Operations Lead Active Top Secret
Beltsville, MD - USA
Job Summary
Peraton is currently seeking to hire an experienced Operations Lead - Engineering for its Federal Strategic Cyber programs.
Location: Beltsville MD
Overview
The Operations Lead Engineering serves as the senior technical and operational authority for the Engineering division of the Security Operations Center (SOC). In this role you will oversee the full lifecycle of SOC engineering operations including systems administration physical and virtual network engineering 24x7x365 shift coverage and direct supervision of all engineering staff. You will ensure that critical systems tools and services remain secure available compliant and fully operational to support mission requirements.
Key Responsibilities
Technical & Operational Leadership
- Provide senior-level direction to system administrators network engineers and cybersecurity engineers supporting 24x7x365 SOC operations.
- Oversee systems administration activities including configuration patching hardening lifecycle management and operational readiness of servers endpoints and security appliances.
- Lead and maintain SOC virtualization platforms (VMware HyperV) and cloud environments (AWS GovCloud Azure Government).
- Recommend and implement solutions to address security issues system outages and network disruptions.
- Apply deep technical infrastructure expertise to ensure compliance with service-level agreements (SLAs) and operational performance metrics.
- Lead or participate in security tests evaluations studies and experiments that directly impact SOC readiness.
Engineering Governance & Documentation
- Develop maintain and enforce SOC engineering SOPs runbooks knowledge base content and technical documentation.
- Conduct technical and management briefings for senior leadership government stakeholders and program management.
- Maintain a centralized service catalog leveraging ITIL practices to improve delivery accountability and efficiency.
Team Management & Staffing
- Lead supervise and mentor systems administrators network engineers and SOC engineering personnel.
- Manage shift coverage scheduling oncall rotations contingency plans and surge support for a 24x7x365 environment.
- Provide hands-on engineering support during staffing gaps or high-demand events.
- Develop staffing and continuity plans for weather events absences emergencies and other mission-impacting situations.
Cross-Functional Coordination
- Integrate and sustain SOC security tools including SIEM IDS/IPS EDR/XDR firewalls proxies and logging solutions.
- Coordinate with SOC Analysts Incident Responders and Threat Intelligence teams to ensure engineering infrastructure meets mission requirements.
- Collaborate with system owners IT teams and stakeholders to assess cybersecurity needs and translate them into actionable solutions.
- Facilitate working groups to identify issues define requirements and prioritize technical improvements.
Operational Excellence & Compliance
- Manage asset inventory capacity planning and technology refresh cycles for all SOC engineering assets.
- Support Continuity of Operations (COOP) planning and execution for critical SOC infrastructure.
- Interface with Contracting Officer Representatives (CORs) program managers and technical leads on engineering matters.
- Ensure compliance with NIST SP 80053 FISMA DISA STIGs DoS policies and O&M contractual requirements.
- Oversee daily operations ensuring system availability security and operational readiness.
- Coordinate remediation activities supporting Authority to Operate (ATO) compliance across multiple networks and classifications.
Incident Response & Operational Reporting
- Provide leadership during high-severity cybersecurity incidents including response coordination client communication and recovery.
- Lead after-action reviews ensuring corrective actions are documented assigned tracked and completed.
- Monitor global infrastructure for vulnerabilities disruptions performance issues and operational risks.
- Coordinate with third-party providers to resolve failures escalate critical issues and minimize downtime.
- Oversee patching and vulnerability remediation across multiple enclaves and security levels.
- Monitor incident request change and problem management processes to identify trends and improve service delivery.
- Identify opportunities to automate recurring cybersecurity tasks such as reporting ticket validation policy enforcement monitoring and patching.
- Audit ServiceNow tickets to ensure accuracy completeness and compliance.
- Track key cybersecurity metrics SLAs performance indicators and operational trends.
- Ensure quality accuracy and timely delivery of all cybersecurity operational products and services.
Additional Responsibilities
- Maintain operational readiness plans escalation procedures contact rosters and continuity documentation.
