Security Operations Lead
Core
Lead a blended team of SOC Analysts and Security Engineers to ensure rapid detection, investigation, and response to security threats for US federal government clients.
Role type
Senior IC Security Operations Lead (SOC Lead)
Builds
Mission-critical security coverage and detection capabilities for federal defense, national security, and public safety organizations.
Domain
Cybersecurity / Federal Government / Defense
Deliverable
production ML models | product features | dashboards & analysis | client delivery
Required skills
SOC operations leadership, incident response management, threat hunting, SIEM administration, log analysis, playbook development, stakeholder communication
Preferred skills
Threat analytics, adversary behavior profiling, SOAR automation, malware triage, cloud security monitoring
Technologies
Splunk, Elastic, ExtraHop, Trellix, Azure, AWS, GCP
Responsibilities
Lead day-to-day SOC operations including queue management and alert triage oversight; Drive threat hunting activities focused on identifying patterns and TTP-aligned behaviors; Lead the full lifecycle of incident response including forensics support; Develop and optimize SIEM correlation rules and monitoring logic; Mentor and develop SOC analysts across tiers; Coordinate with Security Engineering to ensure logging fidelity and sensor coverage
Seniority
Senior, hands-on IC with leadership responsibilities