Unknown Company

NCO Technical Lead

washington, dc • Posted 4 days ago
Onsite Contract IT & Technology

Responsibilities

  • Provide day-to-day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions.
  • Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination.
  • Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems.
  • Produce actionable intelligence products that inform assessment priorities and defensive posture decisions.
  • Coordinate incident response activities when potential security events are identified.
  • Ensure response actions follow established procedures and are documented.
  • Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues.
  • Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks.
  • Brief FAA leadership on threat trends and recommended defensive actions.
  • Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape.
  • Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols.
  • Manage and oversee contractor staff performing NCO functions.
  • Ensure personnel maintain required qualifications and training.

Requirements

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution
  • At least fifteen (15)+ years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions.
  • At least 2 years of recent relevant experience (performed within the last 3 years).
  • Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment.
  • Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products.
  • Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools.Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi-segment network environments.
  • Candidate must have the ability to obtain and maintain a Public Trust Active Secret clearance preferred
  • Security certification such as CISSP, CISM, or CASP required
  • GCIH (GIAC Certified Incident Handler) or GCTI (GIAC Cyber Threat Intelligence) strongly preferred
  • GCFA, GNFA, or GCIA preferred for forensics/network analysis depth
  • CND, CNDA, GDAT, GDSA, GCED, GCFA are directly relevant

#J-18808-Ljbffr
Back to Job Search