Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

SOC CTIC Lead - SME

ECS

SOC CTIC Lead - SME

ECS is seeking a SOC CTIC Lead - SME to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this role, you will support Task 3 — Cybersecurity Operations Support by conducting and leading cyber incident response activities for the ARNG enterprise, including evidence collection, forensic acquisition, analysis of host and network artifacts, malware triage, root-cause analysis, containment support, recovery validation, and incident documentation. The position works as part of ENOCS' broader cybersecurity operations construct, coordinating with SOC analysts, Cyber Incident Response Team (CIRT) personnel, watch officers, engineers, and service owners to strengthen defensive cyberspace operations across classified and unclassified environments.

This role directly supports ENOCS' mission to defend the DoDIN-Army-NG area of responsibility serving more than 120,000 users and approximately 141,000 endpoints across roughly 2,800 sites in 54 states and territories. The SOC CTIC Lead - SME contributes to cybersecurity operations that enable Title 10 and Title 32 missions, mobilization readiness, domestic emergency response, and classified SIPRNet operations by helping detect, investigate, contain, and document cyber incidents. The position operates within an environment that uses USIEM analytics, EDR, IDS/IPS, SOAR, Zeek metadata, Sysmon-informed MITRE ATT&CK analysis, and eMASS-supported continuous monitoring, while coordinating with organizations such as the NETCOM Global Cyber Center and DISA DCDC to maintain enterprise cyber freedom of action.

Please Note: This position is contingent upon contract award.

Responsibilities
  • Conduct cyber incident response investigations through evidence collection, forensic acquisition, and analysis of host and network artifacts in support of ARNG defensive cyberspace operations.
  • Perform malware triage and root-cause analysis to determine incident scope, identify affected systems, and support containment and recovery actions.
  • Document investigative actions, technical findings, and incident outcomes in incident tracking and case management systems to support reporting, governance, and after-action requirements.
  • Support recovery validation by verifying remediation actions, confirming restoration status, and helping ensure incidents are fully resolved before closure.
  • Coordinate incident handling activities with SOC Tier 2 personnel, CIRT, watch officers, problem and change processes, and other cybersecurity operations stakeholders as required.
  • Leverage security data and enterprise monitoring outputs from environments such as USIEM, EDR, IDS/IPS, and related analytics to support investigation, correlation, and incident determination.
  • Apply MITRE ATT&CK-informed analysis and available telemetry such as Sysmon and Zeek metadata to help identify adversary tactics, techniques, and procedures and improve incident understanding.
  • Support coordination and reporting associated with incidents affecting ARNG classified and unclassified enclaves, including environments tied to SIPRNet operations and broader DoDIN-A(NG) mission support.
  • Assist with post-incident reporting and lessons learned documentation to strengthen continuous monitoring, improve defensive measures, and inform follow-on cyber defense activities.
  • Coordinate, as needed, with external mission partners and cyber organizations identified in ENOCS operations, including the NETCOM Global Cyber Center and DISA DCDC, in accordance with incident handling procedures.
Required Qualifications

U.S. Citizenship is required

Security Clearance: Secret Eligible

Required Certifications: DCWF Work Role 531-Cyber Defense Incident Responder — Intermediate proficiency; must hold ONE OR MORE of the following: CEH(P), ECIH, GRID, RCCE Level 1, CBROPS, CCSP, CEH, Cloud+, FITSP-O, GCED, GCIH, GSEC, PenTest+, Security+

Experience: 7+ years of experience in cybersecurity

Education: Bachelors degree or higher in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering

