USAF - SOC Lead

Posted Yesterday
Be an Early Applicant
Linthicum Heights, MD, USA
In-Office
Entry level
Software
The Role
Leads SOC analysts and response personnel supporting the United States Air Force. Oversees alert triage, threat hunting, investigations, incident response, vulnerability remediation, staffing, coverage, compliance documentation, and Government reporting. Coordinates defensive cyber operations across IT and OT environments, manages cyber taskers, supports RMF activities, evaluates SOC tools and telemetry, and improves incident response procedures and operational readiness. The role is on-site in Linthicum Heights, Maryland and requires an active TS/SCI clearance.
Summary Generated by Built In
cFocus Software seeks a SOC Lead to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.
Qualifications:
  • Active TS/SCI clearance
  • B.S. Computer Science, Information Technology, or a related field
  • Experience leading SOC personnel or comparable defensive cybersecurity operations.
  • Experience directing alert triage, threat hunting, investigations, and incident response.
  • Ability to manage operational priorities, analyst development, coverage, and handoffs.
  • Knowledge of networks, endpoints, cloud environments, logs, and common cyberattack techniques.
  • Experience with security monitoring, endpoint detection, vulnerability tools, and detection tuning.
  • Ability to coordinate remediation and response across operations, engineering, and cybersecurity teams.
  • Understanding of evidence handling, secure configurations, compliance records, and operational risk.
  • Strong judgment and communication skills for timely Government reporting and incident coordination
Duties:
  • Lead SOC analysts and assigned response personnel; prioritize work, coach staff, review investigations, and maintain clear accountability for operational actions.
  • Plan assigned staffing, coverage, on-call rotations, and handoffs to support required on-site and global response capabilities.
  • Support SOC stand-up planning, tool configuration, sensor integration with command and control (C2) nodes, and enterprise scanning readiness.
  • Coordinate centralized defensive operations, including monitoring, penetration testing support, threat hunting, cyber orders and taskers, and incident response.
  • Oversee alert triage and analysis of security events and trends; validate findings, assess mission impact, and direct approved mitigation actions.
  • Lead data and intelligence-driven threat hunting and anomaly investigations across DC3 information technology (IT) and operational technology (OT) environments.
  • Direct incident detection, investigation, escalation, and approved containment, eradication, and recovery; keep Government stakeholders informed under established procedures.
  • Review investigation evidence, incident timelines, and reports for accuracy and completeness; ensure response actions and handoffs are documented.
  • Coordinate weekly vulnerability assessments with certified specialists; prioritize findings and track remediation with infrastructure, application, and cybersecurity teams.
  • Maintain effective C2 coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities.
  • Manage assigned cyber orders and taskers, coordinate implementation, and support required compliance documentation and Plans of Action and Milestones (POA&Ms).
  • Assess SOC tools, telemetry coverage, and resource needs; recommend procurement and operational improvements through approved Government processes.
  • Maintain incident response procedures, escalation guides, and operational documentation; incorporate lessons learned and submit required updates for Government approval.
  • Coordinate with ISSOs and the ISSM to provide monitoring evidence and remediation status supporting RMF, authorization, and enterprise risk activities.
  • Recommend improvements based on emerging threats, cybersecurity practices, and technologies, including benefits, risks, and implementation approaches.

Skills Required

  • Active TS/SCI security clearance
  • Bachelor of Science degree in Computer Science, Information Technology, or a related field
  • Experience leading SOC personnel or comparable defensive cybersecurity operations
  • Experience directing alert triage, threat hunting, investigations, and incident response
  • Ability to manage operational priorities, analyst development, coverage, and handoffs
  • Knowledge of networks, endpoints, cloud environments, logs, and common cyberattack techniques
  • Experience with security monitoring, endpoint detection, vulnerability tools, and detection tuning
  • Ability to coordinate remediation and response across operations, engineering, and cybersecurity teams
  • Understanding of evidence handling, secure configurations, compliance records, and operational risk
  • Strong judgment and communication skills for Government reporting and incident coordination
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Largo, MD
25 Employees
Year Founded: 2006

What We Do

Established in 2006, cFocus Software automates FedRAMP compliance and develops government chatbots for the Azure Government Cloud, Office 365, and SharePoint. cFocus Software is the exclusive vendor of ATO (Authority To Operate) as a Service™, which automates FedRAMP compliance for the Azure Government Cloud and Office 365. Contact Us for a demo of ATO as a Service™ or a FREE government chatbot proof of concept project today!

Similar Jobs

Ahold Delhaize USA Logo Ahold Delhaize USA

Specialist Executive Operations

AdTech • eCommerce • Food • Marketing Tech • Retail
Hybrid
Hyattsville, MD, USA
10000 Employees
63K-109K Annually

Optum Logo Optum

RN Case Manager - HouseCalls - Remote - EST or CST - Compact license Required

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office or Remote
Columbia, MD, USA
160000 Employees
60K-107K Annually

Optum Logo Optum

Specialty Pharmacy Liaison - Onsite

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Hagerstown, MD, USA
160000 Employees
18-32 Hourly

Shield AI Logo Shield AI

Senior Lead, Enterprise Strategy and Operations (R5624)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software • Defense Technology
In-Office or Remote
4 Locations
160K-240K Annually

Similar Companies Hiring

Ford Energy Thumbnail
Automotive • Software • Energy • Utilities • Manufacturing • Renewable Energy
US
55 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account