- Drive continual service improvement across engineering operations monitoring and support functions.
- Provide guidance and mentorship to engineering leads analysts and O&M support personnel.
- Perform additional cybersecurity operations and servicemanagement duties as assigned.
#DSCM
Minimum Qualifications Are:
- Bachelors degree in Computer Science Mathematics Physics Engineering Information Technology or other related scientific or technical discipline.
- Four (4) additional years of experience may be substituted in lieu of the bachelors degree requirement.
- 12 years of experience in IT cybersecurity and/or projects related to critical network infrastructure protection.
- Minimum of five (5) years of experience in IT cloud-based security infrastructure protection.
- Minimum of five (5) years of experience in IT infrastructure support. Demonstrated oral and written communications skills.
- Minimum of eight (8) years of specialized experience that is current in cybersecurity system or solution design engineering evaluation integration and/or deployment. Demonstrated ability to provide cybersecurity guidance at the authoritative level.
- Systems: Demonstrated hands-on experience administering Windows Server and/or Linux/Unix environments in an enterprise or government setting including Active Directory Group Policy DNS DHCP and PKI.
- Network:Demonstrated experience designing configuring and troubleshooting physical and virtual network infrastructure including routing protocols (BGP OSPF) switching firewalls load balancers and VPN technologies.
- Virtualization & Cloud:Demonstrated experience managing virtualization platforms (VMware vSphere/ESXi Hyper-V) and government cloud environments (AWS GovCloud Azure Government or equivalent).
- Security Tools:Experience deploying and managing enterprise security tools including SIEM (e.g. Splunk ArcSight Microsoft Sentinel) IDS/IPS EDR/XDR and network monitoring platforms.
- Must either possess and maintain or obtain prior to starting date one of the following professional certifications: ITIL Foundation (or higher).
- Demonstrated technical task management and supervisory experience including shift scheduling and personnel management in a 24x7 operational environment.
- Experience managing cybersecurity or information assurance support programs of similar size complexity and scope as the DSCM Program.
- Experience managing 24x7x365 operational environments including shift rotation planning and surge staffing.
- Experience in network technology management or operations with increasing responsibilities.
- Experience managing network security monitoring and incident response capability.
- Experience with IT service management platforms specifically ServiceNow including ticket auditing metrics tracking and reporting.
- Demonstrated experience leading after-action reviews documenting lessons learned and driving corrective action to closure.
- Experience with vulnerability remediation and patch management across multi-enclave or multi-classification environments.
- U.S. citizenship is required.
- Active Top Secret security clearance.
Preferred Qualifications:
- One or more of the following certifications: CISSP CISM CEH CompTIA Security CCNP Security CCNA AWS Certified Solutions Architect Microsoft Certified: Azure Administrator VMware VCP or GIAC GCED/GCIA/GCIH.
- Experience supporting U.S. Department of State or other federal civilian agency IT/cybersecurity programs.
- Familiarity with DoS IT Security policies FISMA reporting requirements and ATO/RMF processes.
- Experience with Zero Trust Architecture (ZTA) design and implementation.
- Experience with SD-WAN MPLS and global WAN environments supporting diplomatic or government missions.
- Deep familiarity with ITIL service management practices including service catalog design continual service improvement and ITSM toolset implementation (e.g. ServiceNow).
- Prior experience in a SOC leadership role with direct responsibility for engineering infrastructure and O&M contractual performance.
- Experience developing and managing centralized knowledge bases runbook libraries and lessons-learned repositories.
- Experience with process automation tools and scripting (e.g. Python PowerShell Ansible PowerAutomate ) to reduce manual operational burden.
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the worlds leading mission capability integrator and transformative enterprise IT provider we deliver trusted highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land sea space air and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day our employees do the cant be done by solving the most daunting challenges facing our customers. Visit to learn how were keeping people around the world safe and secure.
Required Experience:
Manager
About Company
Peraton provides innovative solutions for the most sensitive and critical programs in government today, developed and executed by scientists, engineers, and other experts.