Evening SOC Lead - Incident Response & Team Development

The Phoenix Group

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

The Phoenix Group is seeking a senior security operations leader to manage the evening shift and drive incident response excellence. You will set escalation criteria, guide containment, and mentor Tier 1/2 analysts while ensuring high-quality runbooks and logs.

You will also participate in incident reviews and FedRAMP evidence collection. Candidates should bring 5+ years in SOC/NOC or MDR, hands-on SIEM experience, cloud security expertise, and the ability to enforce standards across multiple

Qualifications

  • 5+ years in security operations (SOC, NOC/SOC, or MDR) with senior shift experience.
  • Proven track record building and growing teams and resolving incidents.
  • Strong cloud security monitoring, detection engineering, and IR fundamentals.
  • Hands-on with a SIEM and writing/tuning detection rules and use cases.
  • Working knowledge of networks and log analysis (TCP/IP, DNS, firewalls, VPN).
  • Familiar with MITRE ATT&CK, NIST 800-53, and NIST IR guidance.
  • Ability to set standards and hold the team to them.

Responsibilities

  • Serve as the senior person on the floor for the evening shift (2:00 PM to 10:00 PM).
  • Define escalation criteria, including when to wake a manager, what can wait, and what the team resolves.
  • Lead root cause analysis on incidents and update runbooks to prevent repeats.
  • Set and maintain standards for shift logs, handovers, and queue health across shifts.
  • Coach and develop Tier 1 and 2 analysts, assessing readiness for promotion.
  • Triage and investigate alerts across SIEM, EDR, and cloud security tooling; direct containment.
  • Represent the team in incident reviews and contribute to FedRAMP evidence collection.

Skills

Security operations
Leadership
Incident response
Threat detection
Cloud security monitoring
Root cause analysis
Mentoring
Communication

Education

Security+ certification
CySP certification
CISSP certification

Tools

Splunk
Microsoft Sentinel
Elastic
CrowdStrike
Defender for Cloud
GuardDuty
Security Hub
Cortex XSOAR
Splunk SOAR
Python
PowerShell
Tenable
Qualys
Rapid7
ServiceNow
Jira
NetFlow
Firewalls
IDS/IPS
VPN
TCP/IP
DNS

Job description

The Phoenix Group is seeking a senior security operations leader to manage the evening shift and drive incident response excellence. You will set escalation criteria, guide containment, and mentor Tier 1/2 analysts while ensuring high-quality runbooks and logs.

You will also participate in incident reviews and FedRAMP evidence collection. Candidates should bring 5+ years in SOC/NOC or MDR, hands-on SIEM experience, cloud security expertise, and the ability to enforce standards across multiple

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Lead - Evening Shift, Federal Cloud Security
Senior SOC Lead - Evening Shift, Federal Cloud Security

The Phoenix Group • Arlington (VA)

On-site
USD 120,000 - 180,000
Fixed schedule
Four-day rotation awareness
Shift premium
+3
Security Operations Lead - Incident Response & Detection
Security Operations Lead - Incident Response & Detection

The Phoenix Group • Arlington (VA)

On-site
USD 90,000 - 120,000
Security Operations Lead
Security Operations Lead

The Phoenix Group • Washington

On-site
USD 140,000 - 190,000
Onsite SOC Analyst — Shift Work & Incident Response
Onsite SOC Analyst — Shift Work & Incident Response

phoenixcybersecurity • Phoenix (AZ)

On-site
USD 65,000 - 95,000
Senior SOC Lead - Incident Response & Threat Hunting
Senior SOC Lead - Incident Response & Threat Hunting

Master Electronics • Phoenix (AZ)

On-site
USD 100,000 - 125,000
Health insurance
401(k) match
Tuition assistance
+5
SOC Lead: 24/7 Incident Detection & Response
SOC Lead: 24/7 Incident Detection & Response

Optimalsemi • United States

On-site
USD 140,000 - 190,000
Senior Security Operations Lead (Evening Shift)
Senior Security Operations Lead (Evening Shift)

Knox Systems • United States

On-site
USD 125,000 - 160,000
Medical, Dental, Vision
Life & Disability
401k plan
+1
Remote Cybersecurity Analyst: SOC & Incident Response
Remote Cybersecurity Analyst: SOC & Incident Response

Phoenix Cyber • United States

Remote
USD 85,000 - 120,000
Remote Cybersecurity Analyst - SOC & Incident Response
Remote Cybersecurity Analyst - SOC & Incident Response

phoenixcybersecurity • United States

Remote
USD 80,000 - 110,000
Senior SOC Analyst: Incident Commander & Threat Hunter
Senior SOC Analyst: Incident Commander & Threat Hunter

Master-Electronics • Phoenix (AZ)

On-site
USD 100,000 - 125,000
Health insurance
401(k) match
Tuition assistance
+1