f... more
  • 4 Days Ago


Not the job you're looking for? Here are some other Security Operations Center Technical Lead jobs in the Colorado, CO area that may be a better fit.

  • Global Resource Solutions, Inc. Colorado, CO
  • Global Resource Solutions, Inc. (GRS) is seeking an enthusiastic, motivated, detail orientated, and talented individual for the position of Security Operat... more
  • 18 Days Ago

  • P-11 SECURITY Colorado, CO
  • Description P-11 Security, based in Southern California, is a certified Economically-Disadvantaged Women-Owned Small Business (EDWOSB) 8(a) with over 11 ye... more
  • 13 Days Ago

AI Assistant is available now!

Feel free to start your new journey!