Job SummaryReporting to the Director of Information Security, the Security Operations Center (SOC) Lead will implement and lead the day-to-day operations of our campus Security Operations Center. This individual will be responsible for coordinating the day-to-day technical operations of the SOC by leading cybersecurity investigations, coordinating incident response activities, improving security monitoring and detection capabilities, and mentoring student cybersecurity assistants.
The SOC Lead plays a critical role in maintaining a secure campus technology environment while providing meaningful hands-on cybersecurity experience for student assistants employed within the Security Operations Center.
Working outside standard business hours will be required on an as needed basis. Responsibilities - Manage SOC Operations: Coordinate daily Security Operations Center activities including security monitoring, incident detection, analysis, response, and escalation procedures. Collaborate with colleagues to improve operational workflows, security monitoring capabilities, and participate in on-call rotation as needed.
- Student Workforce Development: Hire, onboard, train, schedule, and mentor student assistants to support SOC operations, providing hands-on learning experiences in cybersecurity.
- Incident Response: In collaboration with the Director of Information Security and other colleagues, coordinate incident response efforts, ensure timely and accurate communication, and document security events in compliance with college and university system policies.
- Security Monitoring & Threat Detection: Support enterprise security monitoring, threat detection, threat analysis, and vulnerability management activities to proactively identify, investigate, and respond to cybersecurity threats while continuously improving operational effectiveness.
- Process Development: Develop and maintain standard operating procedures, incident response playbooks, and escalation protocols.
- Collaboration: Work closely with IT infrastructure, help desk, and other units to ensure integrated and timely security support.
- Reporting: Prepare and present regular reports and metrics on SOC performance, incident trends, and student assistant engagement.
- Perform additional duties as assigned.
Required Qualifications - 4 Year / Bachelor's Degree in information security, computer science, information technology, related field, or equivalent experience.
- At least four (4) years of relevant professional experience in cybersecurity, security operations, systems administration, incident response, or a related technical field.
Preferred Qualifications - Graduate Degree in a related field
- Five (5) or more years of professional cybersecurity experience.
- Demonstrated ability to analyze technical issues, prioritize work, and communicate effectively with both technical and non-technical stakeholders.
- Experience working in education, USG experience desired.
- Experience supporting Security Operations Center (SOC) activities or serving as a technical lead within a cybersecurity operations environment.
- Experience mentoring student assistants, interns, junior analysts, or technical staff.
- Relevant cybersecurity certifications such as CISSP, CISM, Security+, CySA+, GCFA, or GCIA.
Proposed Salary71,700 - 91,400 Salary offer will be dependent on candidate's experience and qualifications, internal equity considerations, budget availability, and salary administration guidelines.
Knowledge, Skills, & Abilities - Knowledge of cybersecurity operations, incident response, threat detection, vulnerability management, and cybersecurity best practices.
- Knowledge of enterprise information technology infrastructure, networking, operating systems, identity and access management, cloud technologies, endpoint security, and enterprise
- security monitoring concepts.
- Knowledge of IT Service Management best practices and experience using ticketing platforms.
- Demonstrated ability to coordinate technical investigations, analyze cybersecurity events, determine root cause, and recommend effective remediation strategies.
- Proven ability to assess business needs and understand the end-user impact of technical controls.
- Demonstrated ability to manage risks effectively and enable the business.
- Strong organizational skills with the ability to manage competing priorities and meet deadlines.
- Effective written, verbal, and interpersonal communication skills with the ability to communicate technical information to both technical and non-technical audiences.
- Demonstrated ability to mentor student cybersecurity personnel, foster collaboration, promote continuous learning, and maintain effective working relationships across the College.