Manager, Security Operations Centre (SOC)

BlueVoyant

Maryland Park (MD)

Hybrid

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

BlueVoyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of ~60 employees and protect client relationships. This client‑facing leadership role shapes how customers experience the SOC, from escalation handling to metrics and reporting.

The role offers growth into higher‑level leadership as the team scales. You will lead Team Leads, Trainers, and Analysts, own incident investigations, and drive service improvements with cross‑functional partners.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science or related field preferred.
  • 8+ years of SOC/TOC/NOC experience or equivalent.
  • Experience leading managers or team leads and improving service delivery.

Responsibilities

  • Lead a team of Team Leads, Trainers, and Security Analysts with coaching and performance management.
  • Oversee customer escalations to ensure high‑quality service and client retention.
  • Manage incident response, post‑incident reviews, and knowledge sharing across SOC teams.
  • Collaborate with Client Success, Content Engineering, Threat Hunt, and Product leadership to drive service improvements.
  • Develop and report SOC performance metrics and incident trends to leadership.

Skills

Leadership
Client relations
People management
Communication
Incident response
SOC operations

Education

Bachelor's degree in Information Security/CS

Tools

SIEM
IDS/IPS
Network monitoring
Case management
Vulnerability identification
Encryption

Job description

Position: Manager, Security Operations Centre (SOC)

Location: Hybrid – College Park, MD (On‑site 2–3 days per week)

Work Authorization: US Citizenship Required

BlueVoyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of roughly 60 employees, playing a critical role in protecting client relationships and driving retention.

This is a client‑facing leadership role responsible for shaping how customers experience the SOC — from escalation handling through the metrics and reporting that inform leadership decisions. The role carries strong potential for growth into a higher‑level leadership position as the team and business scale, making it a great fit for an ambitious leader who wants to build and shape a growing organization.

What You’ll Do:
  • Lead, develop, and manage a team of Team Leads, Trainers, and Security Analysts, providing strategic direction, coaching, and performance management
  • Assume full responsibility and accountability for ensuring all SOC customers receive world‑class service
  • Own the management of customer escalations, with the primary goal of client retention, partnering closely with Client Success on remediation plans and client communication
  • Provide oversight and management of Team Leads and the wider Analyst team, ensuring consistent quality and performance across the SOC
  • Lead post‑incident review meetings to capture lessons learned following the resolution of critical events
  • Ensure key Security Operations actions incorporate relevant customer impact considerations by engaging key stakeholders and communicating known/suspected implications of technical decisions
  • Validate that Security Operations activities adequately address customer requirements across all MSS services
  • Oversee operations in deterring, identifying, monitoring, investigating, and analyzing network intrusions
  • Supervise complex event investigation and incident declaration, ensuring events are properly identified, analyzed, and escalated to incidents
  • Ensure the team’s incident investigation, handling, response, and documentation meet quality and SLA standards
  • Assist in the advancement of security policies, procedures, and automation
  • Develop incident response reporting and policy updates as needed
  • Partner cross‑functionally with Client Success, Content Engineering, Threat Hunt, and Product leadership to drive service improvements and represent the SOC’s priorities
  • Develop and maintain SOC performance metrics, delivering regular reporting on team performance, incident trends, and customer outcomes to leadership
  • Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure continued business as usual
  • Maintain a strong awareness of the current threat landscape
What You’ll Bring:
  • Ability and willingness to commute to the College Park, MD office 2–3 days per week
  • Experience working within a global organization, partnering with distributed teams across multiple regions and time zones
  • Prior experience managing managers or team leads, with direct accountability for team performance and development
  • Ability to handle high‑pressure situations in a productive and professional manner
  • Ability to work directly with customers to understand requirements for and feedback on security services, including managing escalations to protect client relationships
  • Advanced written and verbal communication skills, with the ability to present complex technical topics in clear and easy‑to‑understand language
  • Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distributed team
  • Able and willing to work in a 24/7/365 environment
Technical Expertise:
  • Knowledge of and experience with the Microsoft Security Stack (Defender, Sentinel etc)
  • Knowledge of and experience with intrusion detection/prevention systems and SIEM software
  • Advanced knowledge and understanding of network protocols and devices
  • Advanced experience with Mac OS, Windows, and Unix systems
  • Ability to analyze event logs and recognize signs of cyber intrusions/attacks
  • Strong knowledge of: SIEM, Packet Analysis, SSL Decryption, Malware Detection, HIDS/NIDS, Network Monitoring Tools, Case Management System, Knowledge Base, Web Security Gateway, Email Security, Data Loss Prevention, Anti‑Virus, Network Access Control, Encryption, and Vulnerability Identification
Nice to Have:
  • Experience partnering with or managing teams based in the Philippines
  • Experience in network/host vulnerability analysis, intrusion analysis, digital forensics, penetration testing, or related areas
  • 8+ years of hands‑on SOC/TOC/NOC experience
  • Certifications such as GCIA, GCIH, GCFA, GCFE, CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, or MCSE
  • Familiarity with tools such as IDA Pro, PEiD, PEview, Procmon, Snort, Bro, Kali Linux, Metasploit, NMAP, and Nessus
  • Familiarity with GPO, Landesk, or other IT infrastructure tools
  • Understanding of and/or experience with one or more programming languages: .NET, PHP, Perl, Python, Java, Ruby, C, C++
Education:

