NOC/SOC Lead

Leidos Holding$116K — $210K *
Aerospace & Defense
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Active Top Secret clearance with SCI eligibility required.
  • Bachelor’s Degree with 12+ years of experience or Master’s with 10+ years. Relevant experience can potentially substitute for education.
  • DoD 8570/8140 IAT Level III or IAM Level II certification needed.
  • 10+ years of IT/IS experience with significant RMF and ATO experience, including at least 3 years in a leadership role.
  • Proven expertise in managing ATO packages in eMASS and familiarity with DoDI RMF guidelines.

Responsibilities

  • Lead and manage all aspects of the RMF process and ATO lifecycle.
  • Coordinate with security officials to ensure ATO packages are up to date.
  • Oversee the remediation of operations-related findings and validate closure evidence.
  • Prepare teams for ATO assessments and lead remediation efforts based on findings.
  • Execute continuous monitoring strategies, including vulnerability scans and compliance checks.
  • Ensure effective incident response and coordination with relevant security teams.
  • Supervise NOC/SOC staff, providing mentorship and identifying training needs.

Benefits

  • Comprehensive healthcare coverage options.
  • 401(k) retirement plan with company match.
  • Generous paid time off and holiday schedule.
  • Opportunities for professional development and training.
  • Support for certification maintenance and training costs.
Full Job Description

The Defense Sector at Leidos is seeking a cleared NOC/SOC Lead to direct combined network and security operations supporting Department of Defense (DoD) information systems, with primary emphasis on the Risk Management Framework (RMF) and the Authorization to Operate (ATO) lifecycle. This individual will lead operations staff across monitoring, incident response, and vulnerability management while ensuring daily operations produce the evidence, compliance posture, and continuous monitoring outputs required to obtain and sustain system authorizations. The NOC/SOC Lead will serve as the operational bridge between engineering teams, ISSMs/ISSOs, and the Authorizing Official (AO).

Roles and Responsibilities:

RMF & ATO Lifecycle

  • Lead operational support for all RMF steps, from categorization and control selection through assessment, authorization, and continuous monitoring.
  • Coordinate with ISSMs/ISSOs to build, update, and maintain ATO packages in eMASS, ensuring artifacts reflect the current operational state of the system.
  • Own the POA&M process for operations-related findings: track remediation, validate closure evidence, and escalate overdue items.
  • Prepare operations teams for ATO assessments, reauthorizations, and cyber inspections (e.g., CCORI), and lead the remediation of resulting findings.
  • Assess the security impact of proposed changes and ensure Configuration Control Board (CCB) decisions are reflected in authorization documentation.

Continuous Monitoring & Compliance

  • Execute the system ConMon strategy, ensuring scheduled vulnerability scans, STIG checks, and audit log reviews are completed and documented.
  • Oversee ACAS scanning cadence and vulnerability remediation timelines in accordance with IAVM, TASKORD, and OPORD directives.
  • Produce compliance metrics and risk posture reporting for government leadership and the AO.

Operations Leadership

  • Direct day-to-day NOC and SOC operations, including network health monitoring, security event triage, and service restoration.
  • Lead incident response activities, coordinate with the CSSP, and ensure timely and accurate incident reporting.
  • Develop and maintain SOPs, runbooks, shift turnover procedures, and escalation matrices.
  • Supervise, schedule, and mentor NOC/SOC analysts and technicians; identify training needs and support staff certification compliance.

Coordination & Governance

  • Serve as the primary operations liaison to ISSMs, ISSOs, SCAs, engineering teams, and government stakeholders.
  • Participate in CCB meetings and security reviews, representing operational risk and supportability considerations.
  • Drive continuous improvement of operational processes, tooling, and automation to reduce compliance burden and response times.

Required Qualifications:

  • Clearance: US Citizen with at least an active Top Secret clearance and the ability to obtain a SCI prior to your start date.
  • Education: Bachelor’s Degree with 12+ years of experience or a Master’s degree with 10+ years of experience. Additional experience may be considered in lieu of a degree.
  • Certifications: DoD 8570/8140 IAT Level III or IAM Level II certification.
  • Experience: 10+ years of combined IT/IS experience, including substantial hands-on RMF and ATO work and at least 3 years leading cybersecurity operations teams.
  • RMF & ATO Expertise:
    • Thorough working knowledge of DoDI 8510.01 (RMF for DoD Systems), NIST SP 800-37, and NIST SP 800-53 security and privacy controls.
    • Proven experience developing and maintaining ATO packages in eMASS, including System Security Plans (SSPs), control implementation statements, and artifacts.
    • Demonstrated ability to manage Plans of Action and Milestones (POA&Ms), risk acceptance documentation, and continuous monitoring (ConMon) strategies.
    • Experience supporting ATO assessments, reauthorizations, and Security Control Assessor (SCA) validation activities.
  • Operations Expertise:
    • Experience with enterprise monitoring and SIEM platforms and incident response workflows.
    • Hands-on familiarity with DoD compliance tooling, including ACAS/Nessus, STIG Viewer, SCAP Compliance Checker, and Evaluate-STIG.
    • Working knowledge of DoD incident handling and reporting requirements.
  • Leadership: Demonstrated ability to supervise multi-shift operations staff, manage escalations, and communicate risk clearly to technical and senior government audiences.

