ECS

SOC CIRT Team Lead - SME

ECS$120K — $150K *
Education, Government & Non-Profit
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • U.S. Citizenship is required.
  • Secret security clearance eligibility.
  • Certifications: Must hold one or more of the following: CFR, CySA+, GCFA, GCIA, GICSP.
  • 12+ years of experience in cybersecurity.
  • Master's degree or higher in relevant fields such as Computer Science or Cybersecurity.
  • Proven leadership in cyber incident response activities such as investigation and recovery.
  • Experience in managing communication and escalation throughout the incident response lifecycle.

Responsibilities

  • Lead cyber incident response actions including investigation, containment, and recovery for ARNG networks.
  • Coordinate Cyber Incident Response Team activities with SOC functions for effective incident management.
  • Manage forensic and malware analysis to assess incident scope and adversary tactics.
  • Oversee incident communication, ensuring timely updates to stakeholders based on severity and impact.
  • Produce incident reports, after-action reviews, and lessons learned to enhance response strategies.
  • Collaborate with military cybersecurity organizations to support incident analysis and remediation efforts.
  • Utilize operational data to influence incident response decisions and improve defenses.

Benefits

  • Opportunity to work in a high-impact, mission-driven environment.
  • Exposure to cutting-edge cybersecurity technologies and methodologies.
  • Collaboration with various military cybersecurity agencies and stakeholders.
  • Engagement with a broad user base and diverse operational settings.
  • Potential for career advancement within a respected defense and security organization.
Full Job Description
Position Summary

ECS is seeking a SOC CIRT Team Lead - SME to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This position supports Task 3 - Cybersecurity Operations Support - by leading cyber incident response activities across the ARNG enterprise and directing investigation, containment, eradication, recovery, reporting, and post-incident analysis. The SOC CIRT Team Lead serves as a senior response lead within ENOCS' broader cybersecurity operations construct, coordinating with SOC monitoring and analysis personnel, forensic and malware analysts, engineers, and compliance/RMF teams to strengthen Defensive Cyberspace Operations - Internal Defensive Measures (DCO-IDM) outcomes across the DoDIN-Army-NG area of responsibility.

This role directly supports a mission environment delivering DoDIN services to more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories, including support to Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations. The SOC CIRT Team Lead operates within a technical environment that includes 24x7x365 SOC operations, Unified Security Information & Event Management (USIEM) analytics, EDR, SOAR, IDS/IPS event integration, DLP/C2C analytics, and coordination with NETCOM Global Cyber Center, DISA DCDC, ARCYBER, USCYBERCOM, RCCs, and other mission stakeholders to ensure timely incident response and continuous improvement of ARNG cyber defenses.

Please Note: This position is contingent upon contract award.

Responsibilities

  • Lead cyber incident response activities by directing investigation, containment, eradication, and recovery actions for security events affecting ARNG classified and unclassified network environments.
  • Coordinate Cyber Incident Response Team activities with SOC monitoring and analysis functions to ensure incidents are properly triaged, escalated, documented, and resolved in accordance with ARNG and DoD cybersecurity policy.
  • Manage forensic and malware analysis efforts to determine incident scope, identify adversary tactics, techniques, and procedures, and support effective remediation and recovery actions.
  • Oversee incident communications and escalation, ensuring timely coordination with internal stakeholders and external organizations as required by severity, mission impact, and reporting criteria.
  • Produce incident reports, after-action reviews, and lessons-learned artifacts that improve detection engineering, response procedures, and continuous monitoring across the ENOCS cyber operations mission set.
  • Coordinate with NETCOM Global Cyber Center, DISA DCDC, ARCYBER, USCYBERCOM, and regional RCC stakeholders, as applicable, to support incident analysis, notification, and remediation activities across the DoDIN-Army-NG AOR.
  • Leverage operational data from USIEM, EDR, IDS/IPS, and related analytics sources to support incident scoping, response decision-making, and post-incident defensive improvements.
  • Ensure required documentation and reporting are completed in support of Task 3 deliverables for cyber incident response and digital media analysis, while maintaining alignment with continuous monitoring and RMF-related evidence needs.
  • Support the refinement of response playbooks, escalation procedures, and threat-informed defensive processes to improve the speed and quality of ARNG incident response operations.


Required Qualifications

U.S. Citizenship is required

Security Clearance: Secret Eligible

Required Certifications: DCWF Work Role 531-Cyber Defense Incident Responder - Advance proficiency; must hold ONE OR MORE of the following: CFR, CySA+, GCFA, GCIA, GICSP

Experience: 12+ years of experience in cybersecurity

Education: Masters degree or higher in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering
  • Demonstrated ability to lead cyber incident response activities spanning investigation, containment, eradication, and recovery.
  • Experience managing incident communications, escalation actions, and required reporting through all phases of the response lifecycle.
  • Experience coordinating forensic analysis and malware analysis activities to support incident scoping, evidence development, and remediation.
  • Ability to produce complete incident documentation, after-action reporting, and lessons-learned artifacts that inform continuous improvement.
  • Experience operating in a 24x7x365 SOC and cyber defense environment supporting enterprise-scale monitoring and response operations.
  • Familiarity with continuous monitoring requirements and maintaining documentation aligned to DoD and ARNG cybersecurity policy.
  • Experience working with enterprise security analytics and response capabilities such as SIEM, EDR, IDS/IPS, and related case management workflows.
  • Ability to coordinate effectively with cyber operations stakeholders, engineers, watch personnel, and leadership across a distributed enterprise environment.

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    Imagery Analyst Supervisor
    $80K — $100K *
    Fairfax, VA 22030 (Fairfax City County)
    Aerospace & Defense
    In-Person
  • ECS
    DevOps Engineer
    $125K — $155K *
    Washington, DC 20011 (District Of Columbia County)
    Information Technology
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Education, Government & Non-Profit
    In-Person

More Education, Government & Non-Profit Jobs

Find similar SOC CIRT Team Lead - SME jobs: