SOC Operations Manager

Harmonia Holdings Group, LLC

Washington (District of Columbia)

Hybrid

USD 150,000 - 190,000

Full time

21 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental and vision insurance
401(k) matching
Flexible schedules / teleworking
Paid holidays and PTO

Job summary

Revolutional in Washington, DC is seeking an experienced SOC Operations Manager to lead Tier 2 Threat Watch and act as the senior authority for event validation and incident assessment. You will oversee analysts, validate events, assess impact, and coordinate with federal partners to maintain a secure enterprise environment.

The role requires hands-on SIEM and IDS/IPS expertise, Python scripting for automation, and a strong grasp of NIST/FISMA frameworks.

Qualifications

  • Bachelor's degree in CS, information security, or related field (or equivalent experience).
  • 5+ years in security operations, including Tier 2 or senior SOC experience.
  • Experience supervising SOC analysts or watch floor operations.
  • Active Secret clearance required.

Responsibilities

  • Lead Tier 2 Threat Watch Officer function and oversee event triage.
  • Validate security events and determine response actions.
  • Correlate anomalies across IDS, IPS, and SIEM to identify threats.
  • Recommend network config changes to close detection gaps.
  • Author and maintain intrusion detection signatures.
  • Coordinate with law enforcement and interagency partners on significant events.

Skills

Tier 2 Threat Watch
Event validation
IDS/IPS/SIEM analysis
Threat intelligence
Incident response
Leadership / supervision
Interagency coordination
Python scripting

Education

Bachelor's degree in Computer Science / Information Security / related field

Tools

SIEM platforms
IDS/IPS platforms
Python scripting

Job description

Job Description

Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes. We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.

SOC Operations Manager

Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred)

Terms: Full-time

Salary: $150-190k DOE

Clearance: Active Secret required

Travel: 0-10%

Project Description

This position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, incident response, and threat intelligence across a complex enterprise network environment. The SOC operates under demanding federal cybersecurity compliance requirements and supports multiple government stakeholders across classified and unclassified networks.

Position Description

As a SOC Operations Manager at Revolutional, you lead the Tier 2 Threat Watch Officer function and are the senior operational authority for event validation, incident assessment, and analyst oversight during your watch. You validate and confirm security events, assess operational impact, correlate anomalies across IDS, IPS, and SIEM platforms, and make real-time recommendations that shape the program's defensive posture.

What You Will Own
  • Tier 2 Threat Watch Officer function and operational leadership
  • Security event validation, impact assessment, and escalation decisions
  • IDS/IPS/SIEM anomaly correlation and network configuration recommendations
  • Intrusion detection signature authorship and maintenance
  • High Value Asset monitoring and protection oversight
  • Tier 1 analyst oversight, performance, and operational discipline
  • Interagency coordination for significant security events
  • Current threat awareness and its application to enterprise security posture
Responsibilities
  • Lead the Tier 2 Threat Watch Officer function; serve as the senior operational authority for event triage, validation, and incident assessment during assigned watch periods
  • Validate and confirm security events; assess operational impact and determine appropriate response actions, escalation paths, and stakeholder notifications
  • Correlate anomalies across IDS, IPS, and SIEM platforms to distinguish genuine threats from false positives and identify complex, multi-vector attack patterns
  • Recommend network configuration changes to mitigate identified threats, close detection gaps, and strengthen defensive posture
  • Author and maintain intrusion detection signatures to improve detection fidelity against current and emerging threat actors and TTPs
  • Monitor High Value Assets and ensure heightened detection coverage, alert fidelity, and response readiness for critical systems
  • Coordinate with law enforcement, counterintelligence, and interagency partners on significant security events requiring external collaboration or notification
  • Oversee Tier 1 SOC analysts; direct workload, validate analyst actions, enforce SOC procedures, and provide real-time coaching during active events
  • Maintain current awareness of the threat landscape, adversary TTPs, and emerging attack vectors; actively apply threat intelligence to improve program detection and response capabilities
  • Develop and contribute to SOC playbooks, standard operating procedures, and shift documentation
  • Produce accurate shift reports, incident summaries, and escalation notifications for program leadership and government stakeholders
  • Write scripts in Python or equivalent languages to automate analyst workflows, improve detection capabilities, or support SOC tool management
What You Bring (Requirements)

Baseline Requirements

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
  • 5 or more years of security operations experience, including hands-on Tier 2 or senior SOC analyst experience
  • Demonstrated experience in a supervisory or team lead capacity overseeing SOC analysts or watch floor operations
  • Active Secret clearance required
Technical & Domain Capabilities
  • Deep experience with security event validation, IDS/IPS/SIEM correlation, and incident impact assessment in enterprise network environments
  • Hands-on experience authoring intrusion detection signatures for IDS/IPS platforms
  • Proficiency with SIEM platforms: search, correlation rule development, alert tuning, and dashboard operations
  • Experience monitoring High Value Assets and applying elevated detection and response protocols
  • Demonstrated ability to recommend and communicate network configuration changes based on threat analysis findings
  • Experience coordinating with external agencies or government partners during significant security events
  • Proficiency scripting in Python or equivalent language for SOC automation, workflow improvement, or tool integration
  • Current knowledge of adversary TTPs, threat actor trends, and the federal cybersecurity threat landscape
  • Familiarity with FISMA, NIST incident response frameworks, and federal security operations standards
Core Strengths
  • Technically authoritative Tier 2 operator — your event assessments are accurate, well-reasoned, and defensible under scrutiny
  • Decisive under pressure: you make sound calls on complex, fast-moving events without waiting for perfect information
  • Effective supervisor who holds Tier 1 analysts to standard, develops their tradecraft, and keeps the watch floor operationally disciplined
  • Clear communicator who produces crisp incident documentation, sharp shift handoffs, and credible interagency coordination
Certifications

