Provide day-to-day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions.
Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination.
Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems.
Produce actionable intelligence products that inform assessment priorities and defensive posture decisions.
Coordinate incident response activities when potential security events are identified.
Ensure response actions follow established procedures and are documented.
Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues.
Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks.
Brief FAA leadership on threat trends and recommended defensive actions.
Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape.
Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols.
Manage and oversee contractor staff performing NCO functions.
Ensure personnel maintain required qualifications and training.
Requirements
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
At least fifteen (15)+ years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions.
At least 2 years of recent relevant experience (performed within the last 3 years).
Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment.
Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products.
Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools.Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi-segment network environments.
Candidate must have the ability to obtain and maintain a Public Trust Active Secret clearance preferred
Security certification such as CISSP, CISM, or CASP required