  • Demonstrated experience performing evidence collection, forensic acquisition, and analysis of host and network artifacts during cyber incident investigations.
  • Experience supporting malware triage, technical root-cause analysis, containment actions, and recovery validation in operational cybersecurity environments.
  • Ability to produce complete, accurate, and timely incident documentation, technical findings, and after-action reporting aligned to continuous monitoring and cybersecurity operations requirements.
  • Experience working within enterprise cybersecurity operations supporting incident escalation, case management, and coordination across analysts, responders, engineers, and service owners.
  • Familiarity with cybersecurity monitoring and analysis environments using technologies and data sources referenced in ENOCS operations, including USIEM, EDR, IDS/IPS, and related security telemetry.
  • Experience supporting investigations and reporting in environments governed by DoD and ARNG cybersecurity policy, including classified and unclassified operational contexts.
  • Ability to analyze security events and artifacts to determine incident scope, affected assets, and recommended response actions across large enterprise environments.
  • Experience contributing to lessons learned, remediation follow-up, and continuous improvement activities after cyber incident response actions.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the SOC CTIC Lead - SME in Fairfax, VA vacancy
  • ECS is seeking a SOC CTIC Lead - SME to support the Army National Guard’s cybersecurity operations. This role involves conducting cyber incident investigations, performing malware triage, and documenting findings. Candidates should have 7+ years of cybersecurity experience... 
    Suggested
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...SOC CIRT Team Lead - SME ECS is seeking a SOC CIRT Team Lead - SME to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This position supports Task 3 — Cybersecurity Operations Support — by leading cyber... 
    Suggested
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...SOC Team Lead - Senior ECS is seeking a SOC Team Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations...  ...monitoring coverage and alert fidelity; and coordinating with SOC, CTIC, CDAP, and infrastructure teams to maintain continuous... 
    Suggested
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  • Product Manager SME - Endpoint Security Solutions Lead Everforth ECS is seeking a Product Manager SME to work in the National Capital Region covering the...  ...Response (SOAR) platforms, Security Operations Center (SOC) monitoring workflows, and supply chain risk management... 
    Suggested
    Contract work
    Local area

    ECS

    Fairfax, VA
    11 hours ago
  •  ...T&E Gate Lead/Evaluation Science Lead Sme Everforth ECS is seeking a T&E Gate Lead/Evaluation Science Lead SME to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. This position is contingent upon contract award. The War Data... 
    Suggested
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...SOC Vulnerability Management AESS Lead - Senior ECS is seeking a SOC Vulnerability Management AESS Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. Supporting Task 3 — Cybersecurity Operations... 
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...Devsecops/Supply Chain Lead Sme Everforth ECS is seeking a DevSecOps/Supply Chain Lead SME to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. This position is contingent upon contract award. The War Data Platform (WDP) is a... 
    Contract work

    ECS

    Fairfax, VA
    2 days ago
  •  ...SOC Vulnerability Management ACAS Lead - Senior ECS is seeking a SOC Vulnerability Management ACAS Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this senior Task 3 Cybersecurity Operations... 
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...SOC Vulnerability Management Team Lead - Senior ECS is seeking a SOC Vulnerability Management Team Lead - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this Task 3 role, the selected candidate... 
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...RMF Team Lead - SME ECS is seeking a RMF Team Lead - SME to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This position supports Task 3 — Cybersecurity Operations Support, delivering RMF-aligned cybersecurity... 
    Contract work
    Remote work

    ECS

    Fairfax, VA
    1 day ago
  •  ...Enterprise Vulnerability Management Lead SME Everforth ECS is seeking an Enterprise Vulnerability Management Lead SME to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. The War Data Platform (WDP) is a key initiative within... 

    ECS

    Fairfax, VA
    2 days ago
  •  ...SOC Technician (Shift 3 Lead) - Senior ECS is seeking a SOC Technician (Shift 3 Lead) - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this role, the selected candidate supports Task 3 —... 
    Contract work
    Shift work

    ECS

    Fairfax, VA
    1 day ago
  •  ...SOC Technician (Shift 1 Lead) - Senior ECS is seeking a SOC Technician (Shift 1 Lead) - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. In this role, you will support Task 3 — Cybersecurity Operations... 
    Contract work
    Shift work

    ECS

    Fairfax, VA
    1 day ago
  •  ...SOC Technician (Shift 2 Lead) - Senior ECS is seeking a SOC Technician (Shift 2 Lead) - Senior to support the Army National Guard (ARNG) Enterprise Network Operations and Cybersecurity Support (ENOCS) program. This role supports Task 3 — Cybersecurity Operations Support... 
    Contract work
    Shift work

    ECS

    Fairfax, VA
    1 day ago
  • $22.88 per hour

     ...team of first-class Security professionals, and start your career with SecTek today! We are currently seeking a Full-Time Unarmed Lead Supervisor for our client. Job Skills / Requirements Our Assistant Supervisors are responsible for providing quality... 
    Full time
    Contract work
    Part time
    Shift work
    Night shift
    Weekend work

    SecTek

    McLean, VA
    2 days ago
  •  ...SOC Security Engineering Team Lead - Senior ECS is seeking a SOC Security Engineering Team Lead - Senior to support the Army National Guard (ARNG...  ...changes and remediation actions; and coordinating with SOC, CTIC, CDAP, and infrastructure teams to sustain continuous... 
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  •  ...stakeholders to aid in developing and implementing national policies, strategies, and doctrine. Summary: The Asset Management Lead/SME serves as the subject-matter expert responsible for the execution and oversight of the full asset lifecycle, ensuring inventory... 
    Contract work

