SOC Manager
Candidates must reside in one of our approved hiring hubs: DC/Maryland/Virginia, Raleigh/Durham/Chapel Hill, NC, Denver/Colorado Springs, CO, or Dallas/Fort Worth, TX.
About the role
Second Front Systems is looking for a technically fluent, high-ownership, metrics-driven Security Operations Center (SOC) Manager to strengthen our security operations function, architecting modern defensive capabilities across cloud-native infrastructure. Operating at the high-stakes intersection of defense tech and national security, you will be responsible for monitoring, detecting, and responding to threats in cloud-native ecosystems and scaling defensive maturity across the organization. You will own the SOC strategy and execution, partner across engineering and product to embed security controls into platform DNA, ensuring that mission-critical software for the free world remains secure and our defenders operate in a resilient, monitored environment.
Responsibilities
- Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
- Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
- Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.
- Govern the defensive stack—SIEM, EDR, and automated playbooks—ensuring engineering delivers lean, high-fidelity operations at scale.
- Establish proactive threat hunting programs, synthesizing external intelligence to intercept emerging threats before they reach mission-critical systems.
- Synchronize security controls with engineering and product squads, embedding rigorous automated defenses into platform architecture.
- Mentor and scale a high-performing security operations squad, anchoring a culture built on accountability and technical craft.
- Optimize vendor and MDR relationships, ensuring third-party partnerships deliver the technical execution the mission demands.
Requirements
- 8+ years in cyber operations, incident response, and threat intelligence with minimum 3 years leading high-agency security operations teams.
- Deep technical mastery building modern SOC functions: SIEM architecture, EDR stack deployment, high-fidelity incident response frameworks.
- Fluency in cloud-native environments: AWS, Kubernetes security, containerized workload defense, logging pipeline engineering.
- Track record engineering detection logic and automated playbooks that scale defensive operations and reduce alert noise.
- Ability to mentor technical talent and lead complex security initiatives through ambiguity in high-growth startup environments.
- Clear communication translating technical blast radius and complex risk into unsentimental recommendations for leadership.
- Expertise navigating FedRAMP, DoD SRG, and CMMC compliance in regulated government and defense environments.
- Hands-on scripting and automation engineering: Python, Terraform, SOAR playbooks for detection and response tooling development.
Pay
The base salary for this position will fall between $205,000 and $215,000. Your ultimate compensation will be determined by professional background, technical proficiency, seniority, and regional cost factors. This opportunity includes potential eligibility for equity awards and discretionary bonuses.
Benefits
- 100% employer-paid medical, dental, and vision coverage for you and your dependents
- 401(k) with a 3% company contribution
- Comprehensive wellness benefits, including a One Medical membership, mental health resources, family planning support, and more
- Equity incentive plan
- New hire technology and home office stipend
- Annual professional development stipend
- Flexible paid time off, plus all federal holidays
- Generous parental leave
- Flexible remote work opportunities
- Employee referral bonus program
About Us
Second Front Systems (2F) is a public-benefit software company powering software for the free world. We eliminate the friction that slows innovation, enabling faster, more secure development and deployment of software across government and regulated networks. Built by national security veterans and backed by top-tier venture capital, our platform is trusted by the world’s leading organizations to cut deployment timelines from years to weeks. We move fast, solve hard problems, and deliver trusted capabilities where they’re needed most. Our work strengthens global security and gives the United States and its allies a lasting competitive advantage.