Security Operations Team Lead

Virginia Department of Human Resource Management

$120K — $140K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of leadership experience in cybersecurity or information security roles.
  • Proven hands-on incident response skills in a security operations center (SOC).
  • Knowledge of security frameworks such as NIST, CIS Controls, and MITRE ATT&CK.
  • Experience tuning Security Information and Event Management (SIEM) alerts and optimizing detection logic.
  • Practical experience with cloud security operations and tools like AWS CloudTrail and Security Hub.
  • Strong collaboration skills with cross-functional teams including application and cloud teams.

Responsibilities

  • Lead and mentor a team of security analysts responsible for threat monitoring and incident response.
  • Ensure effective identification, analysis, prioritization, and remediation of cyber threats.
  • Develop and refine security playbooks, processes, and team workflows to maintain security posture.
  • Oversee the health of log ingestion across monitoring platforms such as Splunk.
  • Utilize AI-assisted analytics tools to enhance threat detection and reduce false positives.
  • Integrate security controls with system administrators and third-party vendors to strengthen cybersecurity.
  • Conduct continuous improvement initiatives through threat intelligence and security assessments.

Benefits

  • Flexible schedule options with up to two days of telework per week.
  • 12 paid state holidays and generous paid leave policies including vacation and sick leave.
  • Comprehensive health benefits that are affordable.
  • Eligibility for the Public Service Loan Forgiveness program for student loans.
  • Participation in retirement plans such as the Virginia Retirement System and VA 457 Deferred Comp.
Full Job Description
Security Operations Team Lead

Job no:
Work type: Full-Time (Salaried)
Location: Richmond (City), Virginia
Categories: Information Technology

Title: Security Operations Team Lead

State Role Title: Information Security Analysts

Hiring Range: $120,000 - $140,000

Pay Band: 6

Agency: Department of Taxation

Location: Main Street Center

Agency Website: https://www.tax.virginia.gov/work-with-us

Recruitment Type: General Public - G

Job Duties

Virginia Tax is seeking a dedicated Security Operations Team Lead based in Richmond, VA, to oversee and enhance our critical cyber defense capabilities. In this role, you will lead and mentor a team of security analysts responsible for monitoring, detecting, and responding to threats against systems and data essential to the Commonwealth's mission.

The Security Operations Team Lead is responsible for guiding a team of security analysts in protecting the organization's systems, data, and infrastructure. This role provides leadership, develops team processes and playbooks, refines security posture, and ensures effective response to cyber threats. The ideal candidate will bring strong technical expertise, proven incident response capabilities, and experience working across multiple teams and technologies.

The ideal candidate brings not only strong technical and leadership skills, but also a forward-looking mindset that helps Virginia Tax continue progressing as a cybersecurity leader within the Commonwealth of Virginia.

About the Role

As the Security Operations Team Lead, you will be part of a mission driven cybersecurity team dedicated to protecting the agency's systems and data. You will demonstrate strong leadership and deep technical expertise while supervising and developing Security Analysts responsible for frontline monitoring and incident response, you will:

Lead daily security monitoring and incident response activities, ensuring threats are identified, analyzed, prioritized, and remediated in alignment with agency standards.

Provide hands-on leadership by guiding analysts through investigations, escalations, containment actions, and coordinated response efforts.

Prioritize and tune SIEM alerts, refine detection logic, and reconcile daily monitoring results to maintain a robust and accurate security posture.

Oversee log ingestion health and data integrity across Splunk and other monitoring platforms, validating sources, diagnosing ingestion issues, and coordinating with system owners to restore visibility.

Leverage AI-assisted security analytics tools to enhance threat detection accuracy, reduce false positives, and accelerate triage within the SOC environment.

Evaluate and implement AI-driven automation to improve alert correlation, anomaly detection, and incident enrichment while ensuring compliance with agency security standards.

Oversee CyberArk Privileged Access Management (PAM) operations, including least privilege enforcement, credential rotation, privileged account monitoring, and secure onboarding of service accounts.

