user avatar

Cyber Incident Response Team (CIRT) Lead

SOSi

Posted today
Top Secret
Unspecified
Unspecified
IT - Security
Ashburn, VA (On-Site/Office)

Company Description

Founded in 1989, SOSi is among the largest private, founder-owned technology and services integrators in the defense and government services industry. We deliver tailored solutions, tested leadership, and trusted results to enable national security missions worldwide.

Job Description

**This position is contingent upon contract award**

SOSi is seeking highly qualified senior professionals to support a DHS enterprise cybersecurity program providing 24/7 Security Operations Center (SOC) services. These roles deliver leadership, operational oversight, and technical expertise across cyber defense, incident response, intelligence, engineering, and modernization activities.

Job Description

Leads the end-to-end incident response function for the DHS enterprise SOC, coordinating triage, containment, eradication, and recovery; drives tool efficacy (SIEM/EDR/IDS/IPS), case management, and communications with stakeholders.

Responsibilities
  • Lead incident detection, analysis, escalation, and coordinated response across SOC towers.
  • Standardize IR runbooks, playbooks, and communications; ensure evidence handling and documentation.
  • Measure and improve MTTA/MTTR; track lessons learned and corrective actions.
  • Ensure IR alignment to DHS/CBP policy and reporting requirements.


Qualifications

  • Education: Bachelor's degree OR 8 years of directly relevant experience in lieu of a degree.
  • Experience: 5+ years across cyber/IR/security engineering/network engineering/architecture (8+ preferred for lead roles).
  • Certifications (Required): CISSP and at least one of GCIA, GCIH, GCFA, GCED; or DoD 8570 IAT Level III equivalent.
  • Technical Proficiency: SIEM, EDR, IPS/IDS, and case management platforms.
  • Clearance: TS, SCI-eligible.


Additional Information

Work Environment
  • Normal office conditions with potential to perform duties in various CONUS locations.
  • Core hours of operation are Monday through Friday, 0600 - 1700.
  • May be requested to work evenings and weekends to meet program and contract needs.

Working at SOSi

All interested individuals will receive consideration and will not be discriminated against for any reason.
group id: 10237746
job ad image
Find SOSi on Social Media
Network Employers
user avatar
About Us
At SOSi every team member is dedicated to the mission. As a company we're committed to our core values of integrity, excellence and collaboration. Our vision inspires our approach. We push the boundaries of what’s possible to protect and solve today’s most complex problems. We invest in our people. We dream big with our solutions and we execute. We foster a culture of collaboration and mentorship matters. We’re purpose-driven and rise to the challenge.
job ad2 image

SOSi Jobs


Job Category
IT - Security
Clearance Level
Top Secret
Employer
SOSi