Security Operations Center (SOC) Lead
Position Overview
The SOC Lead manages a team of cybersecurity professionals supporting a Security Operations Center and provides comprehensive oversight of daily security operations protecting government systems, networks, applications, data, and end-user devices. The SOC Lead directs operational workflows, coordinates personnel and task assignments, and ensures security activities are executed accurately and on time in accordance with agency priorities, performance standards, federal cybersecurity requirements, and budget constraints.
The ideal candidate is a hands-on operational leader with deep experience across monitoring and detection, incident response, threat analysis, detection engineering, vulnerability coordination, security tool optimization, and escalation management. This individual serves as the central point of accountability for SOC performance, works closely with other technology and cybersecurity teams, and translates operational data into clear risk-based recommendations for technical leaders and executive stakeholders.
Key Responsibilities
SOC Leadership, Staffing, and Service Delivery
· Lead day-to-day IT security operations and manage technical personnel supporting continuous SOC coverage.
· Establish shift coverage, on-call and escalation procedures, staffing schedules, task assignments, and shift-handoff requirements to maintain uninterrupted operational continuity.
· Set daily priorities; balance event queues, investigations, projects, and recurring operational tasks; and reallocate resources based on threat activity, mission impact, and service-level commitments.
· Provide technical direction, coaching, performance feedback, and quality oversight to SOC analysts and engineers; identify training needs and support workforce development.
· Track workload, staffing utilization, deliverables, risks, dependencies, and costs to ensure deadlines, quality standards, and budget targets are met.
· Serve as the primary operational interface among SOC personnel, government cybersecurity leadership, infrastructure and application teams, service providers, and other stakeholders.
Security Monitoring, Detection, and Analysis
· Direct real-time monitoring, triage, detection, analysis, containment, isolation, and escalation of suspected or confirmed cybersecurity incidents across government’s environment.
· Ensure continuous monitoring of websites, servers, databases, applications, cloud services, networks, data centers, endpoints, and ingress and egress connections to government systems.
· Oversee active review and correlation of logs, alerts, events, network traffic, endpoint telemetry, threat intelligence, vulnerability data, identity activity, and other information available to the SOC.
· Validate alert severity and investigative quality, reduce false positives, and ensure events are enriched with sufficient evidence, context, affected assets, business impact, and recommended next actions.
· Develop, tune, test, and maintain detection rules, correlation searches, dashboards, analytics, playbooks, and use cases informed by current threats, adversary tactics, techniques, and procedures (TTPs), and observed gaps.
· Drive proactive threat hunting and gap analysis to identify malicious or anomalous activity that may not be detected through existing automated controls.
Incident Response and Escalation Management
· Lead and coordinate the SOC response to cybersecurity events and incidents from initial validation through containment, eradication, recovery, documentation, and closure.
· Maintain clear incident classification, prioritization, notification, escalation, and communications procedures aligned to operational severity and mission impact.
· Coordinate with incident response, cyber threat intelligence, digital forensics, legal, privacy, communications, infrastructure, application, and business stakeholders as appropriate.
· Ensure evidence is preserved, investigation timelines and decisions are documented, required notifications are made, and incident records are complete and audit-ready.
· Lead post-incident reviews and root-cause analysis; convert findings into corrective actions, updated detections, improved playbooks, training, and measurable control enhancements.
· Provide timely situational awareness and concise executive-level reporting during significant incidents, including known facts, risk, actions taken, decisions required, and next steps.
Security Platforms and Engineering Integration
· Provide operational oversight for the agency's cybersecurity products and their integration with networks, cloud services, applications, end-user devices, and supporting infrastructure.
· Manage and optimize SOC capabilities across SIEM, SOAR, endpoint security/EDR, network security, cloud security, vulnerability management, identity and privileged access, IT service management, and related platforms.
· Support effective integration and use of tools such as Splunk, Splunk SOAR, endpoint security products, Skyhigh Security, Tenable, ServiceNow, SailPoint, BeyondTrust, and other current or future security systems.
· Monitor platform health, data-source coverage, log ingestion, parsing, use-case performance, automation reliability, retention, licensing or capacity considerations, and integration dependencies.
· Identify telemetry gaps, control weaknesses, and opportunities to improve detection fidelity, response speed, analyst efficiency, automation, and overall security visibility.
