user avatar

Security Operations Center (SOC) Manager

ECS

Posted today

Job Requirements

Fairfax, VA
Secret Polygraph Unspecified
Career Level not specified
$190,000 - $225,000

Job Description

Job Description
Everforth ECS is seeking a Security Operations Center (SOC) Manager to work in our Fairfax, VA office in a hybrid remote/on-site capacity.

Everforth ECS is seeking an experienced, outcome-driven Security Operations Center (SOC) Manager to work in our Fairfax, VA office in support of DoW environment U.S. Coalition Mission Partner Environments (MPE), each with a unique set of data and applications. The SOC Manager will oversee personnel responsible for 24x7x365 SOC services that provide proactive and real-time monitoring, detection, analysis, quantification, response, and reporting capabilities for cybersecurity events and incidents in accordance with Federal laws and regulations. These services include continuous cybersecurity monitoring of Enclave IT systems and assets; investigation of security alerts; incident triage; root cause analysis; and full-spectrum incident response activities - including containment, remediation, and recovery - to ensure complete system restoration. The SOC Manager will drive the Enclaves' full recovery from cyber incidents and ensure adherence to Federal incident management and reporting requirements that are central to these security operations. The SOC Manager will report directly to the Defense & Intel Business Unit's Platforms Solutions Division Vice President.

Primary Responsibilities:
  • Build, deploy, and maintain a comprehensive SOC program leveraging best practices and compliant with client standards and requirements.
  • Oversee the Secure Unclassified Network (SUNet) SOC and coordinate all SOC activities including Tier support.
  • Serve as the primary incident commander for all SOC cybersecurity incidents.
  • Support the development of SOC plans, policies, and standard operating procedures (SOP).
  • Act as the primary SOC liaison with external agencies, mission partners, and third-party vendors during joint investigations and coordinated incident response efforts.
  • Represent SOC capabilities and readiness during stakeholder meetings, program reviews, and federal oversight briefings.
  • Integrate cyber threat intelligence (CTI) into SOC detection engineering and incident triage workflows to improve fidelity and contextual relevance of alerts.
  • Define, track, and analyze SOC Key Performance Indicators (KPIs) - such as Mean Time to Detect (MTTD), Mean Time to Repair (MTTR), analyst utilization, and false positive rates - to ensure compliance with Service Level Agreements (SLA) and drive continuous improvement.
  • Develop dashboards and reporting mechanisms to communicate Key Performance Indicator (KPI) trends, SOC effectiveness, and incident lifecycle insights to executive stakeholders and customers.
  • Provide guidance on active Plans of Action and Milestones (POA&M).
  • Lead the implementation and continuous improvement of Security Orchestration, Automation, and Response (SOAR) capabilities by developing automated playbooks to streamline triage, enrichment, and containment workflows, while tracking effectiveness through automation coverage, time savings, and reduced analyst fatigue.
  • Manage project tracking schedules, risk registers, and risk and issue mitigation strategies for SOC and incident response activities.
  • Ensure quality and timeliness of SOC deliverables.
  • Provide hands-on guidance, training, mentoring, and support to junior staff.
  • Other duties, as assigned.

Salary: $190,000 - $225,000

Required Skills
Required Skills:
  • U.S. citizen.
  • Active Department of War (DoW) Secret or higher security clearance.
  • Bachelor's degree in a Science, Technology, Engineering, or Mathematics (STEM) discipline, or related field of study.
  • Minimum DoD 8570 IAT Level II compliant (Security+ or higher; Level III certification preferred).
  • Ability to work in a hybrid on-site/remote environment with potentially up to 3 business days per week onsite at Everforth ECS Corporate offices in Merrifield, VA.
  • 10+ years of progressive, operational cybersecurity experience, with at least 5 years leading SOC or incident response teams in a 24x7 environment.
  • Proven expertise leading end-to-end incident management and response, from initial detection through containment, remediation, and post-incident analysis.
  • Strong understanding of standards and requirements outlined by the Federal Information Security Management Act (FISMA) and the National Institute of Standards and Technology (NIST).
  • Thorough knowledge and understanding of information security concepts, protocols, industry best practices, and principles as a means of relating business needs to security controls.
  • Deep expertise in incident response, threat detection, SIEM operations, endpoint security, and SOC performance metrics, with a focus on driving detection efficacy and operational efficiency.
  • Hands-on familiarity with platforms such as Splunk, Elastic, CrowdStrike, and SOAR tooling (Tines, Phantom, etc.).
  • Demonstrated success in building or maturing SOC operations for DoW, the Intelligence Community, or regulated enterprises.
  • Keen ability to perform threat management and threat modeling in large environments; identify threat vectors, and develop recommendations to eliminate vulnerabilities / weaknesses.
  • Demonstrated experience with:
    • SOC team management and oversight of Incident Response engagements
    • Using cybersecurity tools to protect data and functional assets (i.e. Tenable, ServiceNow Discovery)
    • Implementing advanced technologies
    • Creating security investigation guides and playbooks
    • Integrating cyber threat intelligence into a SOC
    • SOC process automation
  • Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
  • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
Desired Skills
Preference shown to candidates with:
  • Active DoW Top Secret or higher security clearance.
  • Master's degree in a STEM discipline.
  • DoD 8570 IAT Level III compliant certification; CISSP, GIAC (GSOM, GCIH, GCIA, GCTI, GSOC, GCDA), or equivalent certification.
  • Knowledge and experience working with DoW organizations and/or performers.
  • Prior extensive SOC management and/or team leadership.
  • Experience with McAfee, Splunk, Elastic, or CrowdStrike security stacks.
  • Knowledge of Advanced Persistent Threat (APT) Actor Tactics, Techniques, and Procedures (TTP).
  • Experience operationalizing MITRE ATT&CK, threat modeling, and Common Vulnerabilities and Exposures (CVE) analysis to security operations.
  • Hands-on knowledge and experience with Atlassian's Jira and Confluence.

#EverforthECS1

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We value:
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven


Meet the challenge. Make a difference with Everforth ECS!
group id: 10112231A
Find ECS on Social Media
Recruiters
user avatar
About Us
ECS, a key segment of ASGN Incorporated, is a trusted IT systems integrator serving government agencies. ECS provides modern digital solutions that enable fast and efficient decision making and support the effective execution of government agency operations. ECS’ leading-edge AI, cybersecurity, and open data management solutions boost collaboration, innovation, and worker productivity, improve employee and customer experiences, and protect critical agency data and assets.

ECS Jobs


Job Category
IT - Security
Clearance Level
Secret
Employer
ECS