SOC Lead

JFL CONSULTING, LLC

Springfield (VA)

On-site

USD 170,000 - 220,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
Dental & vision
FSAs
Life insurance
Disability
401(k)
PTO 15/5/2/11
Cert reimbursement

Job summary

JFL Consulting, LLC in Springfield, VA is seeking a SOC Lead to serve as senior authority for all SOC shifts, directing the shift teams, managing alert queues, escalation decisions, and ensuring all incidents are tracked and handed off.

Ideal candidate has 10+ years in SOC, 3+ years in lead roles, CISSP/CISM/CISA or GCIH, and strong SIEM/EDR/forensics expertise. This role requires nights, weekends, and holidays on a rotating schedule.

Qualifications

  • 10+ years SOC or similar experience.
  • At least 3+ years in a senior or lead role.
  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, or related field; or four extra years of relevant work experience.
  • Certifications: CISSP, CISM, CISA, or GCIH.
  • Additional: Sec+, CYSA+, SecX, CEH, GCIA, GSOC.
  • Hands-on incident response including containment, eradication, and recovery.
  • Advanced SIEM and log analysis experience.
  • PCAP analysis tools experience (Wireshark, NetworkMiner).
  • EDR, memory forensics, and network forensics tools.
  • MITRE ATT&CK understanding and attacker TTPs.
  • Willingness to work nights, weekends, and holidays on rotating shifts.
  • Experience mentoring junior analysts.

Responsibilities

  • Provide Tier 4 escalation and resolution for the most complex incidents.
  • Direct daily SOC shift operations and monitoring.
  • Triage alerts within SLA and coordinate with Tier 1-3 analysts.
  • Make escalation decisions to activate T3/IR and on-call staff.
  • Oversee shift handoffs and turnover briefings.
  • Mentor SOC staff and junior analysts.
  • Review Priority 2+ tickets before escalation.
  • Develop and update playbooks and ensure proper usage.
  • Maintain situational awareness across alerts and monitoring.
  • Coordinate with NOC on security-related network issues.
  • Review shift logs and required reporting.

Skills

SOC Leadership
Incident Response
SIEM
Threat Hunting
PCAP Analysis
EDR / Forensics
Mentoring
MITRE ATT&CK

Education

Bachelor's in Cyber Security

Tools

Wireshark
Ghidra
IDA Pro
KQL
SPL
NetworkMiner

Job description

Description

Job Title: SOC Lead

Place of Performance: Springfield, VA

Experience Level: Senior-Level (10+ years)

About JFL Consulting

With more than 20 years of securing some of the U.S. Department of Defense and the Intelligence Community’s most critical networks, JFL Consulting, LLC provides advanced network security solutions to a range of US Government and US commercial clients. Our cybersecurity operators are experts at assessing and defending mission-critical data and the networks that facilitate their operation. We are focused on delivering advanced products and industry best practices that meet each customer’s unique requirements. Visit www.jflconsulting.com

What We Offer
  • Salary: $170k- $220k
  • 100% employer-paid medical, dental, and vision premiums for employees and dependents
  • Flexible Spending Accounts (healthcare, dependent care, and commuter)
  • Life insurance, short-term disability and long-term disability
  • 401(k) with immediate vesting of company contribution
  • Generous PTO policy (15 vacation, 5 sick, 2 personal days, 11 holidays)
  • We support your growth through certification reimbursement, dedicated professional development funding, and company-provided access to online learning platforms
Job Overview

We're looking for a SOC Lead who is the senior authority for all SOC shifts. This role is responsible for directing the shift teams, managing alert queues, making escalation decisions, and ensuring all open incidents are properly tracked, documented, and handed off.

Key Responsibilities
  • Provide Tier 4 escalation and resolution for the most complex incidents and outages
  • Direct the daily operations of the shift team across the SOC
  • Monitor alert queues and ensure Tier 1-3 analysts are triaging within SLA standards
  • Make escalation decisions such as activating T3/IR, on-call engineers, and management chain as appropriate
  • Manage the shift handoff process, ensuring a turnover briefing is produced and delivered at each handoff window
  • Mentor, manage and train the SOC staff
  • Review and approve all Priority 2 and above incident tickets before escalation
  • Develop and modify playbooks
  • Ensure all playbooks are being followed correctly and appropriately updated
  • Maintain situational awareness across all incoming alerts, calls, network monitoring, and active triage.
  • Coordinate with NOC staff on network issues that may have a security component
  • Review and verify all shift logs and all required reporting
Requirements

