Job Title: SOC Lead
Place of Performance: Springfield, VA
Experience Level: Senior-Level (10+ years)
About JFL Consulting:
With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients.
Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit www.jflconsulting.com
What We Offer:
-
Salary: $170k- $220k
-
100% employer-paid medical, dental, and vision premiums for employees and dependents
-
Flexible Spending Accounts (healthcare, dependent care, and commuter)
-
Life insurance, short-term disability and long-term disability
-
401(k) with immediate vesting of company contribution
-
Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
-
We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms
Job Overview:
We're looking for a SOC Lead who is the senior authority for all SOC shifts. This role is responsible for directing the shift teams, managing alert queues, making escalation decisions, and ensuring all open incidents are properly tracked, documented, and handed off.
Key Responsibilities:
-
Provide Tier 4 escalation and resolution for the most complex incidents and outages
-
Direct the daily operations of the shift team across the SOC
-
Monitor alert queues and ensure Tier 1-3 analysts are triaging within SLA standards
-
Make escalation decisions such as activating T3/IR, on-call engineers, and management chain as appropriate
-
Manage the shift handoff process, ensuring a turnover briefing is produced and delivered at each handoff window
-
Mentor, manage and train the SOC staff
-
Review and approve all Priority 2 and above incident tickets before escalation
-
Develop and modify playbooks
-
Ensure all playbooks are being followed correctly and appropriately updated
-
Maintain situational awareness across all incoming alerts, calls, network monitoring, and active triage.
-
Coordinate with NOC staff on network issues that may have a security component
-
Review and verify all shift logs and all required reporting
Required Qualifications:
-
10+ years of SOC or similar experience
-
At least 3+ years in a senior or lead role
-
Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
-
One of the following certifications, equivalent or better: CISSP, CISM, or CISA, or GCIH
-
Additionally One of the following certifications, equivalent or better: Sec+, CYSA+, SecX, CEH, GCIA, GSOC
-
Expert proficiency with hands-on incident response experience including containment, eradication, and recovery
-
Advanced experience with SIEM platforms and log analysis
-
Advanced experience SIEM query languages (SPL, KQL, or equivalent)
-
Advanced experience PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
-
Advanced experience with EDR, endpoint forensics, memory analysis, and network forensics tools
-
Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK
-
Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
-
Demonstrated experience managing and mentoring junior analysts
-
Ability to remain calm and direct operations during high-pressure incidents
Preferred Qualifications:
-
GCFA or GCFE certification or other forensic certifications
-
Active Secret clearance preferred but not required
-
Experience with threat hunting frameworks and platforms
-
Reverse engineering experience (IDA Pro, Ghidra)
-
Prior experience on a DFIR team or incident response retainer
-
Experience with malware analysis (static and dynamic)
-
Experience with zero-trust network architecture
-
Experience with classified network environments (SIPRNet, NIPRNet)
-
Direct experience as SOC experience
-
SOAR platform experience
JFL Consulting, LLC is an Equal Opportunity Employer.
We do not discriminate against any applicant for employment on any legally recognized basis including, but not limited to: race, religion or creed, color, national origin, sex, age, disability, marital status, sexual orientation, genetic information, veteran status, status with regard to public assistance or any other protected class under federal, state or local statute. It is also the policy of JFL Consulting, LLC to provide reasonable accommodations for qualified individuals with disabilities.
PI286055444