4 часа назад
SOC Operations Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Operations Manager (Cybersecurity): Leading Tier 2 threat watch operations for a large-scale federal security operations program with an accent on event validation, IDS/IPS/SIEM correlation, intrusion detection signatures, and Tier 1 analyst oversight. Focus on assessing complex multi-vector attacks, monitoring High Value Assets, coordinating significant incidents with government agencies, and automating SOC workflows with Python.
Location: Fort Collins, Colorado; Kansas City, Missouri; or Washington, DC, United States
Company
builds and delivers federal technology using a product-oriented approach focused on speed, ownership, and execution.
What you will do
- Lead the Tier 2 Threat Watch Officer function and act as the senior operational authority during assigned watch periods.
- Validate security events, assess operational impact, determine escalation paths, and coordinate stakeholder notifications.
- Correlate anomalies across IDS, IPS, and SIEM platforms and recommend network configuration changes to strengthen defensive coverage.
- Author and maintain intrusion detection signatures and monitor High Value Assets.
- Oversee Tier 1 SOC analysts, direct workloads, validate actions, and provide real-time coaching during active events.
- Coordinate with law enforcement, counterintelligence, and interagency partners while producing playbooks, shift reports, and incident documentation.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- At least 5 years of security operations experience, including hands-on Tier 2 or senior SOC analyst experience.
- Supervisory or team lead experience overseeing SOC analysts or watch-floor operations.
- Active Secret clearance is required.
- Deep experience with security event validation, IDS/IPS/SIEM correlation, incident assessment, signature development, alert tuning, and dashboard operations.
- Proficiency in Python or an equivalent language, with familiarity with FISMA, NIST incident response frameworks, federal security operations standards, adversary TTPs, and threat actor trends.
Nice to have
- CISSP, GCIA, GCIH, CySA+, or an equivalent security operations certification.
- Federal civilian, defense, or intelligence SOC leadership experience.
- Experience with threat hunting, kill-chain-based detection, Zero Trust monitoring, or cloud-native SOC operations.
- Active TS/SCI clearance.
Culture & Benefits
- Flexible schedules and teleworking options.
- Medical insurance plans, including HSA-eligible options.
- Employer-paid dental, vision, short-term disability, long-term disability, and life insurance options.
- 5% 401(k) company matching, paid holidays, PTO accrual, and paid parental leave.
- Professional development, career growth opportunities, and team recognition events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →