4 ΡΠ°ΡΠ° Π½Π°Π·Π°Π΄
SOC Watch Officer (Cybersecurity)
ΠΡΡΡ & Π‘ΠΎΠΏΡΠΎΠ²ΠΎΠ΄
ΠΠ»Ρ ΠΌΡΡΡΠ° Ρ ΡΡΠΎΠΉ Π²Π°ΠΊΠ°Π½ΡΠΈΠ΅ΠΉ Π½ΡΠΆΠ΅Π½ Plus
ΠΠΏΠΈΡΠ°Π½ΠΈΠ΅ Π²Π°ΠΊΠ°Π½ΡΠΈΠΈ
Π’Π΅ΠΊΡΡ:
TL;DR
SOC Watch Officer (Cybersecurity): Supervising SOC analysts and directing real-time monitoring, triage, escalation, and incident response across enterprise network environments with an accent on operational judgment, detection coverage, and response quality. Focus on managing active security events, coordinating containment and remediation, and maintaining accurate shift handoffs and documentation under federal security standards.
Location: Chandler, Arizona, United States
Company
builds and delivers federal technology using a product-oriented approach focused on speed, ownership, and execution.
What you will do
- Maintain situational awareness across monitoring queues, incidents, and security events during the assigned watch.
- Supervise SOC analysts, direct workloads, review analyst actions, and enforce operational discipline.
- Make real-time decisions on event triage, escalation, prioritization, and notification of leadership.
- Support incident response through containment and remediation while coordinating with technical teams.
- Monitor SOC tooling and sensor coverage, escalating detection gaps, outages, and anomalies.
- Document security events, conduct shift turnover briefings, and contribute to after-action reviews and continuous improvement.
Requirements
- Bachelorβs degree in Computer Science, Information Security, or a related field, or equivalent experience.
- At least 3 years of supervisory experience in security operations or a related technical environment.
- Hands-on experience with enterprise monitoring, detection, alert triage, log analysis, and incident response.
- Experience with SIEM platforms, EDR tools, network monitoring technologies, LAN, WAN, and cloud security architectures.
- Knowledge of FISMA, NIST incident response frameworks, and federal security operations standards.
- Active Secret clearance and Top Secret/SCI eligibility are required. One certification from each specified security operations and DoD 8570 CSSP groups is required; six years of equivalent hands-on experience may replace one certification.
Nice to have
- Experience as a watch officer or shift lead in a federal civilian, defense, or intelligence SOC.
- Experience with tier-less SOC operations, threat hunting, APT detection, kill-chain response, Zero Trust monitoring, or cloud-based security operations.
- Active TS/SCI clearance.
Culture & Benefits
- Flexible schedules and teleworking options.
- Medical insurance, including HSA-eligible plans, plus employer-paid dental and vision options.
- Employer-sponsored short-term disability, long-term disability, and life insurance.
- 5% 401(k) company matching, paid holidays, PTO accrual, and paid parental leave.
- Professional development, career growth opportunities, and team recognition events.
ΠΡΠ΄ΡΡΠ΅ ΠΎΡΡΠΎΡΠΎΠΆΠ½Ρ: Π΅ΡΠ»ΠΈ ΡΠ°Π±ΠΎΡΠΎΠ΄Π°ΡΠ΅Π»Ρ ΠΏΡΠΎΡΠΈΡ Π²ΠΎΠΉΡΠΈ Π² ΠΈΡ ΡΠΈΡΡΠ΅ΠΌΡ, ΠΈΡΠΏΠΎΠ»ΡΠ·ΡΡ iCloud/Google, ΠΏΡΠΈΡΠ»Π°ΡΡ ΠΊΠΎΠ΄/ΠΏΠ°ΡΠΎΠ»Ρ, Π·Π°ΠΏΡΡΡΠΈΡΡ ΠΊΠΎΠ΄/ΠΠ, Π½Π΅ Π΄Π΅Π»Π°ΠΉΡΠ΅ ΡΡΠΎΠ³ΠΎ - ΡΡΠΎ ΠΌΠΎΡΠ΅Π½Π½ΠΈΠΊΠΈ. ΠΠ±ΡΠ·Π°ΡΠ΅Π»ΡΠ½ΠΎ ΠΆΠΌΠΈΡΠ΅ "ΠΠΎΠΆΠ°Π»ΠΎΠ²Π°ΡΡΡΡ" ΠΈΠ»ΠΈ ΠΏΠΈΡΠΈΡΠ΅ Π² ΠΏΠΎΠ΄Π΄Π΅ΡΠΆΠΊΡ. ΠΠΎΠ΄ΡΠΎΠ±Π½Π΅Π΅ Π² Π³Π°ΠΉΠ΄Π΅ β