Cybersecurity Operations Lead
Steampunk, Inc. · McLean, VA · 3 wk ago
ManagementFull-time
About the role
We are seeking a Cybersecurity Operations Lead responsible for overseeing enterprise cybersecurity operations, ensuring the continuous protection of information systems through effective security monitoring, vulnerability management, configuration management, asset management, and incident response.
Responsibilities
- Lead day-to-day cybersecurity operations supporting enterprise information systems.
- Manage and mentor cybersecurity operations personnel, providing technical guidance and operational oversight.
- Oversee enterprise vulnerability management activities, including vulnerability identification, prioritization, remediation tracking, reporting, and validation.
- Lead enterprise configuration management efforts to ensure secure system baselines and compliance with security standards.
- Manage enterprise asset management processes to maintain accurate inventories and visibility across physical, virtual, cloud, and hybrid environments.
- Support and oversee security operations center (SOC) activities, including security monitoring, alert triage, threat detection, and response.
- Lead incident response activities in accordance with NIST SP 800-61, coordinating investigation, containment, eradication, recovery, and lessons learned.
- Develop and improve operational playbooks, standard operating procedures, and incident response workflows.
- Integrate and optimize cybersecurity tools to improve operational efficiency, visibility, and detection capabilities.
- Drive security automation initiatives that reduce manual effort and improve operational response times.
- Collaborate with infrastructure, engineering, cloud, networking, and application teams to remediate identified security risks.
- Analyze security metrics and operational trends to identify opportunities for continuous improvement.
- Support federal cybersecurity compliance efforts, including FISMA and NIST security requirements.
- Prepare operational reports, dashboards, and executive briefings on cybersecurity posture, vulnerabilities, incidents, and key performance indicators.
- Support audits, security assessments, and continuous monitoring activities.
- Stay current on emerging threats, vulnerabilities, and industry best practices.
Qualifications
Ability to obtain and maintain a U.S. government Security Clearance. Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field (or equivalent combination of education and experience).
- 7–10 years of experience supporting cybersecurity operations within enterprise environments.
- Minimum of 5 years of experience leading cybersecurity operations teams or technical security personnel.
- 3–5 years of experience supporting Federal cybersecurity programs with experience implementing or supporting FISMA requirements.
- Experience managing enterprise vulnerability management, configuration management, and asset management programs supporting environments with 30,000+ managed assets.
- Experience leading or supporting Security Operations Center (SOC) functions and SIEM operations.
- Experience leading incident response activities utilizing NIST SP 800-61 guidance.
- Experience integrating cybersecurity tools and implementing operational automation to improve security effectiveness.
- Strong understanding of enterprise security technologies, threat detection, vulnerability management platforms, endpoint security, and security monitoring solutions.
- Ability to communicate effectively with technical teams, executive leadership, and government stakeholders.
- Must possess at least one of the following certifications: CISSP, GIAC certification (GCIA, GCIH, GCFA, or equivalent), or CompTIA Security+ CE with demonstrated enterprise cybersecurity operations experience.
Preferred Qualifications
- Experience with SOAR platforms and security orchestration.
- Experience supporting Zero Trust initiatives.
- Experience implementing security automation using scripting or orchestration technologies.
- Experience supporting enterprise continuous monitoring and federal cybersecurity programs.
- Splunk certification.
- ITIL certification.
- AWS Security Specialty, Azure Security Engineer Associate, or comparable cloud security certification.