One Or More Of The Following Is Preferred

  • CISSP, GCIA (GIAC Certified Intrusion Analyst), GCIH (GIAC Certified Incident Handler), CySA+, or equivalent security operations credential
Nice to Have (Differentiators)
  • Experience leading Tier 2 operations in a federal civilian, defense, or intelligence SOC environment
  • Background in intrusion detection signature development for commercial and custom IDS/IPS platforms
  • Familiarity with High Value Asset (HVA) monitoring frameworks and CISA HVA assessment processes
  • Experience with threat hunting or kill-chain-based detection methodologies
  • Familiarity with Zero Trust monitoring or cloud-native SOC operations
  • Active TS/SCI clearance
Company Culture & Recognitions

Here At Revolutional We Are Pleased To Have Been Repeatedly Recognized For Our Outstanding Work Culture, The Innovative Work We Do, And The Employees On Our Team Who Make a Difference Each Day. Some Of These Recognitions Include

  • Recognized as a Top 20 "Best Place to Work in Virginia"
  • Recipient of Department of Labor's HireVets Gold Medallion
  • Great Place to Work Certification for five years running
  • A Virginia Chamber of Commerce Fantastic 50 company
  • A Northern Virginia Technology Council Tech 100 company
  • Inc. 5000 list of fastest growing companies for eleven years
  • Two-time SBA SBIR Tibbett's Award winner
  • Virginia Values Veterans (V3) Certification
Benefits

In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to

  • Traditional and HSA- eligible medical insurance plans
  • 100% employer-paid dental and vision insurance options
  • 100% employer-sponsored STD, LTD, and life insurance
  • 5% 401(k) company matching
  • Flexible-schedules and teleworking options
  • Paid holidays and PTO Accrual Plans
  • Paid Parental Leave
  • Professional development and career growth opportunities
  • Team and company-wide events, recognition, and appreciation-- and so much more!
Get In Touch

Check out our Revolutional | LinkedIn to find out a little more about who we are and if we are the right next step for your career!

Revolutional is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Revolutional does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@revolutional.com.

"Know Your Rights: Workplace Discrimination is Illegal" Poster | U.S. Equal Employment Opportunity Commission

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Operations Manager
SOC Operations Manager

Revolutional • Kansas City (MO)

On-site
USD 150,000 - 190,000
Medical insurance
Dental & Vision
STD/LTD/Life insurance
+6
SOC Watch Officer
SOC Watch Officer

Revolutional • Chandler (AZ)

On-site
USD 130,000 - 160,000
Medical insurance
Dental & vision insurance
401(k) matching
+1
Security Operations Center (SOC) Chief
Security Operations Center (SOC) Chief

Revolutional • Suitland (MD)

On-site
USD 175,000 - 235,000
Medical insurance
Dental insurance
Vision insurance
+6
Cybersecurity Analyst - Tier 2
Cybersecurity Analyst - Tier 2

Revolutional • Martinsburg (WV)

On-site
USD 90,000 - 130,000
Medical insurance
Dental and vision insurance
401(k) company matching
+1
Senior Threat Hunter
Senior Threat Hunter

Revolutional • Washington

On-site
USD 135,000 - 175,000
Medical insurance
Dental and vision insurance
401(k) matching
+2
Senior Systems Engineer (Top Secret)
Senior Systems Engineer (Top Secret)

Harmonia Holdings Group, LLC • Washington

On-site
USD 150,000 - 180,000
Comprehensive medical coverage
401(k) with company match
Professional development opportunities
Technical Support Analyst (Tier II)
Technical Support Analyst (Tier II)

Revolutional • Washington

On-site
USD 75,000 - 95,000
Medical insurance
401(k) company match
Flexible schedules
+2
Lead Solutions Architect
Lead Solutions Architect

Harmonia Holdings Group, LLC • Washington

Hybrid
USD 160,000 - 225,000
Medical insurance
Dental & Vision
401(k) matching
+2
Lead Systems Engineer
Lead Systems Engineer

Harmonia Holdings Group, LLC • McLean (VA)

Hybrid
USD 160,000 - 190,000
Traditional medical insurance
Dental and vision insurance
Teleworking options
+1
Senior Systems Engineer (Top Secret)
Senior Systems Engineer (Top Secret)

Revolutional • Washington

On-site
USD 150,000 - 180,000
Medical insurance
Dental and Vision insurance
STD/LTD/Life insurance
+6