Security Operations Lead - Incident Response & Detection

The Phoenix Group

Arlington (VA)

On-site

USD 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

The Phoenix Group is seeking an experienced Security Operations Analyst to join our security operations center in Arlington, VA. You will monitor cloud and hybrid environments, lead incident response efforts, and drive continuous improvement in detection and alerting.

You will mentor junior analysts, coordinate escalations, and document incidents and runbooks to support FedRAMP-compliant operations and enterprise security posture.

Qualifications

  • 3+ years in security operations, SOC/NOC or similar environments.
  • Experience investigating alerts, managing escalations, and coordinating incident response in enterprise or cloud.
  • Certifications such as Security+ (CompTIA), CySA+, SSCP preferred.

Responsibilities

  • Serve as a senior analyst on shift, overseeing security operations, threats, escalations, and incident response.
  • Investigate alerts and events using SIEM, cloud tools, and network monitoring; perform root cause analysis.
  • Make informed escalation decisions to contain threats and coordinate with stakeholders.
  • Document security incidents, maintain shift logs, update runbooks, and ensure clear handoffs.
  • Monitor enterprise and cloud environments for malicious activity using SIEM, CSPM, and EDR tools.
  • Collaborate to improve detection rules, alert accuracy, escalation procedures, and incident response."
  • Contribute to incident reviews, security process improvements, and FedRAMP evidence documentation.
  • Mentor junior analysts and build team capability in troubleshooting and threat analysis.
  • Support shift leadership by developing escalation standards and operational best practices.

Skills

Incident response
Threat detection
Escalation decisions
Mentoring teammates
Documentation

Education

Security+ (CompTIA)
CySA+
SSCP

Tools

ArcSight
Splunk
QRadar
CrowdStrike
Carbon Black
Defender ATP
AWS Security Hub
Azure Security Center
GCP Security Command Center
SOAR platforms

Job description

The Phoenix Group is seeking an experienced Security Operations Analyst to join our security operations center in Arlington, VA. You will monitor cloud and hybrid environments, lead incident response efforts, and drive continuous improvement in detection and alerting.

You will mentor junior analysts, coordinate escalations, and document incidents and runbooks to support FedRAMP-compliant operations and enterprise security posture.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior SOC Lead - Evening Shift, Federal Cloud Security
Senior SOC Lead - Evening Shift, Federal Cloud Security

The Phoenix Group • Arlington (VA)

On-site
USD 120,000 - 180,000
Fixed schedule
Four-day rotation awareness
Shift premium
+3
Security Operations Analyst
Security Operations Analyst

The Phoenix Group • Arlington (VA)

On-site
USD 90,000 - 120,000
Cloud Security Engineer - IAM, IaC & Incident Response
Cloud Security Engineer - IAM, IaC & Incident Response

The Phoenix Group • Arlington (VA)

On-site
USD 100,000 - 150,000
Federal Tier I SOC Analyst — High-Impact Cloud Security
Federal Tier I SOC Analyst — High-Impact Cloud Security

The Phoenix Group • Arlington (VA)

On-site
USD 75,000 - 110,000
Shift premium
Certification costs covered
Published salary band
+2
Evening SOC Lead - Incident Response & Team Development
Evening SOC Lead - Incident Response & Team Development

The Phoenix Group • Washington

On-site
USD 140,000 - 190,000
Senior Cloud SecOps Engineer - Incident Response
Senior Cloud SecOps Engineer - Incident Response

Island • Cedar Hill (TX)

On-site
USD 120,000 - 190,000
Health, dental, vision
401(k) match
Generous PTO
+3
Remote Cybersecurity Analyst - SOC & Incident Response
Remote Cybersecurity Analyst - SOC & Incident Response

phoenixcybersecurity • United States

Remote
USD 80,000 - 110,000
Remote Cybersecurity Analyst: SOC & Incident Response
Remote Cybersecurity Analyst: SOC & Incident Response

Phoenix Cyber • United States

Remote
USD 85,000 - 120,000
Remote Cybersecurity Analyst: SOC & Incident Response
Remote Cybersecurity Analyst: SOC & Incident Response

Phoenix Cyber • Chandler (AZ)

Remote
USD 75,000 - 110,000
Senior Security Operations: Detection & Response (Remote)
Senior Security Operations: Detection & Response (Remote)

Point • San Francisco (CA)

On-site
USD 151,000 - 167,000
Health benefits
Unlimited PTO
Remote & onsite options
+3