SOC Lead

Soni

Philadelphia (Philadelphia County)

On-site

USD 140,000 - 180,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Soni is seeking a hands-on SOC Lead to build and mature a Security Operations Center. You will oversee day-to-day SOC operations, strengthen detection and response, and mentor a team of security analysts.

You will develop runbooks and incident response procedures, tune detections, and lead threat hunting across SIEM, EDR, and cloud telemetry, while collaborating with cross-functional teams to improve security maturity.

Qualifications

  • 5+ years in Security Operations, Incident Response, or related fields.
  • Experience leading a SOC or senior security role with process maturity.
  • Hands-on experience building or maturing SOC processes and playbooks.
  • Proficiency with SIEM platforms and security automation tooling.

Responsibilities

  • Lead daily SOC operations and act as escalation point for complex incidents.
  • Develop and maintain SOC runbooks, playbooks, and IR procedures.
  • Mentor SOC analysts and establish effective investigation practices.
  • Tune SIEM detections and reduce false positives.
  • Lead threat hunting across SIEM, EDR, cloud telemetry, threat intel.
  • Manage incidents through triage, containment, eradication, recovery, post-incident review.
  • Perform root cause analysis and drive remediation efforts.
  • Implement automation and SOAR capabilities to scale SOC efficiency.
  • Develop SOC metrics and reporting to measure performance and maturity.
  • Collaborate with security, IT, and engineering teams to improve operations.

Skills

SOC operations
Incident response
Threat detection
Security automation
Python/PowerShell/Bash

Tools

Microsoft Sentinel
Google SecOps
Splunk
IBM QRadar
CrowdStrike
Microsoft Defender
SentinelOne

Job description

Our client is seeking a hands-on SOC Lead to help build and mature its Security Operations Center. This role will oversee day-to-day SOC operations, strengthen detection and response capabilities, establish scalable security processes, and mentor a team of security analysts.

Key Responsibilities
  • Lead daily SOC operations and serve as an escalation point for complex security incidents.
  • Develop and maintain SOC runbooks, playbooks, and incident response procedures.
  • Mentor SOC analysts and establish effective investigation and response practices.
  • Build, tune, and optimize SIEM detections while reducing false positives.
  • Lead threat hunting across SIEM, EDR, cloud telemetry, and threat intelligence sources.
  • Manage security incidents through triage, containment, eradication, recovery, and post-incident review.
  • Conduct root cause analysis and drive security remediation efforts.
  • Implement automation and SOAR capabilities to improve SOC efficiency and scalability.
  • Develop SOC metrics and reporting to measure operational performance and maturity.
  • Partner with security, IT, engineering, and other cross-functional teams to improve overall security operations.
Required Qualifications
  • 5+ years of experience in Security Operations, Incident Response, Detection Engineering, Threat Detection, or a related field.
  • Previous experience in a SOC Lead, Senior SOC Analyst, Incident Response Lead, or comparable senior-level security role.
  • Demonstrated experience building or maturing SOC processes, procedures, and operational frameworks.
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Google SecOps, Splunk, or IBM QRadar.
  • Experience with EDR platforms such as CrowdStrike, Microsoft Defender, or SentinelOne.
  • Strong background in detection engineering, alert tuning, threat hunting, and incident response.
  • Proficiency with Python, PowerShell, or Bash for security automation.
  • Strong communication, documentation, analytical, and cross-functional collaboration skills.
  • Demonstrated ability to mentor and develop security analysts.
Preferred Qualifications
  • Experience with AWS, Azure, or Google Cloud security monitoring.
  • Experience implementing SOAR and security automation.
  • Familiarity with MITRE ATT&CK and threat intelligence programs.
  • Experience building or maturing SOC capabilities within small to mid-sized organizations.
  • Relevant certifications such as CISSP, GCIH, GCIA, GCFA, CySA+, or Security+.
What We're Looking For

The ideal candidate is a hands-on security operations professional who can balance technical incident response and detection expertise with leadership, process development, and team mentorship. This is an opportunity to play a key role in strengthening and scaling a modern SOC environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

No Limit Staffing, Inc. • United States

On-site
USD 90,000 - 120,000
SOC Manager
SOC Manager

HW3 • Jacksonville (FL)

On-site
USD 120,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
Lead SOC Analyst
Lead SOC Analyst

UFP Industries, Inc. • Grand Rapids (MI)

On-site
USD 90,000 - 120,000
SOC Engineer
SOC Engineer

TENEX.AI • United States

On-site
USD 100,000 - 130,000
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Senior SOC Analyst
Senior SOC Analyst

Soni • Philadelphia

On-site
USD 90,000 - 120,000
Security Team Lead
Security Team Lead

IT Resource Hunter • Columbia (SC)

On-site
USD 85,000 - 110,000
SOC Manager
SOC Manager

Experis • Town of Cottage Grove (WI)

On-site
USD 120,000 - 180,000
Security Operations Lead
Security Operations Lead

New York Technology Partners • Chicago (IL)

On-site
USD 120,000 - 190,000