    Goldbelt

    Alexandria, VA
    1 day ago
  •  ...Everforth ECS is seeking a Product Manager SME to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax...  ...leaders, and operational analysts. • The Cloud Security Lead SME is a senior subject matter expert responsible for the enterprise... 
    Contract work

    ECS Limited

    Falls Church, VA
    2 days ago
  •  ...Job Description: Crimson Phoenix seeks exceptionally qualified individuals to serve as an Intelligence Discipline Lead Subject Matter Expert (IDL SME) to support USSOCOM. IDL SME provides support to assist USSOCOM Staff in the conduct of targeting analysis and operations... 
    Contract work
    For contractors
    Overseas

    Crimson Phoenix

    Arlington, VA
    4 days ago
  •  ...Everforth ECS is seeking a Product Manager SME to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon contract award. The War Data Platform (WDP) is a key initiative within the U.S.... 
    Contract work

    ECS Limited

    Falls Church, VA
    2 days ago
  •  ...Full-Time/Part-Time Full-Time Description RiVidium is seeking a SOC Shift Lead to support our planned MODES III team supporting Military Community and Family Policy (MC&FP). This role supports IT, Cybersecurity, and Data Operations - Core Operations and... 
    Full time
    Contract work
    Part time
    Shift work
    Night shift

    Rividium Inc

    Alexandria, VA
    11 hours ago
  •  ...Training Support Manager - Sme ECS is seeking a Training Support Manager - SME to support the ARNG ENOCS program by providing strategic...  ..., course completion metrics, and program effectiveness. Lead the development and implementation of immersive cybersecurity training... 
    Contract work

    ECS

    Fairfax, VA
    1 day ago
  • A cybersecurity firm located in Falls Church, Virginia, seeks a Security Operations Center (SOC) Lead to manage daily security operations, coordinate incident response activities, and oversee SOC analysts. Candidates should have over 12 years of experience in cybersecurity... 

    ZTI Solutions LLC

    Falls Church, VA
    3 days ago
  •  ...technology solutions company seeks an Informatica Subject Matter Expert (SME) in Fairfax, Virginia. This role involves serving as a technical...  ...and a Bachelor’s degree in a relevant field. Key duties include leading platform upgrades and advising on data governance solutions.... 

    Gtscts

    Fairfax, VA
    11 hours ago
  •  ...This is a hybrid position with several days onsite over the course of a month. We are seeking a Fraud Analytics Subject Matter Expert (SME) to provide deep domain expertise supporting fraud detection and identity theft analytics initiatives. This role guides analytical... 
    Full time
    Work at office
    Local area
    Remote work

    Elder Research Inc.

    Arlington, VA
    4 days ago
  • A leading technical services firm in Fairfax, Virginia is seeking an experienced Informatica Subject Matter Expert (SME). This critical role involves providing technical leadership for data integration solutions and requires strong expertise in Informatica PowerCenter and... 

    Government Technical Services Corporation

    Fairfax, VA
    4 days ago
  •  ...Chief Cloud Architect and Lead Infrastructure SME (CCALIS) **Location**: Remote with potential travel **Clearance Requirement**: Tier 5 Favorable Adjudication **Certification**: One of CASP+, CISSP, ISSAP, GCSA, etc. (Required) About Plateau Group... 
    Local area
    Remote work

    Plateau Software, Inc.

    Fairfax, VA
    3 days ago
  •  ...User Interface Subject Matter Expert (SME) / UI Team Lead Nationwide IT Services, NIS, is seeking a User Interface Subject Matter Expert (SME) / UI Team Lead for a potential opportunity to provide technical leadership for the design, development, integration, and support... 
    For contractors
    Work at office

    Nationwide IT Services, Inc.

    Arlington, VA
    1 day ago
  •  ...AI/ML Subject Matter Expert (SME) / Analytics Team Lead Nationwide IT Services, NIS, is seeking an AI/ML Subject Matter Expert (SME) / Analytics Team Lead to provide technical leadership for the design, development, and implementation of advanced analytics, machine... 
    For contractors
    Work at office

    Nationwide IT Services, Inc.

    Arlington, VA
    1 day ago
  • Overview Business Process Technology Subject Matter Expert (SME) / Reporting Team Lead Nationwide IT Services (NIS) is seeking a Business Process Technology Subject Matter Expert (SME) / Reporting Team Lead for a potential opportunity who provides technical and functional... 

    Nationwide IT Services, Inc.

    Arlington, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to SOC CTIC Lead - SME. Be the first to apply!