Bachelor's degree in Computer Science, Cybersecurity, IT, or related STEM field and relevant cybersecurity certification (CISSP, CISM, etc.)
5+ years of experience in cybersecurity, SOC, or cyber incident response
5+ years of experience in detection engineering and automation
Qualified for a DoD 8140 Category E role
Active TS/SCI with CI polygraph
Responsibilities
Manage daily cyber defense tasking across various operational functions
Serve as the primary liaison with military and government counterparts
Maintain a skills matrix for cyber tasking staff and assign tasks accordingly
Oversee 24/7 cyber analysis, incident response, and threat hunting
Guide detection content and identify gaps in coverage
Keep the team trained and ready through exercises and training plans
Brief leadership on operational status and emerging trends
Benefits
Full-time position contingent upon contract award
Opportunity to work in a dynamic threat environment
Engagement with military and government counterparts
Leadership role in a critical cybersecurity program
Access to ongoing training and professional development opportunities
Full Job Description
Title: Defensive Cyber Operations Lead
Location: Chantilly, VA
US Citizenship Required: Yes
Clearance: Active TS/SCI with CI polygraph
Status: Full-time; contingent upon contract award
Job Details:
Invictus is seeking a Defensive Cyber Operations (DCO) Lead to manage daily cyber defense tasking and operational tempo for an enterprise cybersecurity program supporting the NRO. The DCO Lead is the primary liaison between contractor personnel and their military counterparts, keeping coordination seamless and the mission aligned. As a senior technical authority, this role matches personnel skills and certifications to operational requirements and mission priorities, and keeps the team ready for a dynamic threat environment.
Responsibilities:
Manage daily cyber defense tasking across cyber operations, integrated mission defense, cyber readiness, cyber data platform and identity and credentialing functions
Serve as the primary liaison with military and government counterparts; align contractor work with operational priorities
Maintain a skills matrix of cyber tasking staff mapped to DoD 8140 work roles and certifications; assign staff to tasks based on it
Oversee 24/7 cyber analysis, incident response and validation, and intelligence-driven threat hunting
Guide detection content, SIEM/SOAR use and MITRE ATT&CK technique coverage; identify detection gaps and recommend fixes
Keep the team trained and ready through exercises, training plans and cross-training
Brief leadership on operational status, significant incidents and emerging protection, detection and response trends
Requirements:
Bachelor's degree in Computer Science, Cybersecurity, IT or a related STEM field and one of the following: CISSP, CISM, CCISO, GCDA, Security+ CE, CySA+ or equivalent
5+ years of cybersecurity, SOC or cyber incident response experience
5+ years of detection engineering and automation experience
Qualified for a DoD 8140 Category E role (Cyber Workforce Developer 751, Manager or Executive Cyber Leader 901, or IAM Level III)
Active TS/SCI with CI polygraph
Desired Qualifications:
Experience within the NRO and its mission partner community
Demonstrated leadership, management or training experience
Experience leading combined contractor and military cyber defense teams
GIAC incident response or hunting certifications (e.g., GCIH, GCFA, GREM)
Experience with Splunk, SOAR platforms and MITRE ATT&CK-based threat hunting