AOUSC - SOC Manager

Posted 12 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
Senior level
Software
The Role
Lead and manage 24x7x365 SOC operations for the AOUSC, overseeing alert triage, incident response, containment, remediation, forensics, and post-incident reviews. Ensure adherence to NIST and ITIL standards, manage SOC staff and operational metrics, maintain SOPs and work instructions, coordinate with stakeholders, provide executive and technical briefings, and support continuous improvement, onboarding, and transition activities.
Summary Generated by Built In
cFocus Software seeks a SOC Manager to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 7+ years’ experience in an active incident responder position; two (2) years of recent (within the last five (5) years) experience providing technical direction to a SOC (over 5,000 endpoints).
  • 2+ years of experience implementing IR in a federal environment in accordance with federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide.
  • 2+ years of experience using Splunk SIEM to correlate cybersecurity alerts.
  • 3+ years’ experience in auditing using operating system (Linux and Windows) to perform cybersecurity services.
  • Strong technical writing skills to effectively communicate complex analytical findings and produce clear, concise, well-structured reporting to include executive audience level reports,
  • This role aligns to the NICE work role PD-WRL-001 (Defensive Cybersecurity).
  • Active SANS GCIH or GCIA certification

Duties:
  • Provide operational leadership and management oversight for 24x7x365 SOC operations supporting Judiciary cybersecurity activities.
  • Manage cybersecurity triage, incident response, containment, remediation, recovery, and post-incident review activities.
  • Ensure operational adherence to the Judiciary Security Operations Center Incident Response Plan (JSOCIRP), SOC Standard Operating Procedures (SOPs), and AO-defined escalation procedures.
  • Oversee alert triage activities utilizing Splunk Enterprise Security, Microsoft Sentinel, ServiceNow, Jira, and other approved Government systems.
  • Ensure timely acknowledgment, triage, escalation, and handling of cybersecurity alerts in accordance with SLA requirements and incident prioritization timelines.
  • Lead operational coordination during Priority 1 and Priority 2 cybersecurity incidents and ensure timely government notification and escalation.
  • Oversee development and maintenance of cybersecurity triage work instructions, incident handling SOPs, response action procedures, and operational documentation.
  • Manage SOC analysts, incident responders, and forensic personnel to ensure staffing coverage, operational readiness, and quality performance.
  • Review and validate cybersecurity incident reports, post-incident reviews (PIRs), forensic reports, malware analysis reports, and operational status reporting.
  • Coordinate with AO leadership, federal staff, watch officers, branch chiefs, and stakeholders regarding cybersecurity incidents, operational risks, and emerging threats.
  • Ensure accurate documentation of all cybersecurity activities, artifacts, timelines, and communications within ServiceNow and other authorized systems.
  • Manage operational metrics including Mean Time to Acceptance (MTTA), Mean Time to Triage (MTTT), containment timelines, remediation timelines, and quality assurance metrics.
  • Conduct weekly technical meetings and provide operational briefings, metrics, trends, risk assessments, and remediation recommendations.
  • Develop and maintain Common Operational Picture (COP) awareness and cybersecurity operational reporting for AO stakeholders.
  • Support continuous improvement initiatives by identifying detection gaps, process inefficiencies, workflow improvements, and operational enhancements.
  • Coordinate cybersecurity forensics and malware analysis activities including evidence preservation, malware analysis, root cause analysis, and artifact review.
  • Ensure operational compliance with NIST SP 800-53, NIST SP 800-61, NIST Cybersecurity Framework (CSF) 2.0, and ITIL v4 principles.
  • Support transition-in and transition-out activities including onboarding, operational readiness, training, and knowledge transfer.
  • Provide executive-level and technical-level cybersecurity briefings, reports, and presentations.
  • Support enterprise security awareness reporting and development of operational KPIs.

Skills Required

  • Active Public Trust clearance
  • B.S. in Computer Science, Information Technology, or related field
  • 7+ years experience in an active incident responder position
  • 2+ years recent experience providing technical direction to a SOC (over 5,000 endpoints)
  • 2+ years implementing incident response in a federal environment per NIST guidelines (SP-800-61, CSF)
  • 2+ years using Splunk SIEM to correlate cybersecurity alerts
  • 3+ years auditing using Linux and Windows operating systems for cybersecurity services
  • Strong technical writing skills for clear, concise analytical and executive reporting
  • Alignment to NICE work role PD-WRL-001 (Defensive Cybersecurity)
  • Active SANS GCIH or GCIA certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Largo, MD
25 Employees
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint. cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365. Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Similar Jobs

Snap Inc. Logo Snap Inc.

Integrated Circuit Design Verification Engineer

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Remote or Hybrid
Washington, DC, USA
5000 Employees
147K-259K Annually

Bilt Logo Bilt

Business Development Representative

Fintech • Mobile • Real Estate • Financial Services • PropTech
In-Office
Washington, DC, USA
200 Employees
50K-85K Annually

Samsara Logo Samsara

Operations Specialist

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
79K-106K Annually

SoFi Logo SoFi

Customer Service Representative

Fintech • Mobile • Software • Financial Services
Easy Apply
Remote or Hybrid
United States
4500 Employees
17-25 Hourly

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account