· Coordinate changes with engineering, infrastructure, application, cloud, and change-management teams and validate that operational security requirements are incorporated into technology implementations.
Vulnerability, Asset, and Exposure Coordination
· Lead or coordinate vulnerability and asset management activities that inform SOC monitoring, investigation prioritization, and incident response decisions.
· Use vulnerability severity, exploitability, threat intelligence, asset criticality, exposure, and mission impact to support risk-based prioritization and escalation.
· Coordinate with system owners and remediation teams to track high-risk findings, actively exploited vulnerabilities, overdue remediation, exceptions, and compensating controls.
· Ensure asset inventories and contextual data are sufficiently accurate and integrated to help analysts determine ownership, criticality, business function, and potential incident impact.
Procedures, Quality, Compliance, and Continuous Improvement
· Develop, maintain, test, and enforce SOC standard operating procedures (SOPs), runbooks, playbooks, checklists, escalation matrices, and knowledge articles for monitoring, investigation, response, reporting, and shift operations.
· Ensure new staff receive role-appropriate onboarding and training and can consistently execute applicable SOPs before assuming independent operational responsibilities.
· Establish quality-control reviews for tickets, investigations, incident records, reports, detection content, and shift handoffs; identify recurring deficiencies and implement corrective actions.
· Ensure SOC processes and records align with applicable federal cybersecurity requirements, agency policies and standards, records requirements, and audit or assessment expectations.
· Support audits, assessments, exercises, tabletop activities, compliance reviews, and requests for operational evidence; ensure findings and action items are tracked through closure.
· Evaluate operational performance and recommend significant changes affecting short-term execution, long-term maturity, service quality, and mission success.
Metrics, Reporting, and Decision Support
· Define, track, analyze, and report meaningful SOC performance and risk metrics, trends, service levels, and key performance or risk indicators.
· Maintain operational dashboards and reporting that provide real-time and historical visibility into alerts, incidents, response times, backlog, detection coverage, tool health, vulnerabilities, staffing, and recurring threats.
· Prepare daily, weekly, monthly, and ad hoc reports tailored to SOC personnel, cybersecurity leadership, infrastructure teams, program management, and executive stakeholders.
· Use trend analysis and operational data to identify systemic issues, forecast resource needs, measure improvement, and provide evidence-based recommendations to senior management.
Required Qualifications
· Bachelor's degree in information technology, cybersecurity, computer science, engineering, or a related field.
· 8-10 years of progressive cybersecurity experience, including at least 5 years leading SOC, incident response, cyber defense, or comparable security operations teams.
· Demonstrated experience leading operational teams in an enterprise SOC, including shift scheduling, workload management, escalation, quality assurance, and service-level performance.
· Hands-on knowledge of SIEM, SOAR, EDR/endpoint security, network security monitoring, vulnerability management, threat intelligence, identity security, and IT service management technologies.
· Strong understanding of cybersecurity incident response lifecycles, adversary TTPs, threat hunting, detection engineering, log analysis, attack-path analysis, and common enterprise attack vectors.
· Experience developing and improving SOC processes, SOPs, playbooks, use cases, dashboards, metrics, and executive reporting.
· Experience supporting federal cybersecurity environments and applying relevant federal security standards, policies, reporting requirements, and audit expectations.
· Ability to lead high-priority investigations and make sound, risk-based decisions under time pressure while communicating clearly with technical and nontechnical stakeholders.
· Strong written and verbal communication skills, including the ability to brief senior leaders and translate complex technical findings into mission and business risk.
Preferred Qualifications
· Experience supporting federal cybersecurity programs of similar size, scope, and complexity, particularly within financial services, regulatory, or highly controlled environments.
· Experience integrating security tools and data sources, automating response workflows, and measuring improvements in detection and response maturity.
· Experience supporting federal audits, compliance assessments, executive reporting, and cross-functional governance involving cybersecurity, infrastructure, cloud, applications, privacy, and risk management.
· Working knowledge of NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-61, FISMA, and other applicable federal cybersecurity guidance.
Clearance and Citizenship Requirements
Must be a U.S. citizen and able to obtain and maintain a Public Trust or higher-level background investigation/clearance, as required by agency.
Pay: $140,000.00 - $160,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Education:
Experience:
- management/lead: 5 years (Required)
- Security Operations: 8 years (Required)
License/Certification:
Work Location: Hybrid remote in Alexandria, VA 22308