About this role
Title: Defensive Cyber Operations Lead
Location: Chantilly, VA
US Citizenship Required: Yes
Clearance: Active TS/SCI with CI polygraph
Status: Full-time; contingent upon contract award
Description:
Invictus, a Red River company, delivers technology and services supporting government and national security missions. We combine cleared mission expertise with enterprise engineering, technology partnerships and large-program execution in support of advanced modernization, cybersecurity, intelligence and systems integration. Our teams support complex operational environments across the U.S. and around the world, helping customers strengthen resilience, accelerate mission outcomes and deploy capabilities that meet demanding mission requirements. Learn more at www.InvictusIC.com .
Job Details:
Invictus is seeking a Defensive Cyber Operations (DCO) Lead to manage daily cyber defense tasking and operational tempo for an enterprise cybersecurity program supporting the NRO. The DCO Lead is the primary liaison between contractor personnel and their military counterparts, keeping coordination seamless and the mission aligned. As a senior technical authority, this role matches personnel skills and certifications to operational requirements and mission priorities, and keeps the team ready for a dynamic threat environment.
Responsibilities:
- Manage daily cyber defense tasking across cyber operations, integrated mission defense, cyber readiness, cyber data platform and identity and credentialing functions
- Serve as the primary liaison with military and government counterparts; align contractor work with operational priorities
- Maintain a skills matrix of cyber tasking staff mapped to DoD 8140 work roles and certifications; assign staff to tasks based on it
- Oversee 24/7 cyber analysis, incident response and validation, and intelligence-driven threat hunting
- Guide detection content, SIEM/SOAR use and MITRE ATT&CK technique coverage; identify detection gaps and recommend fixes
- Keep the team trained and ready through exercises, training plans and cross-training
- Brief leadership on operational status, significant incidents and emerging protection, detection and response trends
Requirements:
- Bachelor's degree in Computer Science, Cybersecurity, IT or a related STEM field and one of the following: CISSP, CISM, CCISO, GCDA, Security+ CE, CySA+ or equivalent
- 5+ years of cybersecurity, SOC or cyber incident response experience
- 5+ years of detection engineering and automation experience
- Qualified for a DoD 8140 Category E role (Cyber Workforce Developer 751, Manager or Executive Cyber Leader 901, or IAM Level III)
- Active TS/SCI with CI polygraph
Desired Qualifications:
- Experience within the NRO and its mission partner community
- Demonstrated leadership, management or training experience
- Experience leading combined contractor and military cyber defense teams
- GIAC incident response or hunting certifications (e.g., GCIH, GCFA, GREM)
- Experience with Splunk, SOAR platforms and MITRE ATT&CK-based threat hunting
Equal Opportunity Employer/Veteran/Disabled