Security Operations Lead

Accenture Federal Services

Washington (District of Columbia)

On-site

USD 126,300 - 243,100

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading consulting firm in Washington, DC, seeks a Security Operations Lead to oversee SOC functions and lead a blended team of analysts and engineers. Responsibilities include directing incident response processes, developing detection capabilities, and mentoring team members. The position requires significant cybersecurity experience and expertise with SIEM, NDR, and EDR technologies. Preferred qualifications include advanced threat hunting skills and relevant certifications. The role offers competitive compensation based on experience, ranging from $126,300 to $243,100.

Qualifications

  • 8 years of cybersecurity experience, with 3+ years leading SOC or IR teams.
  • Hands-on experience triaging alerts, logs, events, and incident artifacts across enterprise environments.
  • Strong experience with SIEM/NDR/EDR tools and incident response.

Responsibilities

  • Lead day‑to‑day SOC operations including queue management and alert triage oversight.
  • Guide analysts during high‑severity incidents and act as the primary interface with client leadership.
  • Develop and optimize SIEM correlation rules and monitoring logic.

Skills

Cybersecurity experience
SIEM experience (Splunk, Elastic)
NDR experience (ExtraHop)
Incident response leadership

Tools

SIEM tools
Packet analysis tools

Job description

Role Summary

The Security Operations Lead will oversee all SOC functions and lead a blended team of SOC Analysts and Security Engineers to ensure rapid detection, investigation, and response to security threats. This role is responsible for driving threat hunting, leading major incidents, engineering detection capabilities, and maturing SOC operations to stay ahead of evolving adversary behaviors. The Lead acts as the central coordination point during security events and sets the strategic direction for the SOC to ensure continuous, mission‑critical security coverage.

Key Responsibilities
SOC Leadership & Operations
  • Lead day‑to‑day SOC operations, including queue management, alert triage oversight, escalation handling, on‑call rotations, and daily situational reporting.
  • Mentor and develop SOC analysts across tiers; refine SOPs, workflows, and response playbooks.
  • Drive threat hunting activities focused on identifying patterns, outliers, and TTP‑aligned behaviors across host, network, email, and cloud logs.
  • Oversee SIEM dashboarding, alert tuning, log source health, and rule/correlation development to strengthen detection depth.
  • Coordinate with Security Engineering to ensure logging fidelity, sensor coverage, and integration of new technologies.
Incident Response
  • Lead the full lifecycle of incident response: identification, containment, eradication, recovery, forensics support, and post‑incident reporting.
  • Perform or direct deep‑dive investigations using SIEM, NDR, EDR, packet analysis tools, and forensic artifacts.
  • Provide expert investigative support for large‑scale or complex incidents where technical detections may not be available.
  • Guide analysts during high‑severity incidents and act as the primary interface with client leadership and internal stakeholders.
  • Oversee threat intelligence intake and ensure IOCs, adversary behaviors, and campaign indicators are integrated into SOC detections.
Detection Engineering & Threat Analytics
  • Develop and optimize SIEM correlation rules, dashboards, and monitoring logic.
  • Enhance playbooks and automation pipelines to improve consistency and reduce analyst workload.
  • Ensure ongoing alignment to evolving threat actor TTPs, including insider threat and APT‑style behaviors.
  • Integrate new data sources into SOC detection pipelines and validate alert efficacy.
Required Qualifications
  • 8 years of cybersecurity experience, with 3+ years leading SOC or IR teams.
  • Hands‑on experience triaging alerts, logs, events, and incident artifacts across enterprise environments.
  • Strong experience with one or more of the following technologies: SIEM (Splunk, Elastic), NDR (ExtraHop), EDR/XDR (Trellix), and packet analysis tools.
  • Demonstrated ability to lead incident response for high‑severity cybersecurity events.
Preferred Qualifications
  • Advanced experience in threat hunting, analytics, and adversary behavior profiling.
  • Certifications such as CISSP, GCIH, GCIA, GCED, CEH, or similar.
  • Experience building SIEM/SOAR automations and custom detection content.
  • Familiarity with malware triage, static/dynamic analysis, and IOC development.
  • Experience leading SOCs supporting federal missions or high‑tempo operational environments.
  • Exposure to cloud security monitoring (Azure, AWS, GCP) and SaaS logging integrations.
Compensation

The base pay range for this position in the following locations is $126,300—$243,100 USD: California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland.

Equal Employment Opportunity Statement

We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities. For details, view a copy of the Accenture Federal Services Equal Opportunity Policy Statement.

Accenture Federal Services is an Equal Employment Opportunity employer. Additionally, as an affirmative action employer for Veterans and Individuals with Disabilities, Accenture Federal Services is committed to providing veteran employment opportunities to our service men and women.

Other Employment Statements

Applicants for employment in the US must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States.

Candidates who are currently employed by a client of Accenture Federal Services or an affiliated Accenture business may not be eligible for consideration.

Job candidates will not be obligated to disclose sealed or expunged records of conviction or arrest as part of the hiring process.

The Company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. Additionally, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the Company's legal duty to furnish information.

California requires additional notifications for applicants and employees. If you are a California resident, live in or plan to work from Los Angeles County upon being hired for this position, please click here for additional important information.

Requesting An Accommodation

Accenture Federal Services is committed to providing equal employment opportunities for persons with disabilities or religious observances, including reasonable accommodation when needed. If you are hired by Accenture Federal Services and require accommodation to perform the essential functions of your role, you will be asked to participate in our reasonable accommodation process. Accommodations made to facilitate the recruiting process are not a guarantee of future or continued accommodations once hired.

If you are being considered for employment opportunities with Accenture Federal Services and need an accommodation for a disability or religious observance during the interview process or for the job you are interviewing for, please speak with your recruiter.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Accenture Federal Services • Arlington (VA)

On-site
USD 57,000 - 109,000
Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Accenture • Arlington (VA)

On-site
USD 57,000 - 109,000
Cybersecurity Incident Response Triage IR Analyst
Cybersecurity Incident Response Triage IR Analyst

Accenture Federal Services Careers Marketplace • Arlington (VA)

On-site
USD 53,900 - 120,100
GIAC Certifications
CISSP
Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Socket.dev • Arlington (VA)

On-site
USD 57,000 - 109,000
Security Engineer
Security Engineer

Accenture Federal Services • Clearfield (UT)

On-site
USD 100,000 - 204,000
Detection Engineer
Detection Engineer

Accenture Federal Services • Arlington (VA)

On-site
USD 91,000 - 222,000
Hands-on experience
Certifications and industry training
Collaborative work environment
Security Operations Engineer
Security Operations Engineer

Accenture Federal Services • Fort Meade (MD)

On-site
USD 126,000 - 244,000
Collaborative work environment
Career development opportunities
Comprehensive benefits package
Senior Security Engineer
Senior Security Engineer

Accenture Federal Services • Clearfield (UT)

On-site
USD 116,000 - 244,000
Cybersecurity Incident Response Triage Analyst
Cybersecurity Incident Response Triage Analyst

Accenture-Federal-Services-2 • Arlington (VA)

On-site
USD 57,000 - 109,000
Senior Security Engineer
Senior Security Engineer

Accenture-Federal-Services-2 • Salt Lake City (UT)

On-site
USD 117,000 - 243,000