Job DescriptionSOC ManagerThe SOC Manager is an experienced cybersecurity operations leader with a strong technical background in network-security monitoring, incident detection, investigation, response, and threat analysis. This position manages SOC personnel and daily operations while coordinating closely with ISSOs, incident-response teams, system owners, and infrastructure teams.
Compensation & BenefitsPay commensurate with experience.
Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice.
SOC Manager Responsibilities Include:- Manage a Security Operations Center or lead enterprise cybersecurity operations.
- Supervise SOC analysts, incident responders, threat hunters, and security engineers.
- Lead security monitoring, alert triage, escalation, investigation, containment, and incident reporting.
- Develop SOC procedures, playbooks, escalation paths, metrics, and operational reports.
- Monitor indicators of compromise and coordinate incident response across technical teams.
- Perform network traffic analysis, intrusion analysis, log analysis, and threat detection.
- Work with SIEM, endpoint detection and response, network detection, IDS/IPS, and threat-intelligence platforms.
- Coordinate vulnerability and incident data with ISSOs for risk assessments, POA&Ms, SSP updates, and continuous monitoring.
- Brief leadership on active threats, incidents, operational risks, and remediation status.
- Support 24x7 operational continuity, shift coverage, and incident escalation as required.
- Perform other job-related duties as assigned.
SOC Manager Experience, Education, Skills, Abilities Requested:- Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related field.
- Minimum of 8 years of relevant cybersecurity experience.
- CISSP, GCIA, or equivalent advanced cybersecurity or intrusion-analysis certification.
- Active Top Secret (TS) security clearance is required. Candidates must possess the required clearance to be considered for this position.
- U.S. citizenship required.
- Must be available during required Department of State core hours and for mission-critical incidents.
- Federal SOC or Department of State cybersecurity experience preferred.
- Experience with Splunk, Microsoft Sentinel, Elastic, QRadar, or comparable SIEM platforms preferred.
- Experience with EDR, IDS/IPS, packet analysis, malware analysis, threat hunting, and digital forensics preferred.
- Familiarity with NIST incident-response guidance, MITRE ATT&CK, CISA reporting requirements, and federal continuous monitoring preferred.
- Experience coordinating with ISSOs, Security Control Assessors, system owners, cloud teams, and vulnerability-management teams preferred.
- Equivalent certifications may include GCIH, GCED, GMON, GCFA, GSLC, CASP+/SecurityX, or other advanced incident-response, intrusion-analysis, or security-operations certifications, subject to customer approval.
- Must pass pre-employment qualifications of Cherokee Federal.
Similar Searchable Job Titles:- SOC Manager
- Security Operations Manager
- Cybersecurity Operations Manager
- Incident Response Manager
- Cyber Defense Operations Lead
Keywords:- SOC Manager, Security Operations, Network Security Monitoring
- Incident Response, Threat Hunting, Intrusion Analysis
- SIEM, Splunk, Sentinel, IDS/IPS, EDR
- MITRE ATT&CK, Packet Analysis, Indicators of Compromise
- CISSP, GCIA, GCIH, Top Secret (TS) Clearance
Pipeline Position Notice: This is a pipeline position intended to identify qualified candidates for anticipated future opportunities. This posting does not represent a current vacancy. Candidates who meet the qualifications may be contacted as positions become available and program requirements are finalized.