AOUSC - SOC Operations Lead / Managed Detection & Response (MDR) Lead

cFocus Software Incorporated

Washington (District of Columbia)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

cFocus Software Incorporated is seeking a SOC Operations Lead / MDR Lead to direct 24x7x365 security operations for a major federal enterprise. You will oversee SOC analysts, incident responders, and MDR personnel across on-prem and cloud environments.

The ideal candidate has 10+ years in cybersecurity operations and proven experience in enterprise SOC/MDR, including SIEM, EDR, and cloud monitoring, with strong executive briefing skills.

Qualifications

  • 10+ years of cybersecurity operations experience.
  • Experience leading enterprise SOC or MDR environments.
  • Experience supporting federal civilian or DoD environments.
  • Experience with Splunk ES, MS Sentinel, CrowdStrike, and SOAR tools.

Responsibilities

  • Lead enterprise SOC and MDR operations for on-premises and cloud environments.
  • Oversee 24x7 monitoring, detection, triage, and escalation activities.
  • Direct operational workflows for SIEM monitoring, alert management, incident coordination, case management, and reporting.
  • Manage analyst teams supporting SIEM, EDR, cloud telemetry platforms.
  • Develop and maintain SOC SOPs, playbooks, runbooks, and escalation matrices.
  • Lead operational metrics reporting (MTTD, MTTR, false positives, automation).
  • Coordinate with Threat Hunting, CTI, Detection Engineering, and Incident Response teams.
  • Brief executives on incidents, trends, and threats; support proposals and staffing.

Skills

SOC Leadership
MDR Operations
Incident Response
Executive Briefing
Threat Intelligence Collaboration

Tools

Splunk Enterprise Security
Microsoft Sentinel
CrowdStrike
EDR/XDR platforms
SOAR technologies

Job description

Position Title

SOC Operations Lead / Managed Detection & Response (MDR) Lead

Position Overview

The SOC Operations Lead will oversee 24x7x365 Security Operations Center (SOC) and Managed Detection & Response (MDR) operations supporting a large federal enterprise environment. The Lead will direct SOC analysts, incident responders, and MDR personnel responsible for security monitoring, alert triage, incident analysis, escalation, containment coordination, reporting, and continuous operational improvement.

The ideal candidate possesses deep experience leading enterprise SOC operations supporting federal agencies, including SIEM operations, endpoint detection and response (EDR), cloud security monitoring, incident coordination, and executive cyber reporting.

Key Responsibilities
  • Lead enterprise SOC and MDR operations supporting on-premises and cloud environments.
  • Oversee 24x7 monitoring, detection, triage, and escalation activities.
  • Direct operational workflows for:
    • SIEM monitoring
    • alert management
    • incident coordination
    • case management
    • and operational reporting
  • Manage analyst teams supporting:
    • Splunk
    • Microsoft Sentinel
    • CrowdStrike
    • Sysmon
    • Windows event logging
    • and cloud telemetry platforms
  • Develop and maintain SOC SOPs, playbooks, runbooks, escalation matrices, and reporting procedures.
  • Lead operational metrics reporting including:
    • MTTD
    • MTTR
    • false positive rates
    • automation effectiveness
    • analyst productivity
    • and incident impact assessments
  • Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams.
  • Brief executives and government leadership on significant incidents, operational trends, and emerging threats.
  • Support proposal development, oral presentations, staffing, and transition planning.
Required Qualifications
  • 10+ years of cybersecurity operations experience.
  • 5+ years leading enterprise SOC or MDR environments.
  • Experience supporting federal civilian or DoD environments.
  • Experience managing large-scale SOC operations in environments exceeding:
    • 10,000+ users
    • enterprise cloud environments
    • and large SIEM deployments
  • Experience with:
    • Splunk Enterprise Security
    • Microsoft Sentinel
    • CrowdStrike
    • EDR/XDR platforms
    • SOAR technologies
    • and cloud security monitoring
  • Deep understanding of:
    • MITRE ATT&CK
    • incident response
    • detection engineering
    • and threat-informed defense
  • Strong executive briefing and oral presentation skills.
Preferred Certifications
  • CISSP
  • GCIA
  • GCIH
  • GMON
  • GSOC
  • Splunk Architect/Admin certifications
  • Microsoft Security certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center Manager
Security Operations Center Manager

Fidelity National Financial • Jacksonville (FL)

On-site
USD 140,000 - 180,000
SOC Manager
SOC Manager

K&A Technologies LLC • Washington

On-site
USD 120,000 - 150,000
Security Operations Center (SOC) Manager/Team Lead
Security Operations Center (SOC) Manager/Team Lead

Ariento • Franklin (TN)

On-site
USD 100,000 - 130,000
AOUSC - SOC Manager
AOUSC - SOC Manager

cFocus Software Incorporated • Washington

Hybrid
USD 140,000 - 190,000
Senior Federal SOC Operations & MDR Lead
Senior Federal SOC Operations & MDR Lead

cFocus Software Incorporated • Washington

On-site
USD 140,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Managed Detection and Response (MDR) Operations Manager
Managed Detection and Response (MDR) Operations Manager

SecureSky, Inc • Omaha (NE)

On-site
USD 110,000 - 160,000
SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000
SOC Manager
SOC Manager

Fulcrum Technology Solutions • United States

On-site
USD 100,000 - 130,000