SOC Manager (Hands-On) - Remote (USA)

Echelon Risk + Cyber

Washington (District of Columbia)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, dental, and vision insurance
401(k) with employer contribution
Flexible vacation policy
Employer-funded health savings accounts

Job summary

Echelon Risk + Cyber is hiring a SOC Manager in Washington, DC, to oversee technical security operations. This role combines leadership and hands-on management within the SOC environment, ensuring effective incident handling and continuous improvement of security processes.

The ideal candidate will bring 7-10 years of experience, including operational oversight of SIEM and EDR tools, along with a commitment to driving high-security standards through effective teamwork and client engagement.

Qualifications

  • 7-10 years of experience in MSSP settings.
  • 5+ years working directly within a SOC environment.
  • Strong knowledge of technical security operations.

Responsibilities

  • Establish SOC processes and drive continuous improvement.
  • Lead investigations and major incidents end-to-end.
  • Serve as technical point of contact for customers.

Skills

SOC operations
Security engineering
Incident response
Detection engineering
Automation scripting

Education

BS in CS/Cybersecurity or equivalent experience

Tools

CrowdStrike
SIEM (Splunk, Microsoft Sentinel)
EDR (Microsoft Defender for Endpoint)
SOAR tools
Vulnerability management tools

Job description

At Echelon Risk + Cyber, we believe in defending fundamental human rights to security and privacy. We are seeking a highly skilled and hands‑on SOC Manager to join our dynamic team. This player‑coach role combines technical leadership, operational oversight, and hands‑on security operations. The ideal candidate brings 7–10 years of MSSP experience, including at least 5 years working directly within a SOC environment and a strong security engineering background across EDR/MDR, SIEM, Microsoft 365 Security, Crowdstrike and Email Security.

What You Will Do
SOC Leadership & Maturity (no hiring duties)
  • Establish and refine SOC processes (tiering, shift coverage, escalation paths, QA, SLAs/OLAs).
  • Drive runbook discipline, training plans, and continuous improvement for service quality.
  • Own SOC KPIs (MTTD/MTTR, detection efficacy, false‑positive rate, case aging, CSAT/NPS).
Detection & Response (hands‑on)
  • Build and tune detections in SIEM/XDR; develop correlation rules, parsers, and dashboards.
  • Lead investigations and major incidents end‑to‑end; conduct post‑incident reviews and reporting.
  • Perform proactive threat hunting aligned to MITRE ATT&CK and emerging TTPs.
Tooling & Platform Engineering
  • Deploy, integrate, and operate EDR/MDR (CrowdStrike, SentinelOne, Blackpoint), Microsoft 365/Windows Defender, SIEM, SOAR, email security, vulnerability scanners, and NSM tools.
  • Engineer log onboarding/normalization across cloud (AWS, Azure, M365, GCP), network, endpoint, identity, and SaaS sources.
  • Build automation/orchestration playbooks to reduce MTTD/MTTR and analyst toil.
Service Delivery & Client Engagement
  • Serve as technical point of contact for customers; present posture reviews and improvement plans.
  • Define and meet service SLAs; contribute to SOWs, service catalogs, and onboarding playbooks.
  • Coordinate with customer IT/CISO teams, vendors, and legal/compliance during incidents.
Risk, Compliance & Continuous Improvement
  • Map detections, controls, and reporting to frameworks/standards (NIST CSF/800‑53, CIS Controls, SOC 2, ISO 27001).
  • Drive vulnerability and exposure management with risk‑based prioritization.
  • Run tabletop exercises, purple‑team activities, and lessons learned.
Your Knowledge, Skills, and Abilities
  • Deep knowledge of SOC operations (triage, incident lifecycle, evidence handling, documentation).
  • Strong grasp of Windows/*nix/AD/M365, identity security (SSO/MFA), network protocols, and cloud telemetry.
  • Expertise in detection engineering and query languages (SPL, KQL, Elastic DSL, AQL).
  • Familiarity with adversary emulation and frameworks (MITRE ATT&CK, D3FEND, CIS Controls).
  • Understanding of email security (phishing, BEC), vulnerability scanning/patching, and network security monitoring (IDS/IPS, PCAP).
  • Proficiency with SOAR concepts and playbook design (enrichment, containment, ticketing).
  • Scripting/automation (PowerShell, Python, or equivalent) for enrichment, triage, and response.
  • Clear written/verbal communication for executive briefings and technical reports.
  • Applicants must have authorization to work in the United States without current or future visa sponsorship.
Specific Qualifications
  • Experience: 7–10 years in MSSP settings; 5+ years on a SOC team; 2–4+ years in a lead/technical lead capacity.
  • Platforms (hands‑on in several):
    • EDR/XDR/MDR: CrowdStrike, SentinelOne, Blackpoint, Microsoft Defender for Endpoint, Cortex XDR, etc.
    • Microsoft ecosystem: Microsoft 365, Windows Defender / Defender for Endpoint, Defender for Office 365, Azure security telemetry (KQL, Log Analytics, Sentinel).
    • SIEM: Splunk, Microsoft Sentinel, Elastic, QRadar, Exabeam, or similar.
    • SOAR: Splunk SOAR, Cortex XSOAR, Sentinel automation.
    • Email security & awareness: Mimecast, KnowBe4, Material Security, M365 Defender for Office 365.
    • Vulnerability management: Tenable, Qualys, or Rapid7.
    • NSM/IDS: Zeek, Suricata, commercial IDS/IPS.
Process and Leadership

