Peraton is currently seeking to hire an experienced Operations Lead - Engineering for its' Federal Strategic Cyber programs.
Location: Beltsville, MD
Overview
The Operations Lead – Engineering serves as the senior technical and operational authority for the Engineering division of the Security Operations Center (SOC). In this role, you will oversee the full lifecycle of SOC engineering operations, including systems administration, physical and virtual network engineering, 24x7x365 shift coverage, and direct supervision of all engineering staff. You will ensure that critical systems, tools, and services remain secure, available, compliant, and fully operational to support mission requirements.
Key Responsibilities
Technical & Operational Leadership
- Provide senior-level direction to system administrators, network engineers, and cybersecurity engineers supporting 24x7x365 SOC operations.
- Oversee systems administration activities, including configuration, patching, hardening, lifecycle management, and operational readiness of servers, endpoints, and security appliances.
- Lead and maintain SOC virtualization platforms (VMware, Hyper‑V) and cloud environments (AWS GovCloud, Azure Government).
- Recommend and implement solutions to address security issues, system outages, and network disruptions.
- Apply deep technical infrastructure expertise to ensure compliance with service-level agreements (SLAs) and operational performance metrics.
- Lead or participate in security tests, evaluations, studies, and experiments that directly impact SOC readiness.
Engineering Governance & Documentation
- Develop, maintain, and enforce SOC engineering SOPs, runbooks, knowledge base content, and technical documentation.
- Conduct technical and management briefings for senior leadership, government stakeholders, and program management.
- Maintain a centralized service catalog leveraging ITIL practices to improve delivery, accountability, and efficiency.
Team Management & Staffing
- Lead, supervise, and mentor systems administrators, network engineers, and SOC engineering personnel.
- Manage shift coverage, scheduling, on‑call rotations, contingency plans, and surge support for a 24x7x365 environment.
- Provide hands-on engineering support during staffing gaps or high-demand events.
- Develop staffing and continuity plans for weather events, absences, emergencies, and other mission-impacting situations.
Cross-Functional Coordination
- Integrate and sustain SOC security tools including SIEM, IDS/IPS, EDR/XDR, firewalls, proxies, and logging solutions.
- Coordinate with SOC Analysts, Incident Responders, and Threat Intelligence teams to ensure engineering infrastructure meets mission requirements.
- Collaborate with system owners, IT teams, and stakeholders to assess cybersecurity needs and translate them into actionable solutions.
- Facilitate working groups to identify issues, define requirements, and prioritize technical improvements.
Operational Excellence & Compliance
- Manage asset inventory, capacity planning, and technology refresh cycles for all SOC engineering assets.
- Support Continuity of Operations (COOP) planning and execution for critical SOC infrastructure.
- Interface with Contracting Officer Representatives (CORs), program managers, and technical leads on engineering matters.
- Ensure compliance with NIST SP 800‑53, FISMA, DISA STIGs, DoS policies, and O&M contractual requirements.
- Oversee daily operations ensuring system availability, security, and operational readiness.
- Coordinate remediation activities supporting Authority to Operate (ATO) compliance across multiple networks and classifications.
Incident Response & Operational Reporting
- Provide leadership during high-severity cybersecurity incidents, including response coordination, client communication, and recovery.
- Lead after-action reviews, ensuring corrective actions are documented, assigned, tracked, and completed.
- Monitor global infrastructure for vulnerabilities, disruptions, performance issues, and operational risks.
- Coordinate with third-party providers to resolve failures, escalate critical issues, and minimize downtime.
- Oversee patching and vulnerability remediation across multiple enclaves and security levels.
- Monitor incident, request, change, and problem management processes to identify trends and improve service delivery.
- Identify opportunities to automate recurring cybersecurity tasks such as reporting, ticket validation, policy enforcement, monitoring, and patching.
- Audit ServiceNow tickets to ensure accuracy, completeness, and compliance.
- Track key cybersecurity metrics, SLAs, performance indicators, and operational trends.
- Ensure quality, accuracy, and timely delivery of all cybersecurity operational products and services.
Additional Responsibilities
- Maintain operational readiness plans, escalation procedures, contact rosters, and continuity documentation.
- Drive continual service improvement across engineering, operations, monitoring, and support functions.
- Provide guidance and mentorship to engineering leads, analysts, and O&M support personnel.
- Perform additional cybersecurity operations and service‑management duties as assigned.
#DSCM