yoinka

NOC/SOC Lead

Leidos

Hampton, VASeniorH-1B sponsor companyClearance required
Sign in to applyVerified 3h ago
Location
Hampton, VA
Work model
On-Site
Level
Senior
H-1B history
26 approvals (FY2023)
Posted
Sep 18, 2026

Skills

Cybersecurity

About this role

The Defense Sector at Leidos is seeking a cleared NOC/SOC Lead to direct combined network and security operations supporting Department of Defense (DoD) information systems, with primary emphasis on the Risk Management Framework (RMF) and the Authorization to Operate (ATO) lifecycle. This individual will lead operations staff across monitoring, incident response, and vulnerability management while ensuring daily operations produce the evidence, compliance posture, and continuous monitoring outputs required to obtain and sustain system authorizations. The NOC/SOC Lead will serve as the operational bridge between engineering teams, ISSMs/ISSOs, and the Authorizing Official (AO). Roles and Responsibilities: RMF & ATO Lifecycle Lead operational support for all RMF steps, from categorization and control selection through assessment, authorization, and continuous monitoring. Coordinate with ISSMs/ISSOs to build, update, and maintain ATO packages in eMASS, ensuring artifacts reflect the current operational state of the system. Own the POA&M process for operations-related findings: track remediation, validate closure evidence, and escalate overdue items. Prepare operations teams for ATO assessments, reauthorizations, and cyber inspections (e.g., CCORI), and lead the remediation of resulting findings. Assess the security impact of proposed changes and ensure Configuration Control Board (CCB) decisions are reflected in authorization documentation. Continuous Monitoring & Compliance Execute the system ConMon strategy, ensuring scheduled vulnerability scans, STIG checks, and audit log reviews are completed and documented. Oversee ACAS scanning cadence and vulnerability remediation timelines in accordance with IAVM, TASKORD, and OPORD directives. Produce compliance metrics and risk posture reporting for government leadership and the AO. Operations Leadership Direct day-to-day NOC and SOC operations, including network health monitoring, security event triage, and service restoration. Lead incident response activities, coordinate with the CSSP, and ensure timely and accurate incident reporting. Develop and maintain SOPs, runbooks, shift turnover procedures, and escalation matrices. Supervise, schedule, and mentor NOC/SOC analysts and technicians; identify training needs and support staff certification compliance. Coordination & Governance Serve as the primary operations liaison to ISSMs, ISSOs, SCAs, engineering teams, and government stakeholders. Participate in CCB meetings and security reviews, representing operational risk and supportability considerations. Drive continuous improvement of operational processes, tooling, and automation to reduce compliance burden and response times.

Required Qualifications

Clearance: US Citizen with at least an active Top Secret clearance and the ability to obtain a SCI prior to your start date.

Education

Bachelor’s Degree with 12+ years of experience or a Master’s degree with 10+ years of experience. Additional experience may be considered in lieu of a degree. Certifications: DoD 8570/8140 IAT Level III or IAM Level II certification.

Experience

10+ years of combined IT/IS experience, including substantial hands-on RMF and ATO work and at least 3 years leading cybersecurity operations teams. RMF & ATO Expertise: Thorough working knowledge of DoDI 8510.01 (RMF for DoD Systems), NIST SP 800-37, and NIST SP 800-53 security and privacy controls. Proven experience developing and maintaining ATO packages in eMASS, including System Security Plans (SSPs), control implementation statements, and artifacts. Demonstrated ability to manage Plans of Action and Milestones (POA&Ms), risk acceptance documentation, and continuous monitoring (ConMon) strategies. Experience supporting ATO assessments, reauthorizations, and Security Control Assessor (SCA) validation activities. Operations Expertise: Experience with enterprise monitoring and SIEM platforms and incident response workflows. Hands-on

Listing verified 3h ago. Applications go through the company's official careers site.

← Back to Yoinka

NOC/SOC Lead at Leidos, Hampton, VA | Yoinka