Manage CyberArk or BeyondTrust Endpoint Privilege Management (EPM) processes, including elevation rule design, policy tuning, auditing, and balancing security controls with user productivity.

Support cloud security operations through services such as CloudTrail and Security Hub, ensuring effective detection of misconfigurations, anomalies, and unauthorized activity.

Collaborate with system administrators, application teams, cloud teams, and third-party vendors to integrate security controls, strengthen infrastructure, and ensure secure system configurations.

Develop, maintain, and improve security playbooks, workflows, and procedures to ensure consistency, readiness, and alignment with frameworks such as SEC 530, NIST, CIS Controls, and MITRE ATT&CK.

Drive continuous improvement through integration of threat intelligence, periodic security posture assessments, and enhancement of detection and response capabilities across the SOC.

The position is located at our Main Street Centre location in Richmond Virginia and has a hybrid schedule consisting of 3 days in the office (Tuesday, Wednesday, Thursday) and 2 days teleworking (Monday and Friday).

Candidate must reside within 50 miles of the Richmond office to be eligible for this role.

The salary range for this position is $120,000 to $140,000 commensurate with knowledge, skills, abilities and experience.

As a member of the Virginia Tax team, you can expect additional benefits such as:
• Job stability and quality of life! Enjoy your work/life balance with flexible schedule options and up to two days of telework per week.
• 12 Paid State holidays on top of vacation, sick, volunteer, and personal leave!
• Comprehensive and affordable health benefits.
• Got student loans? You may be eligible for the Public Service Loan Forgiveness program.
• Participation in the Virginia Retirement System, VA 457 Deferred Comp, and more.

Minimum Qualifications

Demonstrated leadership experience guiding and mentoring security analysts, including providing hands-on direction during investigations, escalations, and containment activities.

Strong, hands-on experience performing daily security monitoring and incident response, including identifying, analyzing, prioritizing, and remediating cyber threats.

Practical experience applying security frameworks such as NIST, CIS Controls, SEC 530, and MITRE ATT&CK to develop, maintain, and improve SOC playbooks and workflows.

Experience tuning SIEM alerts, refining detection logic, reconciling monitoring results, and ensuring accuracy of security event and log data.

Experience supporting cloud security operations using tools such as AWS CloudTrail and Security Hub to detect misconfigurations, anomalies, and unauthorized activity.

Ability to collaborate effectively with system administrators, application teams, cloud teams, and vendors to integrate and strengthen security controls across multiple environments.

Additional Considerations

Experience using AI-assisted detection, correlation, or analysis tools within a SOC.

Familiarity with integrating AI into SIEM, SOAR, or cloud-native security platforms.

Industry certification in Information Security such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Offensive Security Certified Professional or Expert (OSCP or OSCE), or Certified Ethical Hacker (CEH), AWS Certified Cloud Practitioner, AWS Certified Security

Special Instructions

You will be provided a confirmation of receipt when your application and/or résumé is submitted successfully. Please refer to "Your Application" in your account to check the status of your application for this position.

All Virginia Tax employees must be current with filing their tax returns ensuring they were filed in compliance with established laws, rules and regulations.

Selected candidate(s) will be required to consent to and successfully pass a background investigation which includes fingerprint-based criminal history, tax compliance, and DMV driving record (if applicable) checks. Selected candidates require a valid Driver's License.

The selected candidate will be prohibited from performing tax or accounting services for compensation during or outside business hours.

Contact Information

Name: Virginia Tax Talent Acquisition Team

Phone: 804-786-3608

Email: [email protected]

Advertised: 14 Sep 2026 Eastern Daylight Time
Applications close: 21 Sep 2026 Eastern Daylight Time

Whatsapp Facebook LinkedIn Email App

Similar Jobs

More Jobs at Virginia Department of Human Resource Management

More Information Technology Jobs

Find similar Security Operations Team Lead jobs: