ROC Lead

Posted Yesterday
Be an Early Applicant
Pearl City, HI, USA
In-Office
Expert/Leader
Information Technology • Analytics • Cybersecurity • Defense
The Role
Leads regional cybersecurity operations and incident-response campaign administration across 24/7/365 Regional Operations Centers. Oversees incident prioritization, investigation quality, reporting, documentation, SOP compliance, stakeholder coordination, ticket reviews, resource allocation, and surge support. Develops training curricula, leads tabletop exercises, mentors analysts, and drives process improvement while ensuring adherence to DoD cyber incident-handling requirements.
Summary Generated by Built In

Sentar is proud to be an employee-owned company, fostering a culture of empowerment, collaboration, and innovation. Sentar is dedicated to developing the critical talent that the connected world demands to create solutions to address the convergence of cybersecurity, intelligence, analytics, and systems engineering. We invite you to join the team where you can build, innovate, and secure your career.

Sentar is seeking a ROC Lead in Hawaii!

Role Description:

As the ROC Lead, you provide operational leadership and administrative oversight for cybersecurity defense activities within your assigned region. You direct the prioritization, coordination, and quality control of incident identification, isolation, investigation, while informing stakeholders and implementing lessons learned to protect data across diverse sources and locations.
You serve as the primary Training Lead for ROC personnel, ensuring team proficiency through structured training programs, curriculum development, and leadership of tabletop exercises. Your core focus is managing the end-to-end incident response campaign lifecycle—task assignment, documentation, reporting accuracy, inter-agency coordination, and continuous process improvement—while mentoring analysts and maintaining operational readiness across 24/7 operations.

Qualifications:

  • Bachelor’s degree in Cybersecurity, Computer, Electrical, or Electronics Engineering, or Mathematics with a concentration in computer science or equivalent with 5 years of relevant cybersecurity / Security Operations Center (SOC) experience OR at least 8 years of experience in a SOC or similar environment.
  • Minimum of 4 years of experience leading or managing incident response cases.
  • Position may require up to 10% travel.
  • Support 24/7/365 operations across three Regional Operations Centers (ROC).
  • Work overtime as required to support incident response actions (surge operations).
  • Must meet Department of Defense (DoD) 8570 Information Assurance Technical (IAT) Level II and Computer Network Defense Service Provider (CNDSP) Analyst certification requirements.
  • Must also hold a relevant DoD 8570 Operation System / Computing Environment (OS/CE) certification: FEDVTE Linux OS; FEDVTE Windows OS; Server+

Preferred Qualifications:

  • Strong working knowledge of CJCSM 6510.01B and DoD cyber incident handling processes.
  • Proven experience in project or campaign management within an operations center or incident response environment (planning, tracking, documentation, and closure of complex efforts).
  • Experience developing or maintaining SOPs, training curricula, or quality assurance processes.
  • Demonstrated ability to lead tabletop exercises, training programs, or professional development activities.
  • Experience mentoring or supervising junior analysts/operators in a high-tempo environment.
  • Familiarity with common SOC tools and workflows sufficient to perform effective quality oversight (deep hands-on expertise in IDS/IPS signature development, digital forensics, or advanced log correlation is not required).

Highly Desired

  • Exceptional verbal and written communication skills, including the ability to brief leadership, draft clear reports, and coordinate across organizations.
  • Proven project management or operational leadership skills (ability to plan, prioritize, track, and close complex multi-shift efforts).
  • Strong logical thinking, analytical ability, and independent problem-solving under time pressure.

Responsibilities:

  • Lead and guide administrative functions during incident response campaigns, ensuring all tasks are assigned, completed, vetted, documented, and closed in accordance with established processes and timelines.
  • Coordinate with reporting agencies, subscriber sites, and higher headquarters to ensure timely, accurate, and complete incident reporting and information sharing.
  • Oversee quality assurance reviews of validated security incidents, confirming severity and impact determinations align with Chairman of the Joint Chiefs of Staff Manual (CJCSM) 6510.01B and applicable directives.
  • Manage ticket review processes and indicator/analysis quality control to maintain reporting standards and operational consistency.
  • Ensure disciplined turnover of tasks, findings, and situational awareness through structured verbal turnovers and written shift roll-up documentation.
  • Compile, maintain, and continuously improve internal Standard Operating Procedure (SOP) documentation; enforce compliance with CJCSM 6510.01B and other governing directives.
  • Provide structured mentorship and performance feedback to ROC analysts to improve triage efficiency, decision-making, and professional development.
  • Plan, execute, and evaluate training programs, including curriculum development and facilitation of tabletop exercises that enhance team readiness and response capabilities.
  • Participate in and support program reviews, product evaluations, process improvement initiatives, and onsite certification evaluations as required.
  • Coordinate resource allocation, surge support, and cross-shift prioritization to sustain 24/7/365 operations across the three ROCs.
  • Maintain sufficient working knowledge of security concepts, protocols, processes, architectures, and tools to effectively oversee analyst work products and provide informed guidance (deep technical execution remains with analysts).

    Clearance Level:

    Secret, with ability to obtain Top Secret/Sensitive Compartmented Information (TS/SCI)

    Education:

    Bachelor’s degree in Cybersecurity, Computer, Electrical, or Electronics Engineering, or Mathematics with a concentration in computer science or equivalent with 5 years of relevant cybersecurity / Security Operations Center (SOC) experience OR at least 8 years of experience in a SOC or similar environment.

    Benefits at Sentar:

    Our unique employee ownership model attracts top talent, giving employees the freedom to take initiative and drive meaningful improvements. In addition to cultivating a thriving and inclusive work environment, Sentar offers an extensive benefits package designed to support the well-being of employees and their families. Employee ownership is the foundation of our culture, promoting participation, teamwork, and accountability while ensuring long-term financial security and a commitment to excellence.

    • Voluntary Medical, Dental, Vision, with Flexible Spending Plan options
    • Voluntary Life, Critical Illness, Accident, and Long Term Care insurance options
    • Group Term Life, Short-Term and Long-Term Disability is provided by Sentar to all qualifying employees
    • Generous 401(k) match
    • Competitive PTO plan that graduates quickly with years of service
    • Other leave programs; holiday schedule along with bereavement, maternity, jury and military duty
    • Tuition reimbursement
    • Professional development reimbursement
    • Recognition and Awards programs

    If you are not ready to apply for this position, submit your resume here to join our talent community. We'll keep you updated occasionally on new job opportunities.

    Sentar is an Affirmative Action and Equal Opportunity Employer M/F/Vets/Persons with Disabilities

    Our culture is one of inclusivity and support. Sentar is proudly an Equal Opportunity and VEVRAA Federal Contractor Employer M/F/Vets/Persons with Disabilities. Follow these links to learn more about your rights: EEO Is the Law Poster; EEO Is Law Supplement; and Pay Transparency.

    We want you to build your career at Sentar, so if you are an individual with a disability and require a reasonable workplace accommodation applying for a job or at any point in the employment process, contact the Recruiting Manager at [email protected]. Please indicate the specifics of the assistance needed. Thank you for considering Sentar in your employment search.

    Build, Innovate, Secure Your Career at Sentar.

    Skills Required

    • Bachelor’s degree in Cybersecurity, Computer Engineering, Electrical Engineering, Electronics Engineering, or Mathematics with a computer science concentration, plus five years of relevant cybersecurity or SOC experience; alternatively, eight years of SOC or similar experience.
    • At least four years of experience leading or managing incident response cases.
    • Ability to support 24/7/365 operations across three Regional Operations Centers.
    • Ability to work overtime during incident-response surge operations.
    • DoD 8570 IAT Level II and CNDSP Analyst certification requirements.
    • Relevant DoD 8570 OS/CE certification: FEDVTE Linux OS, FEDVTE Windows OS, or Server+.
    • Working knowledge of CJCSM 6510.01B and DoD cyber incident-handling processes.
    • Experience with project or campaign management in an operations center or incident-response environment.
    • Experience developing or maintaining SOPs, training curricula, or quality-assurance processes.
    • Experience leading tabletop exercises, training programs, or professional-development activities.
    • Experience mentoring or supervising junior analysts or operators.
    • Secret clearance and ability to obtain Top Secret/Sensitive Compartmented Information clearance.
    Am I A Good Fit?
    beta
    Get Personalized Job Insights.
    Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

    The Company
    HQ: Huntsville, AL

    What We Do

    Sentar is a leading cyber-intelligence solutions provider focused on the National Security sector. The company blends expertise in cybersecurity, intelligence and analytics, and systems and software engineering to protect national security by innovating, building, and securing mission-critical assets. Key clients include the U.S. Army, the U.S. Navy, and the Defense Health Agency.

    Similar Jobs

    CDW Logo CDW

    Operations Analyst

    Information Technology
    Remote or Hybrid
    US
    15100 Employees
    26K-31K Hourly

    CDW Logo CDW

    Business Development Manager

    Information Technology
    Remote or Hybrid
    US
    15100 Employees

    MetLife Logo MetLife

    Business Analyst

    Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
    Remote or Hybrid
    United States
    43000 Employees
    42K-55K Annually

    Samsara Logo Samsara

    Firmware Engineer

    Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
    Easy Apply
    Remote or Hybrid
    United States
    4000 Employees
    155K-290K Annually

    Similar Companies Hiring

    NODA AI Thumbnail
    Artificial Intelligence • Information Technology • Software • Cybersecurity
    Sydney, AU
    54 Employees
    Golden Pet Brands Thumbnail
    Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
    El Segundo, California
    178 Employees
    Outpost Space Thumbnail
    Aerospace • Defense
    Los Angeles, California
    38 Employees

    Sign up now Access later

    Create Free Account

    Please log in or sign up to report this job.

    Create Free Account