Preferred Qualifications:

  • Clearance: US Citizen with an active TS/SCI
  • RMF Certification: ISC2 CGRC or equivalent governance, risk, and compliance credential.
  • CSSP Certification: DoD 8570/8140 CSSP Analyst or Incident Responder certification (e.g., CySA+, GCIH, GCIA).
  • Classified Authorization: Experience authorizing classified systems under ICD 503 (IC) or the Joint SAP Implementation Guide (JSIG).
  • Continuous ATO: Exposure to continuous ATO (cATO) initiatives, DevSecOps pipelines, or automated control inheritance.
  • Zero Trust: Familiarity with the DoD Zero Trust Strategy and mapping ZT capabilities to RMF controls.
  • Endpoint & Security Tools: Experience with Trellix/HBSS, Tanium, or comparable endpoint security and asset management platforms.
  • ITSM: Experience with ITIL-based service management and ticketing platforms.

DABAOPP1



Original Posting:
September 18, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $116,350.00 - $210,325.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos Holding

Leidos Holding Careers

Joining Leidos Holding presents an unparalleled opportunity to advance one's career with a leader in innovation and technology. The company offers a plethora of job opportunities aimed at fostering professional growth and development in a diverse and inclusive environment.

Explore Career Opportunities

Leidos Holding is actively seeking skilled professionals who are passionate about leveraging their expertise to drive innovation and leadership in their fields. With a variety of open positions, Leidos Holding provides a platform for individuals to challenge themselves in a dynamic work environment.

Innovation and Professional Growth

At Leidos Holding, innovation is at the core of everything they do. Employees are encouraged to think creatively and push boundaries. The company supports this drive for innovation through comprehensive professional development and diversity training programs that are designed to enhance skills and foster leadership.

Commitment to Diversity and Inclusion

Leidos Holding is committed to creating a workplace where diversity is not only recognized but celebrated. With a culture that values and promotes diversity, Leidos Holding ensures that all team members have the opportunity to contribute, learn, and grow.

Internship Programs

For those starting their career, Leidos Holding offers internship programs that provide a robust foundation in the industry. Internships are a great way to develop essential skills, gain valuable work experience, and build professional networks.

Benefits and Culture

Employees at Leidos Holding enjoy a range of benefits designed to support their professional and personal lives. The company culture is built on a foundation of respect and integrity, providing a supportive and collaborative environment where every team member is valued.

Join the Team

Leidos Holding is hiring! Explore job opportunities that match your skills and interests. Leidos Holding looks for driven, curious, and innovative individuals to join their team. Positions are available across various disciplines and experience levels.

Stay Connected

Stay informed with the latest career tips, industry insights, and company news from Leidos Holding. Subscribe to receive updates and be the first to know about new job opportunities, company developments, and more.

Prepare for Your Interview

To prepare for an interview at Leidos Holding, candidates should familiarize themselves with the company's missions and values, update their resumes, and be ready to discuss how their background and skills align with the position they are applying for.

Networking and Career Advancement

Leidos Holding encourages its employees to engage in networking within the company to discover new opportunities for career advancement. The leadership team at Leidos Holding is dedicated to supporting employees in their career paths with ample opportunities for networking and growth.

Explore Leidos Holding Jobs and Careers

Discover the exciting career opportunities at Leidos Holding today. With a commitment to employee growth, innovation, and diversity, Leidos Holding is the perfect place to advance your career. Check out the latest job listings and find your perfect fit at Leidos Holding.

SEARCH LEIDOS HOLDING JOBS

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts and insider tips tailored to your preferences from Leidos Holding. See what exciting and rewarding opportunities await in your professional journey.
Learn more about Leidos Holding

Similar Jobs

More Jobs at Leidos Holding

More Aerospace & Defense Jobs

Find similar NOC/SOC Lead jobs: