SOC Lead
Soni · Philadelphia, PA · 1 wk ago
HybridFull-time
About the role
The ideal candidate is a hands-on security operations professional who can balance technical incident response and detection expertise with leadership, process development, and team mentorship. This is an opportunity to play a key role in strengthening and scaling a modern SOC environment.
Responsibilities
- Lead daily SOC operations and serve as an escalation point for complex security incidents.
- Develop and maintain SOC runbooks, playbooks, and incident response procedures.
- Mentor SOC analysts and establish effective investigation and response practices.
- Build, tune, and optimize SIEM detections while reducing false positives.
- Lead threat hunting across SIEM, EDR, cloud telemetry, and threat intelligence sources.
- Manage security incidents through triage, containment, eradication, recovery, and post-incident review.
- Conduct root cause analysis and drive security remediation efforts.
- Implement automation and SOAR capabilities to improve SOC efficiency and scalability.
- Develop SOC metrics and reporting to measure operational performance and maturity.
- Partner with security, IT, engineering, and other cross-functional teams to improve overall security operations.
Requirements
- 5+ years of experience in Security Operations, Incident Response, Detection Engineering, Threat Detection, or a related field.
- Previous experience in a SOC Lead, Senior SOC Analyst, Incident Response Lead, or comparable senior-level security role.
- Demonstrated experience building or maturing SOC processes, procedures, and operational frameworks.
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Google SecOps, Splunk, or IBM QRadar.
- Experience with EDR platforms such as CrowdStrike, Microsoft Defender, or SentinelOne.
- Strong background in detection engineering, alert tuning, threat hunting, and incident response.
- Proficiency with Python, PowerShell, or Bash for security automation.
- Strong communication, documentation, analytical, and cross-functional collaboration skills.
- Demonstrated ability to mentor and develop security analysts.
Preferred Qualifications
- Experience with AWS, Azure, or Google Cloud security monitoring.
- Experience implementing SOAR and security automation.
- Familiarity with MITRE ATT&CK and threat intelligence programs.
- Experience building or maturing SOC capabilities within small to mid-sized organizations.
- Relevant certifications such as CISSP, GCIH, GCIA, GCFA, CySA+, or Security+.