AOUSC - SOC Manager

cFocus Software Incorporated

Washington (District of Columbia)

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

cFocus Software seeks a SOC Manager to join our program supporting AOUSC. The position is hybrid with onsite in Washington, DC, and requires a Public Trust clearance.

You will lead 24x7x365 SOC operations, oversee incident response, and ensure adherence to JSOCIRP and AO escalation procedures. You will coordinate alerts via Splunk, Microsoft Sentinel, ServiceNow, and Jira, manage SOC staff and forensic teams, and deliver executive-level reporting.

Qualifications

  • Active Public Trust clearance is required.
  • B.S. in Computer Science, Information Technology, or related field.
  • 7+ years in an active incident responder role with SOC leadership for 5,000+ endpoints.
  • 2+ years implementing IR in a federal environment per NIST guidelines.
  • 2+ years using Splunk SIEM for alert correlation.
  • 3+ years auditing Linux/Windows for cybersecurity services.
  • Strong technical writing for executive-level reporting.
  • NICE PD-WRL-001 alignment.
  • Active SANS GCIH or GCIA certification.

Responsibilities

  • Provide operational leadership for 24x7x365 SOC operations supporting Judiciary cybersecurity activities.
  • Oversee incident response, containment, remediation, recovery, and post-incident reviews.
  • Ensure adherence to JSOCIRP, SOPs, and AO escalation procedures.
  • Oversee alert triage using Splunk ES, Microsoft Sentinel, ServiceNow, Jira, and other government systems.
  • Ensure timely acknowledgment, triage, escalation and handling of cybersecurity alerts per SLA.
  • Lead coordination during Priority 1 and 2 incidents and government notification.
  • Develop and maintain SOC triage instructions and incident handling SOPs.
  • Manage SOC analysts and forensic personnel for staffing and performance.
  • Review incident reports, PIRs, malware analyses, and status reporting.
  • Coordinate with AO leadership and stakeholders regarding incidents and threats.
  • Document all cybersecurity activities in ServiceNow and other systems.

Skills

Active Public Trust clearance
Technical writing skills
Executive communication

Education

B.S. Computer Science/Information Technology or related field

Tools

Splunk SIEM
Microsoft Sentinel
ServiceNow
Jira

Job description

cFocus Software seeks a SOC Manager to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.

Qualifications
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 7+ years’ experience in an active incident responder position; two (2) years of recent (within the last five (5) years) experience providing technical direction to a SOC (over 5,000 endpoints).
  • 2+ years of experience implementing IR in a federal environment in accordance with federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide.
  • 2+ years of experience using Splunk SIEM to correlate cybersecurity alerts.
  • 3+ years’ experience in auditing using operating system (Linux and Windows) to perform cybersecurity services.
  • Strong technical writing skills to effectively communicate complex analytical findings and produce clear, concise, well-structured reporting to include executive audience level reports.
  • This role aligns to the NICE work role PD-WRL-001 (Defensive Cybersecurity).
  • Active SANS GCIH or GCIA certification
Duties
  • Provide operational leadership and management oversight for 24x7x365 SOC operations supporting Judiciary cybersecurity activities.
  • Manage cybersecurity triage, incident response, containment, remediation, recovery, and post-incident review activities.
  • Ensure operational adherence to the Judiciary Security Operations Center Incident Response Plan (JSOCIRP), SOC Standard Operating Procedures (SOPs), and AO-defined escalation procedures.
  • Oversee alert triage activities utilizing Splunk Enterprise Security, Microsoft Sentinel, ServiceNow, Jira, and other approved Government systems.
  • Ensure timely acknowledgment, triage, escalation, and handling of cybersecurity alerts in accordance with SLA requirements and incident prioritization timelines.
  • Lead operational coordination during Priority 1 and Priority 2 cybersecurity incidents and ensure timely government notification and escalation.
  • Oversee development and maintenance of cybersecurity triage work instructions, incident handling SOPs, response action procedures, and operational documentation.
  • Manage SOC analysts, incident responders, and forensic personnel to ensure staffing coverage, operational readiness, and quality performance.
  • Review and validate cybersecurity incident reports, post-incident reviews (PIRs), forensic reports, malware analysis reports, and operational status reporting.
  • Coordinate with AO leadership, federal staff, watch officers, branch chiefs, and stakeholders regarding cybersecurity incidents, operational risks, and emerging threats.
  • Ensure accurate documentation of all cybersecurity activities, artifacts, timelines, and communications within ServiceNow and other authorized systems.
  • Manage operational metrics including Mean Time to Acceptance (MTTA), Mean Time to Triage (MTTT), containment timelines, remediation timelines, and quality assurance metrics.
  • Conduct weekly technical meetings and provide operational briefings, metrics, trends, risk assessments, and remediation recommendations.
  • Develop and maintain Common Operational Picture (COP) awareness and cybersecurity operational reporting for AO stakeholders.
  • Support continuous improvement initiatives by identifying detection gaps, process inefficiencies, workflow improvements, and operational enhancements.
  • Coordinate cybersecurity forensics and malware analysis activities including evidence preservation, malware analysis, root cause analysis, and artifact review.
  • Ensure operational compliance with NIST SP 800-53, NIST SP 800-61, NIST Cybersecurity Framework (CSF) 2.0, and ITIL v4 principles.
  • Support transition-in and transition-out activities including onboarding, operational readiness, training, and knowledge transfer.
  • Provide executive-level and technical-level cybersecurity briefings, reports, and presentations.
  • Support enterprise security awareness reporting and development of operational KPIs.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AOUSC - Program Manager
AOUSC - Program Manager

cFocus Software Incorporated • Washington

Hybrid
USD 120,000 - 170,000
AOUSC - Detection Engineering Lead
AOUSC - Detection Engineering Lead

cFocus Software Incorporated • Washington

Hybrid
USD 130,000 - 170,000
AOUSC - Cybersecurity Shift Lead
AOUSC - Cybersecurity Shift Lead

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 150,000
AOUSC - Forensic and Malware Lead
AOUSC - Forensic and Malware Lead

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 190,000
AOUSC - Cybersecurity Triage Analyst
AOUSC - Cybersecurity Triage Analyst

cFocus Software Incorporated • Washington

Hybrid
USD 70,000 - 100,000
AOUSC - Threat Hunt Lead
AOUSC - Threat Hunt Lead

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 170,000
AOUSC - Detection Engineering Lead
AOUSC - Detection Engineering Lead

cFocus Software Incorporated • Washington

Hybrid
USD 150,000 - 190,000
AOUSC - Cyber Exercises Support Lead
AOUSC - Cyber Exercises Support Lead

cFocus Software Incorporated • Washington

Hybrid
USD 90,000 - 120,000
AOUSC - Blue Team Lead
AOUSC - Blue Team Lead

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 210,000
AOUSC - Cyber Exercises Support Lead
AOUSC - Cyber Exercises Support Lead

cFocus Software Incorporated • Washington

Hybrid
USD 110,000 - 160,000