A complete application in a minute — tailored resume and cover letter, ready to send.
Programmers.io is seeking an experienced Security Operations Center professional to lead daily SOC operations in Draper, UT. The role requires 5+ years in a SOC or cyber defense, with 1-2 years in a lead or senior analyst capacity, and strong skills in incident response, SIEM/EDR, and case management.
You will coordinate cross-functional teams across Tech Operations, IT, and Engineering, including on-call coverage and mentor junior analysts.
5+ years of experience in a Security Operations Center or similar cyber defense role, including at least 1-2 years in a lead, senior analyst, or shift-lead capacity
Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
Working knowledge of SIEM, EDR, and case/ticket management tooling"
Own the SOC case queue: triage incoming alerts, tickets, and requests; assign priority and ownership; track cases through to resolution.
Maintain SLAs for case handling and escalation; identify and clear bottlenecks before they become backlogs.
Ensure consistent documentation, categorization, and closure quality across all cases.
Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
Coordinate shift coverage and on-call rotations to maintain continuous monitoring.
Serve as a senior escalation point for analysts on complex or ambiguous cases.
Drive continuous improvement Of detection content, playbooks, and standard operating procedures.
Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
Coordinate response and remediation activities that require Tech Operations involvement, ensuring clear handoffs and shared visibility into status.
Participate in change management and operational reviews where security input is needed.
Support incident response efforts, including initial triage, containment recommendations, and coordination across teams during active incidents.
Contribute to post-incident reviews and help translate lessons learned into process or tooling improvements.
Mentor and provide day-to-day guidance to SOC analysts; support onboarding and skills development.
Help set expectations for case quality, communication, and escalation practices.
Track and report on SOC operational metrics (case volume, time-to-triage, time-to-resolution, escalation rates) to the Director, Cyber Defense & Strategy.
Flag trends or recurring issues that indicate a need for process, tooling, or staffing changes.