Leidos logo

NOC/SOC Lead

Leidos
  • Hampton, Virginia
    2 days ago
    Leidos

    Job Description

    The Defense Sector at Leidos is seeking a cleared NOC/SOC Lead to direct combined network and security operations supporting Department of Defense (DoD) information systems, with primary emphasis on the Risk Management Framework (RMF) and the Authorization to Operate (ATO) lifecycle. This individual will lead operations staff across monitoring, incident response, and vulnerability management while ensuring daily operations produce the evidence, compliance posture, and continuous monitoring outputs required to obtain and sustain system authorizations. The NOC/SOC Lead will serve as the operational bridge between engineering teams, ISSMs/ISSOs, and the Authorizing Official (AO).

    Roles and Responsibilities:

    RMF & ATO Lifecycle

    • Lead operational support for all RMF steps, from categorization and control selection through assessment, authorization, and continuous monitoring.
    • Coordinate with ISSMs/ISSOs to build, update, and maintain ATO packages in eMASS, ensuring artifacts reflect the current operational state of the system.
    • Own the POA&M process for operations-related findings: track remediation, validate closure evidence, and escalate overdue items.
    • Prepare operations teams for ATO assessments, reauthorizations, and cyber inspections (e.g., CCORI), and lead the remediation of resulting findings.
    • Assess the security impact of proposed changes and ensure Configuration Control Board (CCB) decisions are reflected in authorization documentation.

    Continuous Monitoring & Compliance

    • Execute the system ConMon strategy, ensuring scheduled vulnerability scans, STIG checks, and audit log reviews are completed and documented.
    • Oversee ACAS scanning cadence and vulnerability remediation timelines in accordance with IAVM, TASKORD, and OPORD directives.
    • Produce compliance metrics and risk posture reporting for government leadership and the AO.

    Operations Leadership

    • Direct day-to-day NOC and SOC operations, including network health monitoring, security event triage, and service restoration.
    • Lead incident response activities, coordinate with the CSSP, and ensure timely and accurate incident reporting.
    • Develop and maintain SOPs, runbooks, shift turnover procedures, and escalation matrices.
    • Supervise, schedule, and mentor NOC/SOC analysts and technicians; identify training needs and support staff certification compliance.

    Coordination & Governance

    • Serve as the primary operations liaison to ISSMs, ISSOs, SCAs, engineering teams, and government stakeholders.
    • Participate in CCB meetings and security reviews, representing operational risk and supportability considerations.
    • Drive continuous improvement of operational processes, tooling, and automation to reduce compliance burden and response times.

    Required Qualifications:

    • Clearance: US Citizen with at least an active Top Secret clearance and the ability to obtain a SCI prior to your start date.
    • Education: Bachelor’s Degree with 12+ years of experience or a Master’s degree with 10+ years of experience. Additional experience may be considered in lieu of a degree.
    • Certifications: DoD 8570/8140 IAT Level III or IAM Level II certification.
    • Experience: 10+ years of combined IT/IS experience, including substantial hands-on RMF and ATO work and at least 3 years leading cybersecurity operations teams.
    • RMF & ATO Expertise:
      • Thorough working knowledge of DoDI 8510.01 (RMF for DoD Systems), NIST SP 800-37, and NIST SP 800-53 security and privacy controls.
      • Proven experience developing and maintaining ATO packages in eMASS, including System Security Plans (SSPs), control implementation statements, and artifacts.
      • Demonstrated ability to manage Plans of Action and Milestones (POA&Ms), risk acceptance documentation, and continuous monitoring (ConMon) strategies.
      • Experience supporting ATO assessments, reauthorizations, and Security Control Assessor (SCA) validation activities.
    • Operations Expertise:
      • Experience with enterprise monitoring and SIEM platforms and incident response workflows.
      • Hands-on familiarity with DoD compliance tooling, including ACAS/Nessus, STIG Viewer, SCAP Compliance Checker, and Evaluate-STIG.
      • Working knowledge of DoD incident handling and reporting requirements.
    • Leadership: Demonstrated ability to supervise multi-shift operations staff, manage escalations, and communicate risk clearly to technical and senior government audiences.

    Preferred Qualifications:

    • Clearance: US Citizen with an active TS/SCI
    • RMF Certification: ISC2 CGRC or equivalent governance, risk, and compliance credential.
    • CSSP Certification: DoD 8570/8140 CSSP Analyst or Incident Responder certification (e.g., CySA+, GCIH, GCIA).
    • Classified Authorization: Experience authorizing classified systems under ICD 503 (IC) or the Joint SAP Implementation Guide (JSIG).
    • Continuous ATO: Exposure to continuous ATO (cATO) initiatives, DevSecOps pipelines, or automated control inheritance.
    • Zero Trust: Familiarity with the DoD Zero Trust Strategy and mapping ZT capabilities to RMF controls.
    • Endpoint & Security Tools: Experience with Trellix/HBSS, Tanium, or comparable endpoint security and asset management platforms.
    • ITSM: Experience with ITIL-based service management and ticketing platforms.

    DABAOPP1

    If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

    Original Posting:

    September 18, 2026

    For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

    Pay Range:

    Pay Range $116,350.00 - $210,325.00

    The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

    Numbers & Facts

    LocationHampton, Virginia
    IndustryEngineering Services
    Company Size10,000 employees or more
    Year Founded1969
    Websitehttp://leidos.com/

    About Company

    Everything we do is built on our commitment to do the right thing for our customers, our employees, and our communities. Learn more about the values and culture that are the foundations of our business.

    Skills

    • Aerospace and Defenseunmatched
    • Analysis Skillsunmatched
    • Asset Managementunmatched
    • Automationunmatched
    • Bridge Buildingunmatched
    • Cadenceunmatched
    • Change Controlunmatched
    • Civil Engineeringunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • DoD Directive 8140unmatched
    • DoD Directive 8570unmatched
    • Documentationunmatched
    • Endpoint Securityunmatched
    • GCIA - GIAC Certified Intrusion Analystunmatched
    • GCIH - GIAC Certified Incident Handlerunmatched
    • Governmentunmatched
    • Government Reportingunmatched
    • IAM - Information Assurance Managementunmatched
    • IAT - Information Assurance Technicalunmatched
    • IT Service Management (ITSM)unmatched
    • ITIL (IT Infrastructure Library)unmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Integrated Circuits (ICs)unmatched
    • International Classification of Diseases (ICD)unmatched
    • International Information Systems Security Certification Consortium (ISC)2unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Legalunmatched
    • Machine Toolunmatched
    • Mentoringunmatched
    • Metricsunmatched
    • Needs Assessmentunmatched
    • Nessusunmatched
    • Network Monitoringunmatched
    • Network Operations Centerunmatched
    • Network Securityunmatched
    • Operational Auditunmatched
    • Operational Improvementunmatched
    • Operational Supportunmatched
    • Operationsunmatched
    • Operations Processesunmatched
    • Privacy Controlsunmatched
    • Process Improvementunmatched
    • Riskunmatched
    • Risk Management Framework (RMF)unmatched
    • SAPunmatched
    • Schedule Developmentunmatched
    • Security Analysisunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Sensitive Compartmented Information (SCI)unmatched
    • Standard Operating Procedures (SOP)unmatched
    • System Operationsunmatched
    • Systems Maintenanceunmatched
    • Team Lead/Managerunmatched
    • Time Managementunmatched
    • Top Secret Clearanceunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Citizenunmatched
    • United States Department of Defense (DoD)unmatched
    • Vulnerability Scannersunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder