Security Operations Lead in at Crest Security Assurance
Explore Related Opportunities
Job Description
Security Operations Center (SOC) Lead (US Citizenship Required)
Leads daily Security Operations Center (SOC) operations, overseeing security monitoring, threat detection, incident triage, analyst performance, staffing, and resource management. Ensures effective SOC coverage during 12-hour operational shifts (6:00 AM–6:00 PM), including holidays, while maintaining service levels, operational readiness, and continuous improvement of enterprise threat detection capabilities.
Key Responsibilities
- Manage daily SOC operations, personnel, staffing schedules, resource allocation, shift coverage, workload distribution, and analyst performance.
- Develop and maintain staffing plans supporting 12-hour SOC operations (6:00 AM–6:00 PM), including weekends and holidays, ensuring adequate coverage, backup personnel, and continuity of operations.
- Supervise SOC analysts, assign responsibilities, manage attendance and leave, oversee shift handoffs, provide technical guidance, and conduct performance evaluations.
- Monitor staffing utilization, operational capacity, service-level compliance, and resource requirements; identify coverage gaps and implement corrective actions.
- Oversee security monitoring, alert triage, threat detection, event correlation, and investigation across enterprise networks, endpoints, applications, and cloud environments.
- Manage SOC technologies, including SIEM, SOAR, EDR/XDR, IDS/IPS, and threat intelligence platforms such as Splunk, Microsoft Defender, and other approved security tools.
- Direct the development, tuning, and optimization of detection rules, correlation searches, dashboards, security alerts, and automated response playbooks.
- Ensure timely identification, classification, investigation, documentation, and escalation of cybersecurity incidents to incident response teams.
- Apply MITRE ATT&CK tactics, techniques, and procedures (TTPs) to strengthen threat detection, threat hunting, alert fidelity, and investigation capabilities.
- Monitor security tool availability, log ingestion, telemetry coverage, detection gaps, and integration performance to maintain enterprise security visibility.
- Develop and maintain SOC CONOPS, SOPs, operational runbooks, shift handoff procedures, and escalation workflows aligned with NIST and applicable federal requirements.
- Coordinate with incident response, vulnerability management, security engineering, and infrastructure teams to address emerging threats and security weaknesses.
- Track SOC performance metrics, including MTTD, MTTA, alert volume, investigation timelines, analyst productivity, staffing coverage, and SLA compliance.
- Prepare operational reports, dashboards, incident summaries, and executive briefings while driving analyst training, quality assurance, and continuous improvement.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- 8+ years of cybersecurity experience, including 5+ years leading SOC or enterprise security operations teams.
- Demonstrated experience managing SOC staffing, resource planning, personnel performance, and 12-hour shift operations.
- Hands-on experience with SIEM, SOAR, EDR/XDR, network security monitoring, threat intelligence, and security event analysis.
- Strong knowledge of MITRE ATT&CK, detection engineering, incident triage, threat hunting, and SOC operational procedures.
- Proven ability to manage operational priorities, staffing coverage, escalation procedures, and service-level performance.
Preferred Qualifications
- Experience supporting federal cybersecurity operations in complex enterprise environments.
- Familiarity with NIST SP 800-53, NIST SP 800-61, FISMA, and federal continuous monitoring requirements.
- Experience with SOC automation, security tool integration, detection optimization, and executive reporting.
- CISSP, CySA+, GCIH, GCIA, or equivalent cybersecurity certification.
Clearance Requirements
Must be a U.S. Citizen; Public Trust or higher clearance required.
Work Environment
Hybrid role based in Alexandria, VA. Initial 30 days onsite, followed by 2–3 days onsite per week. SOC operates on 12-hour shifts from 6:00 AM to 6:00 PM, including weekends and federal holidays.