Live opening · Posted 7 days ago

Security Operations Lead

The Phoenix Group · District of Columbia, United States (Remote)
Linkedin Yes
You are 7 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 7 days ago
CompanyThe Phoenix Group
LocationDistrict of Columbia, United States (Remote)
Salary$140K/yr - $160K/yr · 3 benefits
Work modeYes
SourceLinkedin
Listed7 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
16 min from Linkedin publishing this role to us finding it
11 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
68,210 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Security Operations Lead
Responsibilities
Serve as the senior person on the floor for the evening shift (2:00 PM to 10:00 PM).
Define escalation criteria, including what warrants waking a manager, what can wait, and what the team resolves on its own.
Lead root cause analysis on any incident that reached containment, and update runbooks to prevent repeat events.
Set and maintain standards for shift logs, handovers, and queue health across all shifts.
Coach and develop Tier 1 and Tier 2 analysts, including assessing their readiness for promotion.
Triage and investigate alerts across SIEM, EDR, and cloud-native security tooling, and direct containment and remediation.
Represent the team in incident reviews and contribute to FedRAMP evidence collection.
Requirements
5+ years in security operations (SOC, NOC/SOC, or MDR environments), including experience as the senior person on shift.
A demonstrated record of developing people, in addition to resolving incidents.
Solid knowledge of cloud security monitoring, detection engineering, and incident response.
Hands-on experience with a SIEM platform and writing or tuning detection rules and use cases.
Working knowledge of network fundamentals (TCP/IP, DNS, firewalls, VPN, IDS/IPS) and log analysis.
Familiarity with frameworks such as MITRE ATT&CK, NIST 800-53, and NIST incident response guidance.
The confidence to set a standard and hold a team to it.
Tools and Technologies (experience with a similar toolset is fine)
SIEM and log management: Splunk, Microsoft Sentinel, Elastic, or similar
Endpoint and threat detection: CrowdStrike, Microsoft Defender, SentinelOne, or similar
Cloud platforms and native security services: AWS, Azure, GCP (GuardDuty, Security Hub, Defender for Cloud, or similar)
SOAR and automation: Cortex XSOAR, Splunk SOAR, or scripting in Python or PowerShell
Vulnerability management: Tenable, Qualys, or Rapid7
Ticketing and documentation: ServiceNow, Jira, or similar
Network and perimeter monitoring: firewalls, IDS/IPS, packet capture, NetFlow
Nice to Have
Security+, CySP+, GCIH, GCIA, GCED, CISSP, or cloud security certifications
Experience with FedRAMP, FISMA, or other federal compliance environments
Active security clearance, or the ability to obtain one (confirm with the client)
Experience in a 24x7 operations environment or a federal or defense contractor

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App