SOC Manager
About the Role
This position will be responsible for managing a Security Operations Center (SOC) tools, team members, and engineering SOC tools solutions for Health and Human Services (HHS). Responsibilities include security architecture, design, analysis, and testing, as well as gathering technical requirements, developing complex solutions, testing architecture solutions, and implementation oversight. The role also involves developing and briefing SOC performance reports, conducting vulnerability assessments, making recommendations, and managing security incidents.
Responsibilities
- Manage and supervise SOC Tools Analysts (team of 5), providing guidance and delegation.
- Provide security analysis for integrated security solutions related to design, development, and integration of Man-Machine Interfaces and system-level requirements.
- Develop moderately complex security designs and test plans using existing technology.
- Prepare technical proposals for presentation to HHS and other stakeholders to update existing security technologies and add new technologies to the network.
- Work closely with the SAIC SOC Program Manager to identify and recommend process and system improvements for the HHS program.
- Create relevant documentation for changes to the current security architecture and provide customer-facing technical presentations as needed.
- Drive capabilities and execution to effectively optimize and improve HHS security.
- Demonstrate expert-level knowledge of security services and implementations.
- Provide technical oversight and direction to SOC personnel.
- Investigate, positively identify, and document anomalous events and incidents escalated by Tier 2 analysts.
- Conduct risk analysis and convert it into actionable monitoring recommendations for the SOC.
- Recommend remediation and mitigation strategies based on vulnerability assessment results.
- Provide support for security incidents throughout the incident lifecycle and make recommendations to protect infrastructure.
- Develop a metrics program to report on overall SOC performance and effectiveness.
- Effectively communicate with personnel at all levels, from the Executive Office to technicians, both verbally and in writing.
Tools and Technologies
- Splunk
- ServiceNow
- Palo Alto
- Archer
- Nessus
- Microsoft Exchange Online Protection
- CrowdStrike
- Trellix (NX/CM/AX)
- Cisco ISE
Requirements
- Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field and a minimum of 13 years of experience. Alternatively, an additional 4 years of experience may substitute for the degree.
- 3+ years of Cyber Security / SOC experience.
- Must be a U.S. citizen with the ability to obtain a Public Trust clearance.
- 2+ years of team leadership/management experience.
- Demonstrated experience with risk analysis.
- Demonstrated experience briefing senior leaders.
Preferred Qualifications
- Certified Information Systems Security Professional (CISSP).
- Experience with Information Assurance Policy and Guidelines.
- Familiarity with NIST Special Publication 800-53 and the NIST Cybersecurity Framework.
- ITIL® Foundation Level or higher certification.
Location
This role is primarily remote, with a preference for candidates located within the DC Capital Region for occasional onsite work.
Pay
Target salary range: $120,001 – $160,000, based on experience and other factors.