The OpportunityThe SOC Team Lead role serves as the technical leader for a dedicated team of Security Analysts and Security Engineers. They are accountable for ensuring SecOps team operates efficiently, mitigates threats in a timely manner, and matures organizational cyber defense programs. The SOC Team Lead leverages their highly technical expertise, leadership communication and decision-making skills to enable the team and cross-department collaboration.
What Success Looks Like- Lead by example working consistently with the nuHarbor values: Help Clients Win, Always Improve, Protect the House.
- Are responsible and accountable for analyzing security alerts, events, and trends to effectively communicate the value of NuHarbor services.
- Conduct investigations independently and provide actionable, context-relevant escalations and recommendations to clients.
- Support the security analysts with ticket intake, disposition, and escalation within SLA requirements.
- Serve as the primary technical escalation point for complex or high-severity security incidents. Guide the investigation and response efforts to ensure timely and effective remediation.
- Perform regular quality assurance checks on analysts' work, including alert triage, investigation notes, and incident reports, to ensure accuracy, thoroughness, and adherence to established procedures.
- Contribute to the development, documentation, and refinement of SOC processes, standard operating procedures (SOPs).
- Train, mentor, and support security analysts and security engineers autonomously.
- Develop recommendations and enhancements to mature a client's cybersecurity program as a trusted cross-team liaison.
- Demonstrate a team-first mindset and proactively support operations without direct leader assignment.
- Communicate effectively with leadership or key stakeholders regarding escalations or advanced threats that require incident response actions.
- Provide constructive, real-time feedback to analysts and engineers on their technical work and help them develop their skills and career goals.
- Perform 1 on 1 meetings with security analysts and security engineers.
Your FoundationWe're looking for someone who brings these minimum qualifications:
- Bachelor's Degree in a related field and five (5) or more years in Security Operations (SecOps).
- In lieu of a degree, two (2) years of experience in a related technology field and relevant industry certifications are required.
- Experience executing initial triaging and response through Splunk.
- Demonstrated experience executing security event triaging and tuning.
- Demonstrated experience writing playbooks and support procedures.
- Demonstrated experience as a technical lead for security operations.
- Proven experience performing the following advanced techniques: incident response, threat hunting, malware analysis, detection creation, threat intelligence, and automation.
- Strong understanding of Incident Response phases and demonstrated experience responding to security incidents.
- Demonstrated experience with detection engineering and threat hunting through both a SIEM and EDR toolset.
- Demonstrated experience with managing and maintaining Endpoint Detection and Response (EDR) or Security Orchestration Automation and Response solutions.
- CrowdStrike
- SentinelOne
- Splunk Enterprise Security
- Demonstrated experience with scripting in industry standard languages in a manner that supports automation solutions.
- Demonstrated experience communicating and presenting to executive level client stakeholders.
- Demonstrated experience with FedRAMP and NIST 800-53.
- Must be a citizen of the United States.
- Must be located in the Atlanta, GA metro area and willing and able to be in office two days per week.
Stand out WithYou may stand out if you have experience with:
- Seven (7) or more years in the Security Operations (SecOps).
- Holds at least two relevant industry certifications (GCFA, GNFA, GCIH, BTL1, BTL2, CySa+, CISSP, CISM, etc.)
- Technical writing and reporting experience.
- Experience with multiple operating systems (Linux, Cloud providers, Windows), their command lines, processes, and file systems.
- Experience building and scaling Security Operations Centers.
- Experience with static and dynamic malware analysis.
- Experience providing cyber risk recommendations to harden existing security controls.
- Experience identifying gaps within security control architecture.
- Talent for communicating complex topics in an easily digestible manner.
- Experience with artificial intelligence (AI) technologies, deployment, and hardening procedures
- Experience working in multiple cybersecurity disciplines (i.e. Detection Engineering, Threat Hunting, Threat Intelligence, Information Assurance, Security Engineering, etc.)
You can expect:
- A collaborative, high-performing team environment
- Leaders who are invested in your success and development
- Meaningful work that helps organizations protect critical services and missions
- The encouragement to bring your authentic self to work every day
- Competitive pay, performance-based bonus opportunities, generous paid time off, and comprehensive benefits
CompensationThis position has an anticipated base salary range of
$130,000-$150,000 annually, plus eligibility for nuHarbor's annual bonus program with a target opportunity of 10%.
Actual compensation is based on factors including experience, skills, certifications, and geographic location.