Job Requirements
Remote Alexandria, VA
Public Trust Polygraph not specified
Senior Level Career (10+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Security Operations Lead
Summary: We are seeking a Security Operations Lead to direct enterprise-wide threat detection, incident response, and security monitoring across hybrid and cloud environments. This role manages SOC analysts, drives SIEM/EDR/XDR platform optimization, and authors detection analytics to mitigate emerging cyber threats. The ideal candidate pairs deep operational technical expertise with strong team leadership to streamline event triage, elevate incident escalation workflows, and maintain robust operational metrics.
Key Responsibilities
• SOC Leadership & Operations: Direct day-to-day Security Operations Center (SOC) activities, overseeing security monitoring, threat detection, event triage, and rapid incident response across enterprise and cloud infrastructures.
• Team Management & Development: Lead, mentor, and manage a team of SOC analysts, establishing operational workflows, escalation paths, performance metrics, and training programs.
• Platform Optimization & Engineering: Optimize, tune, and maintain SIEM, EDR, XDR, and SOAR platforms to enhance visibility, reduce false positives, and automate threat detection routines.
• Threat Analytics & Hunting: Develop custom detection analytics, correlation rules, and threat hunting strategies to proactively identify sophisticated attack vectors and advanced persistent threats (APTs).
• Incident Escalation & Management: Drive major security incident investigations, coordinating containment, eradication, and post-incident reporting across cross-functional engineering and executive leadership teams.
• Continuous Process Improvement: Establish, refine, and report on key operational metrics (MTTD/MTTR), driving continuous enhancements to SOC playbooks, threat intelligence feeds, and incident management procedures.
Qualifications Required:
• Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
• Experience: 8–10+ years in security operations, including at least 5 years directly leading or managing SOC teams and operations.
• Technical Mastery: Deep hands-on experience configuring and tuning SIEM, EDR, and XDR solutions across hybrid-cloud environments.
• Operational Expertise: Proven track record establishing SOC playbooks, tracking operational metrics, and managing end-to-end incident response lifecycles.
Preferred Certifications:
• Core Operations & Leadership: CISSP, CISM, or GIAC (GCIH/GCIA).
• Cloud & Operations Certifications: Microsoft Security Operations Analyst (SC-200), Microsoft Azure Security Engineer (AZ-500), or equivalent AWS/cloud security credentials.
Job Location: Hybrid to Alexandria, VA.
Clearance: Public Trust or higher.
Summary: We are seeking a Security Operations Lead to direct enterprise-wide threat detection, incident response, and security monitoring across hybrid and cloud environments. This role manages SOC analysts, drives SIEM/EDR/XDR platform optimization, and authors detection analytics to mitigate emerging cyber threats. The ideal candidate pairs deep operational technical expertise with strong team leadership to streamline event triage, elevate incident escalation workflows, and maintain robust operational metrics.
Key Responsibilities
• SOC Leadership & Operations: Direct day-to-day Security Operations Center (SOC) activities, overseeing security monitoring, threat detection, event triage, and rapid incident response across enterprise and cloud infrastructures.
• Team Management & Development: Lead, mentor, and manage a team of SOC analysts, establishing operational workflows, escalation paths, performance metrics, and training programs.
• Platform Optimization & Engineering: Optimize, tune, and maintain SIEM, EDR, XDR, and SOAR platforms to enhance visibility, reduce false positives, and automate threat detection routines.
• Threat Analytics & Hunting: Develop custom detection analytics, correlation rules, and threat hunting strategies to proactively identify sophisticated attack vectors and advanced persistent threats (APTs).
• Incident Escalation & Management: Drive major security incident investigations, coordinating containment, eradication, and post-incident reporting across cross-functional engineering and executive leadership teams.
• Continuous Process Improvement: Establish, refine, and report on key operational metrics (MTTD/MTTR), driving continuous enhancements to SOC playbooks, threat intelligence feeds, and incident management procedures.
Qualifications Required:
• Education: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
• Experience: 8–10+ years in security operations, including at least 5 years directly leading or managing SOC teams and operations.
• Technical Mastery: Deep hands-on experience configuring and tuning SIEM, EDR, and XDR solutions across hybrid-cloud environments.
• Operational Expertise: Proven track record establishing SOC playbooks, tracking operational metrics, and managing end-to-end incident response lifecycles.
Preferred Certifications:
• Core Operations & Leadership: CISSP, CISM, or GIAC (GCIH/GCIA).
• Cloud & Operations Certifications: Microsoft Security Operations Analyst (SC-200), Microsoft Azure Security Engineer (AZ-500), or equivalent AWS/cloud security credentials.
Job Location: Hybrid to Alexandria, VA.
Clearance: Public Trust or higher.
group id: 91130095