Security Operations Lead

The Phoenix Group

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

The Phoenix Group is seeking a senior security operations leader to manage the evening shift and drive incident response excellence. You will set escalation criteria, guide containment, and mentor Tier 1/2 analysts while ensuring high-quality runbooks and logs.

You will also participate in incident reviews and FedRAMP evidence collection. Candidates should bring 5+ years in SOC/NOC or MDR, hands-on SIEM experience, cloud security expertise, and the ability to enforce standards across multiple

Qualifications

  • 5+ years in security operations (SOC, NOC/SOC, or MDR) with senior shift experience.
  • Proven track record building and growing teams and resolving incidents.
  • Strong cloud security monitoring, detection engineering, and IR fundamentals.
  • Hands-on with a SIEM and writing/tuning detection rules and use cases.
  • Working knowledge of networks and log analysis (TCP/IP, DNS, firewalls, VPN).
  • Familiar with MITRE ATT&CK, NIST 800-53, and NIST IR guidance.
  • Ability to set standards and hold the team to them.

Responsibilities

  • Serve as the senior person on the floor for the evening shift (2:00 PM to 10:00 PM).
  • Define escalation criteria, including when to wake a manager, what can wait, and what the team resolves.
  • Lead root cause analysis on incidents and update runbooks to prevent repeats.
  • Set and maintain standards for shift logs, handovers, and queue health across shifts.
  • Coach and develop Tier 1 and 2 analysts, assessing readiness for promotion.
  • Triage and investigate alerts across SIEM, EDR, and cloud security tooling; direct containment.
  • Represent the team in incident reviews and contribute to FedRAMP evidence collection.

Skills

Security operations
Leadership
Incident response
Threat detection
Cloud security monitoring
Root cause analysis
Mentoring
Communication

Education

Security+ certification
CySP certification
CISSP certification

Tools

Splunk
Microsoft Sentinel
Elastic
CrowdStrike
Defender for Cloud
GuardDuty
Security Hub
Cortex XSOAR
Splunk SOAR
Python
PowerShell
Tenable
Qualys
Rapid7
ServiceNow
Jira
NetFlow
Firewalls
IDS/IPS
VPN
TCP/IP
DNS

Job description

  • Serve as the senior person on the floor for the evening shift (2:00 PM to 10:00 PM).
  • Define escalation criteria, including what warrants waking a manager, what can wait, and what the team resolves on its own.
  • Lead root cause analysis on any incident that reached containment, and update runbooks to prevent repeat events.
  • Set and maintain standards for shift logs, handovers, and queue health across all shifts.
  • Coach and develop Tier 1 and Tier 2 analysts, including assessing their readiness for promotion.
  • Triage and investigate alerts across SIEM, EDR, and cloud-native security tooling, and direct containment and remediation.
  • Represent the team in incident reviews and contribute to FedRAMP evidence collection.
Requirements
  • 5+ years in security operations (SOC, NOC/SOC, or MDR environments), including experience as the senior person on shift.
  • A demonstrated record of developing people, in addition to resolving incidents.
  • Solid knowledge of cloud security monitoring, detection engineering, and incident response.
  • Hands-on experience with a SIEM platform and writing or tuning detection rules and use cases.
  • Working knowledge of network fundamentals (TCP/IP, DNS, firewalls, VPN, IDS/IPS) and log analysis.
  • Familiarity with frameworks such as MITRE ATT&CK, NIST 800-53, and NIST incident response guidance.
  • The confidence to set a standard and hold a team to it.
Tools and Technologies (experience with a similar toolset is fine)
  • SIEM and log management: Splunk, Microsoft Sentinel, Elastic, or similar
  • Endpoint and threat detection: CrowdStrike, Microsoft Defender, SentinelOne, or similar
  • Cloud platforms and native security services: AWS, Azure, GCP (GuardDuty, Security Hub, Defender for Cloud, or similar)
  • SOAR and automation: Cortex XSOAR, Splunk SOAR, or scripting in Python or PowerShell
  • Vulnerability management: Tenable, Qualys, or Rapid7
  • Ticketing and documentation: ServiceNow, Jira, or similar
  • Network and perimeter monitoring: firewalls, IDS/IPS, packet capture, NetFlow
Nice to Have
  • Security+, CySP+, GCIH, GCIA, GCED, CISSP, or cloud security certifications
  • Experience with FedRAMP, FISMA, or other federal compliance environments
  • Active security clearance, or the ability to obtain one (confirm with the client)
  • Experience in a 24x7 operations environment or a federal or defense contractor
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Analyst
Security Operations Analyst

The Phoenix Group • Arlington (VA)

On-site
USD 90,000 - 120,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
W2 - Lead of Cybersecurity Operations
W2 - Lead of Cybersecurity Operations

Acumenz Consulting • Richardson (TX)

On-site
USD 120,000 - 150,000
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder

OneMain Financial • Washington

On-site
USD 140,000 - 190,000
Senior Security Operations Analyst
Senior Security Operations Analyst

Prosegur Security USA, Inc • Lowell (MA), Northern (KY)

Hybrid
USD 90,000 - 140,000
Cybersecurity Analyst
Cybersecurity Analyst

EXOS • Indianapolis (IN)

On-site
USD 90,000 - 120,000
Network Security Analyst
Network Security Analyst

vTech Solution • Washington

On-site
USD 75,000 - 110,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

invictusic • Colorado Springs (CO)

On-site
USD 120,000 - 180,000