Live opening · Posted 7 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Security Operations Lead
Responsibilities
Serve as the senior person on the floor for the evening shift (2:00 PM to 10:00 PM).
Define escalation criteria, including what warrants waking a manager, what can wait, and what the team resolves on its own.
Lead root cause analysis on any incident that reached containment, and update runbooks to prevent repeat events.
Set and maintain standards for shift logs, handovers, and queue health across all shifts.
Coach and develop Tier 1 and Tier 2 analysts, including assessing their readiness for promotion.
Triage and investigate alerts across SIEM, EDR, and cloud-native security tooling, and direct containment and remediation.
Represent the team in incident reviews and contribute to FedRAMP evidence collection.
Requirements
5+ years in security operations (SOC, NOC/SOC, or MDR environments), including experience as the senior person on shift.
A demonstrated record of developing people, in addition to resolving incidents.
Solid knowledge of cloud security monitoring, detection engineering, and incident response.
Hands-on experience with a SIEM platform and writing or tuning detection rules and use cases.
Working knowledge of network fundamentals (TCP/IP, DNS, firewalls, VPN, IDS/IPS) and log analysis.
Familiarity with frameworks such as MITRE ATT&CK, NIST 800-53, and NIST incident response guidance.
The confidence to set a standard and hold a team to it.
Tools and Technologies (experience with a similar toolset is fine)
SIEM and log management: Splunk, Microsoft Sentinel, Elastic, or similar
Endpoint and threat detection: CrowdStrike, Microsoft Defender, SentinelOne, or similar
Cloud platforms and native security services: AWS, Azure, GCP (GuardDuty, Security Hub, Defender for Cloud, or similar)
SOAR and automation: Cortex XSOAR, Splunk SOAR, or scripting in Python or PowerShell
Vulnerability management: Tenable, Qualys, or Rapid7
Ticketing and documentation: ServiceNow, Jira, or similar
Network and perimeter monitoring: firewalls, IDS/IPS, packet capture, NetFlow
Nice to Have
Security+, CySP+, GCIH, GCIA, GCED, CISSP, or cloud security certifications
Experience with FedRAMP, FISMA, or other federal compliance environments
Active security clearance, or the ability to obtain one (confirm with the client)
Experience in a 24x7 operations environment or a federal or defense contractor
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.