Required Qualifications:

  • 10+ years of SOC or similar experience
  • At least 3+ years in a senior or lead role
  • Bachelor's degree in Cyber Security, Information Technology, Computer Science, Information Security, or related field. In lieu of degree, four additional years of experience in a NOC, SOC, IT security, or network engineering role
  • One of the following certifications, equivalent or better: CISSP, CISM, or CISA, or GCIH
  • Additionally One of the following certifications, equivalent or better: Sec+, CYSA+, SecX, CEH, GCIA, GSOC
  • Expert proficiency with hands‑on incident response experience including containment, eradication, and recovery
  • Advanced experience with SIEM platforms and log analysis
  • Advanced experience SIEM query languages (SPL, KQL, or equivalent)
  • Advanced experience PCAP analysis tools (Wireshark, NetworkMiner, or equivalent)
  • Advanced experience with EDR, endpoint forensics, memory analysis, and network forensics tools
  • Deep understanding of attacker TTPs, kill chain methodology, and MITRE ATT&CK
  • Ability to work shifts including nights, weekends, and holidays on rotating shift schedule
  • Demonstrated experience managing and mentoring junior analysts
  • Ability to remain calm and direct operations during high‑pressure incidents
Preferred Qualifications
  • GCFA or GCFE certification or other forensic certifications
  • Active Secret clearance preferred but not required
  • Experience with threat hunting frameworks and platforms
  • Reverse engineering experience (IDA Pro, Ghidra)
  • Prior experience on a DFIR team or incident response retainer
  • Experience with malware analysis (static and dynamic)
  • Experience with zero‑trust network architecture
  • Experience with classified network environments (SIPRNet, NIPRNet)
  • Direct experience as SOC experience
  • SOAR platform experience
Equal Opportunity Employer

We do not discriminate against any applicant for employment on any legally recognized basis including, but not limited to: race, religion or creed, color, national origin, sex, age, disability, marital status, sexual orientation, genetic information, veteran status, status with regard to public assistance or any other protected class under federal, state or local statute. It is also the policy of JFL Consulting, LLC to provide reasonable accommodations for qualified individuals with disabilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst Tier 3
SOC Analyst Tier 3

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 140,000 - 180,000
Salary: $140k- $180k
100% employer-paid medical, dental, &
SOC Analyst Tier 3
SOC Analyst Tier 3

JFL Consulting LLC • Springfield (VA)

On-site
USD 140,000 - 180,000
Employer-paid medical, dental, vision
FSA (healthcare & dependent care)
Commuter FSA
+9
Program Manager (Ops Center Manager for SOC & NOC)
Program Manager (Ops Center Manager for SOC & NOC)

JFL CONSULTING, LLC • Springfield (VA)

On-site
USD 180,000 - 250,000
Program Manager (Ops Center Manager for SOC & NOC)
Program Manager (Ops Center Manager for SOC & NOC)

Socket.dev • Springfield (VA)

On-site
USD 180,000 - 250,000
Premium benefits
Health insurance
401(k)
+2
NOC Lead
NOC Lead

JFL Consulting, LLC • Springfield (VA)

On-site
USD 170,000 - 220,000
Health insurance
FSA accounts
Life insurance + disability
+2
Security Operations Center Manager
Security Operations Center Manager

Agile Defense • Reston (VA)

Hybrid
USD 120,000 - 150,000
Competitive benefits package
Supportive work culture
Mentorship opportunities
SOC Manager
SOC Manager

Fulcrum Technology Solutions • United States

On-site
USD 100,000 - 130,000
Journeyman SOC Analyst (Q Clearance)
Journeyman SOC Analyst (Q Clearance)

ShorePoint, LLC • Las Vegas (NV)

On-site
USD 90,000 - 130,000
PTO 18 days
Health insurance
401k plan
+2
SOC Analyst Tier 2 (Q Clearance)
SOC Analyst Tier 2 (Q Clearance)

ShorePoint, LLC • North Las Vegas (NV)

On-site
USD 80,000 - 100,000
18 days of PTO
11 holidays
85% of insurance premium covered
+2
Security Operations Center Manager
Security Operations Center Manager

Fidelity National Financial • Jacksonville (FL)

On-site
USD 140,000 - 180,000