Senior Cybersecurity Engineer / Analyst – Incident Response Lead (IR Lead) jobs in United States
cer-icon
Apply on Employer Site
company-logo

SOSi · 4 months ago

Senior Cybersecurity Engineer / Analyst – Incident Response Lead (IR Lead)

SOSi is seeking a Senior Cybersecurity Engineer / Analyst – Incident Response Lead (IR Lead) to join their elite team in Hawaii, focusing on cyber defense operations for INDOPACOM. In this role, you will lead incident response efforts, mentor analysts, and ensure the effectiveness of cybersecurity measures against advanced threats.

ConsultingGovernmentInformation Technology
badNo H1BnoteSecurity Clearance Requirednote

Responsibilities

Lead the Cybersecurity Engineer / Analyst team, assigning monitoring priorities, overseeing investigations, and providing mentorship
Act as Incident Response Lead (IRL) during escalations, coordinating containment, remediation, and reporting across the NSOC, mission partners, and external stakeholders
Validate and adjudicate escalated detections from SOC tools (including AI-assisted platforms), ensuring accuracy, prioritization, and timely response
Mentor and coach analysts in advanced detection, threat hunting, and incident response skills; provide regular feedback and performance oversight
Serve as the primary liaison between analysts and engineering staff to refine detections, SOAR playbooks, and automation workflows
Direct proactive threat hunting operations based on adversary TTPs, threat intelligence, and anomaly detection
Ensure incidents are documented to NSOC standards, with lessons learned integrated into playbooks and training
Lead tabletop drills and red/blue team exercises to validate readiness and incident response procedures
Provide senior-level reporting and executive briefings on major incidents
Maintain compliance with RMF, CSSP, and NSOC SOPs; validate processes meet accreditation requirements

Qualification

Incident Response LeadThreat HuntingCybersecurity LeadershipSIEM ProficiencyDoD 8140 CertificationMalware AnalysisAdvanced Detection TechniquesExecutive Briefing SkillsTeam MentorshipCommunication Skills

Required

Active in scope SECRET clearance
Bachelor's Degree in Cybersecurity, Computer Science, Information Systems, or related technical discipline; equivalent work experience considered
5+ years of SOC/NSOC or cyber defense experience, with demonstrated IR and threat hunting expertise
DoD 8140 baseline certification (CASP+/SecurityX or CISSP or GCIA or GCIH or CEH or CFR)
Proven experience leading analyst teams or serving as a shift/incident lead
Strong knowledge of adversary TTPs (MITRE ATT&CK), malware analysis, and advanced detection/response techniques
Proficiency with SIEM, EDR, SOAR, and packet capture/analysis tools (e.g., Wireshark, Zeek)
Strong leadership, communication, and briefing skills for technical and executive audiences

Preferred

Active Top Secret clearance with ability to obtain/maintain TS/SCI
Advanced certifications such as GCIA, GCIH, GDAT, CISSP, or GCTI
Experience in a military cyber defense environment or enterprise-level 24/7 SOC
Prior IR Lead/Tier 3 response experience with major incident coordination responsibilities
Familiarity with AI/LLM-assisted SOC tools or automation pipelines (nice to have)

Benefits

Relocation packages may include a two-year commitment.

Company

SOSi solves the challenges of the modern mission.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Jim Edwards
Chief Growth Officer
linkedin
Company data provided by crunchbase