AOUSC - SOC Operations Lead / Managed Detection & Response (MDR) Lead

Reposted 8 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
Expert/Leader
Software
The Role
Lead 24x7 SOC and MDR operations for a large federal enterprise: manage analysts, SIEM and EDR/XDR monitoring, triage, incident coordination, playbooks, reporting, metrics (MTTD/MTTR), and executive briefings. Coordinate with threat hunting, detection engineering, CTI, and incident response and support staffing, proposals, and transitions.
Summary Generated by Built In
Position Title
SOC Operations Lead / Managed Detection & Response (MDR) Lead
Position Overview
The SOC Operations Lead will oversee 24x7x365 Security Operations Center (SOC) and Managed Detection & Response (MDR) operations supporting a large federal enterprise environment. The Lead will direct SOC analysts, incident responders, and MDR personnel responsible for security monitoring, alert triage, incident analysis, escalation, containment coordination, reporting, and continuous operational improvement.
The ideal candidate possesses deep experience leading enterprise SOC operations supporting federal agencies, including SIEM operations, endpoint detection and response (EDR), cloud security monitoring, incident coordination, and executive cyber reporting.
Key Responsibilities
  • Lead enterprise SOC and MDR operations supporting on-premises and cloud environments.
  • Oversee 24x7 monitoring, detection, triage, and escalation activities.
  • Direct operational workflows for:
    • SIEM monitoring,
    • alert management,
    • incident coordination,
    • case management,
    • and operational reporting.
  • Manage analyst teams supporting:
    • Splunk,
    • Microsoft Sentinel,
    • CrowdStrike,
    • Sysmon,
    • Windows event logging,
    • and cloud telemetry platforms.
  • Develop and maintain SOC SOPs, playbooks, runbooks, escalation matrices, and reporting procedures.
  • Lead operational metrics reporting including:
    • MTTD,
    • MTTR,
    • false positive rates,
    • automation effectiveness,
    • analyst productivity,
    • and incident impact assessments.
  • Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams.
  • Brief executives and government leadership on significant incidents, operational trends, and emerging threats.
  • Support proposal development, oral presentations, staffing, and transition planning.
Required Qualifications
  • 10+ years of cybersecurity operations experience.
  • 5+ years leading enterprise SOC or MDR environments.
  • Experience supporting federal civilian or DoD environments.
  • Experience managing large-scale SOC operations in environments exceeding:
    • 10,000+ users,
    • enterprise cloud environments,
    • and large SIEM deployments.
  • Experience with:
    • Splunk Enterprise Security,
    • Microsoft Sentinel,
    • CrowdStrike,
    • EDR/XDR platforms,
    • SOAR technologies,
    • and cloud security monitoring.
  • Deep understanding of:
    • MITRE ATT&CK,
    • incident response,
    • detection engineering,
    • and threat-informed defense.
  • Strong executive briefing and oral presentation skills.
Preferred Certifications
  • CISSP
  • GCIA
  • GCIH
  • GMON
  • GSOC
  • Splunk Architect/Admin certifications
  • Microsoft Security certifications

Skills Required

  • 10+ years of cybersecurity operations experience.
  • 5+ years leading enterprise SOC or MDR environments.
  • Experience supporting federal civilian or DoD environments.
  • Experience managing large-scale SOC operations (10,000+ users, enterprise cloud, large SIEM deployments).
  • Experience with Splunk Enterprise Security.
  • Experience with Microsoft Sentinel.
  • Experience with CrowdStrike and EDR/XDR platforms.
  • Experience with SOAR technologies and cloud security monitoring.
  • Deep understanding of MITRE ATT&CK, incident response, detection engineering, and threat-informed defense.
  • Strong executive briefing and oral presentation skills.
  • Splunk Architect/Admin, CISSP, GCIA, GCIH, GMON, GSOC, or Microsoft Security certifications.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Largo, MD
25 Employees
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint. cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365. Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Similar Jobs

Samsara Logo Samsara

Scientist

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
170K-319K Annually

Cloudflare Logo Cloudflare

Senior Customer Engineer, Named

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
4400 Employees

Cloudflare Logo Cloudflare

Marketing Events and Campaigns Intern (Fall 2026)

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Washington, DC, USA
4400 Employees
24-24 Hourly

Sprout Social Logo Sprout Social

Customer Success Manager

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
US
1400 Employees
92K-153K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account