Bachelor’s degree in Information Security, Computer Science, or another technology / engineering‑related field preferred. Candidates with proven experience in security/network operations will also be considered.

Why BlueVoyant?
  • Work alongside experienced SOC and cybersecurity leaders, including former government cyber professionals and industry veterans
  • Gain exposure to complex customer environments and a wide range of MSS services across industries
  • Join a global, mission‑driven cybersecurity company defending organizations worldwide with cutting‑edge data, technology, and expertise
  • Competitive compensation and a comprehensive benefits package, with support for wellbeing, development, and career growth
About BlueVoyant

BlueVoyant is an AI‑driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award‑winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.

Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real‑time datasets with industry leading analytics and technologies.

Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats.

All employees must be authorized to work in the United States of America. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, colour, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non‑discrimination in employment in every location in which the company has facilities.

Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Operations Centre (SOC)
Manager, Security Operations Centre (SOC)

BlueVoyant • Maryland City (MD)

Hybrid
USD 180,000 - 230,000
Competitive compensation
Benefits package
Career growth opportunities
Security Content Engineer – Splunk
Security Content Engineer – Splunk

BlueVoyant • Maryland

Remote
USD 80,000 - 130,000
Senior Security Content Engineer
Senior Security Content Engineer

BlueVoyant • Northern (KY)

Hybrid
USD 140,000 - 190,000
Competitive compensation
Comprehensive benefits package
Wellbeing and career development
Lead SOC Manager: Client-Focused Security Operations
Lead SOC Manager: Client-Focused Security Operations

BlueVoyant • Maryland City (MD)

Hybrid
USD 180,000 - 230,000
Competitive compensation
Benefits package
Career growth opportunities
Senior Microsoft Purview Specialist
Senior Microsoft Purview Specialist

BlueVoyant • Northern (KY)

Hybrid
USD 140,000 - 180,000
Comprehensive benefits
Flexible remote work
Professional development
+1
Cybersecurity Engineer (Architecture, Infrastructure and Remediation)
Cybersecurity Engineer (Architecture, Infrastructure and Remediation)

Trustwave • United States

Hybrid
USD 90,000 - 130,000
Medical insurance
401(k) matching
Paid time off
+1
Senior Cybersecurity Consultant, Blue Team Lead
Senior Cybersecurity Consultant, Blue Team Lead

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2
Security Operations Center (SOC) Manager
Security Operations Center (SOC) Manager

DirectViz Solutions, LLC • Washington

On-site
USD 120,000 - 150,000
Comprehensive medical benefits
401(k) match
Generous PTO accrual
+2
SOC Manager (Hands-On) - Remote (USA)
SOC Manager (Hands-On) - Remote (USA)

Echelon Risk + Cyber • Washington

On-site
USD 110,000 - 140,000
Health, dental, and vision insurance
401(k) with employer contribution
Flexible vacation policy
+1
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1