Peraton is currently seeking to hire an experienced Deputy Operations Lead, Engineering for its Federal Strategic Cyber programs.
Location: Rosslyn, VA - Flexible for occasional telework – must be local to work location.
Overview
The role supports the Operations Lead – Engineering by providing technical and operational leadership to a multidisciplinary team of system administrators, network engineers, and cybersecurity engineers responsible for ensuring 24x7x365 operational readiness of SOC infrastructure and services. This position assumes full authority in the absence of the Operations Lead.
Key Responsibilities
Operational Leadership & Oversight
- Assist the Operations Lead – Engineering in guiding daily technical and operational activities across engineering teams.
- Assume full authority of the Operations Lead during absences, including personnel management, customer engagement, and critical operational decision-making.
- Supervise and mentor system administrators, network engineers, and SOC engineering staff during assigned shifts.
- Manage shift scheduling, coverage planning, on‑call rotations, surge support, and contingency staffing.
- Provide hands-on coverage for engineering shifts during staffing gaps or surge events.
- Deliver recurring operational and security briefings to federal clients, senior leadership, and stakeholders.
- Provide written and verbal status reporting on engineering operations, incidents, and team performance.
Systems Administration & Engineering
- Perform hands-on system administration tasks including configuration, patching, hardening, and lifecycle management across Windows Server and Linux/Unix environments.
- Manage virtualization platforms (e.g., VMware, Hyper‑V) and cloud environments (e.g., AWS GovCloud, Azure Government).
- Recommend and implement solutions to remediate security issues, outages, and system performance problems.
- Support the deployment, integration, and sustainment of SOC security tools including SIEM, IDS/IPS, EDR/XDR, firewalls, proxies, and log aggregation systems.
- Maintain hardware/software inventories, support capacity planning, and assist in technology refresh cycles.
- Monitor globally deployed agents, servers, workstations, and SOC infrastructure for vulnerabilities, performance degradation, and service disruptions.
Security Operations & Compliance
- Participate in security tests, evaluations, studies, and experiments impacting SOC readiness.
- Ensure adherence to security frameworks, policies, and directives (e.g., NIST SP 800‑53, FISMA, DISA STIGs, DoS IT Security policies).
- Support O&M contractual compliance, SLA adherence, and timely delivery of cybersecurity products and services.
- Support ATO compliance activities across applicable networks and security classifications.
- Assist in monitoring and improving incident, problem, request, and change‑management processes.
- Coordinate with SOC Analysts, Incident Responders, and Threat Intelligence teams to ensure engineering infrastructure meets mission requirements.
Incident Response & Continuity
- Support the Operations Lead during high‑severity cybersecurity incidents, assisting with coordination, communication, escalations, and recovery.
- Assume incident lead responsibilities during the Operations Lead’s absence.
- Participate in after-action reviews and ensure corrective actions are documented, tracked, and completed.
- Support Continuity of Operations (COOP) planning and execution for SOC engineering infrastructure.
- Assist in maintaining operational readiness plans, escalation procedures, contact rosters, and continuity documentation.
Process Improvement & Documentation
- Develop, maintain, and enforce SOC engineering SOPs, runbooks, and technical documentation.
- Contribute to centralized service catalog development using ITIL practices.
- Maintain and update SOC knowledge base documentation, troubleshooting guidance, and lessons learned.
- Identify and support automation opportunities (e.g., reporting, ticket validation, monitoring, patch management).
- Participate in working-group sessions to identify issues, develop user stories, define requirements, and refine acceptance criteria.
- Support the definition, implementation, and monitoring of IT and cybersecurity processes to align with federal requirements and mission objectives.
ServiceNow & Reporting
- Audit and validate ServiceNow tickets to ensure accuracy, completeness, and compliance.
- Track cybersecurity metrics, operational trends, SLA performance, and service delivery data using ServiceNow and approved reporting tools.
- Provide summary reports and surface significant issues, risks, and operational impacts to the Operations Lead.
Collaboration & Stakeholder Engagement
- Coordinate with third-party service providers and technical teams to resolve failures, escalate critical issues, and maintain high availability.
- Collaborate with system owners, IT teams, and stakeholders to assess cybersecurity needs and translate them into actionable solutions.
- Support cross-functional initiatives to strengthen cybersecurity posture and improve Transition to Operations lifecycle.
Other Duties:
- Perform additional cybersecurity operations and service-management tasks as assigned.