IR leadership: Proven track record leading medium/major incidents (ransomware, BEC, insider, cloud credential abuse). Cloud: Experience securing and monitoring AWS/Azure/GCP and M365 (identity and endpoint telemetry). Process: Built or matured playbooks, runbooks, use‑case catalogs, and service reporting. Demonstrated KPI/OKR management.

Certifications (nice to have)

CISSP, GIAC (GCIA/GCIH/GCFA/GCDA/GMON), OSCP, Azure/Microsoft security (SC‑200/SC‑100), Splunk, CrowdStrike CCFR/CCFA, or similar.

Availability

Able to participate in escalation/on‑call rotation and support off‑hours incidents as needed.

Education

BS in CS/Cybersecurity or equivalent experience (experience > degree where applicable).

Benefits
  • Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer.
  • Employer funding to HSA accounts and FSA access.
  • Access to a 401(k) through Vanguard with a guaranteed employer contribution.
  • Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.
  • 11 holidays with flexibility based on what is important for you and those you love.
  • Employer‑paid short‑term and long‑term disability, employer‑paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more.
  • Support for individual development through certifications, continued learning, conferences, and more.

We value a diverse workforce and a culture of inclusivity and belonging. All employment decisions shall be made without regard to age, race, creed, color, religion, gender, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Echelon Risk + Cyber is an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer (MSP or MSSP) - Remote (USA)
Senior Security Engineer (MSP or MSSP) - Remote (USA)

Echelon Risk + Cyber • United States

Remote
USD 140,000 - 170,000
Medical, dental, and vision insurance
HSA funding
401(k) with employer contribution
+2
SOC Manager
SOC Manager

GMI - Global Market Innovators • Scottsdale (AZ)

On-site
USD 100,000 - 130,000
Competitive salary and benefits package
401(k) match
Stock Appreciation Rights
+2
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Fargo (ND)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Training and development programs
+1
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Kansas City (KS)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Competitive Compensation
+2
Security Operations Center (SOC) Analyst (Remote)
Security Operations Center (SOC) Analyst (Remote)

Trace3 • Louisville (KY)

On-site
USD 70,000 - 90,000
Comprehensive medical, dental and vision plans
401(k) Retirement Plan with Employer Match
Competitive Compensation
+4
SOC Engineer
SOC Engineer

TENEX.AI • Overland Park (KS)

On-site
USD 100,000 - 130,000
SOC Engineer
SOC Engineer

TENEX.AI • Sarasota (FL)

On-site
USD 90,000 - 120,000
Cybersecurity Risk & Technical Advisory Consultant - Remote (USA)
Cybersecurity Risk & Technical Advisory Consultant - Remote (USA)

Echelon Risk + Cyber • Washington

On-site
USD 120,000 - 180,000
Medical, dental, vision insurance
HSA contributions
401(k) with employer contribution
+4
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2