Director, Security Operations & SOC Leader
USD 168K-255K Senior-level Contract
Tasks
- Conduct threat hunting
- Coordinate vulnerability handling for software and firmware
- Develop detection as code
- Develop incident response runbooks and playbooks
- Evidence security operations controls for compliance
- Implement security automation and orchestration
- Lead detection engineering and content management
- Lead insider threat investigations support
- Lead technical security reviews of systems and integrations
- Maintain MITRE ATT and CK coverage mapping
- Maintain incident response plan and playbook
- Manage DFIR retainer
- Manage DLP and insider risk tooling
- Manage EDR and email security
- Manage SIEM detection content lifecycle
- Onboard telemetry and log sources
- Operate insider risk and DLP monitoring
- Operationalize threat intelligence into detections
- Own security operations stack
- Partner on secure development practices
- Partner on vulnerability exploitation validation
- Produce security operations metrics for leadership
- Provide SEC incident disclosure technical input
- Run 24 7 hybrid SOC
- Run phishing simulation and security awareness training
- Run purple team exercises
- Run tabletop exercises
- Support M and A cybersecurity due diligence
- Support legal holds and evidence preservation
- Translate security risk for executive stakeholders
Perks/Benefits
- N/A
Skills/Tech-stack
800-171 | Automated response | CISSP | CMMC | Content Lifecycle | DFIR | DLP | Data Loss Prevention | Data loss | Detection and Response | Detection engineering | Detection-as-code | EDR | Email Security | Endpoint Detection and Response | Endpoint detection | Forensic Incident Response | GCFA | GCIA | GCIH | GRC | ICS Security | IEC 62443 | Incident Response | Insider Risk | Insider Threat | Log source management | Loss prevention | MITRE ATT and CK | Managed detection | Media Encryption | NIST 800 | NIST 800-171 | OT Security | Playbooks | Purple Team | Purple Team exercises | Removable Media | Removable media encryption | Runbooks | SEC Cyber Disclosure | SIEM | SIEM Content Lifecycle | SIEM content | SOAR | SOX ITGC | Security Automation | Security Compliance | Security Orchestration | Security Orchestration and Automated Response | Source Management | Tabletop Exercises | Team exercises | Telemetry onboarding | Threat Intelligence | Threat hunting | USB Encryption | Vulnerability Management | Vulnerability exploitation | “as-code”
Education
N/A
Regions
Countries
States
Cities
Related jobs
-
Team Lead, Security Operations Center (SOC) - 2nd Shift USD 121K-152KCyber Security | Detection engineering | EDR | Evidence Based Investigation | Incident Response401(k) plan matching | Bereavement leave | Employee assistance program | Employee discount program | Health and wellbeing benefitsSenior-level Full TimeRemote - Nationwide, United States R10h ago
-
Mgr, Risk Monitor & Intel USD 107K-171KAudit trails | Change Management | Compliance | DAX | Data IntegritySenior-level Full TimeSan Antonio, TX, United States12h ago
-
Case management | Corelight | CrowdStrike | Cyware CSAP | Detection SystemsHybrid work | On-call rotation | Telework optionMid-level ContractAustin, United States13h ago
-
Automated Enrichment Workflows | Automated enrichment | Correlation rules | Data Normalization | Detection engineeringHybrid work | Occasional after-hours supportMid-level ContractAustin, United States13h ago
-
Cloud Security | Cybersecurity | Data Architecture | Hybrid Data | Hybrid Data ArchitectureOnsite work 5 days per weekSenior-level Full TimeLas Vegas, Nevada, United States14h ago
-
Manager - AI SOC USD 134K-265KApplication Programming | Application Programming Interface | Automation | Automation and response | Case managementMid-level Full TimeChicago, Illinois, United States14h ago
-
Mid-level Full TimeHuntsville, Alabama, United States14h ago
-
Automation | Correlation rules | Event Correlation | Event collector | Event managementSenior-level Full TimeArlington/Rosslyn, Virginia, United States14h ago
-
Lead Security Engineer II, Splunk Security Content Visualization Expert (Secret Clearance) USD 102K-188KAlerting | Correlation searches | Dashboard Development | Data Modeling | Log ParsingSenior-level Full TimeArlington/Rosslyn, Virginia, United States14h ago
-
Project Cyber Engineer USD 95K-159KAccess Management | Cloud Security | Cybersecurity | Identity and Access Management | Identity and accessMid-level Full TimeColorado Springs, Colorado, United States14h ago
-
Access Control | Access Control Lists | Alert analysis | Coverage Validation | Detection Coverage ValidationOnsite work | Travel opportunitiesMid-level Full TimeArlington/Rosslyn, Virginia, United States14h ago
-
Project- Platform Software Engineer USD 95K-159KAWS GovCloud | Accreditation | Agile | Ansible | AuthenticationMid-level Full TimeColorado Springs, Colorado, United States14h ago
-
AI Security Analyst | Camden Corporate Office USD 128K-237KAI/ML | Access Control | Application Firewall | Automation | AzureDisaster recovery exercise support | Off-hours support | Periodic travelSenior-level Full TimeHouston, TX, United States22h ago
-
Senior Corporate Security Engineer USD 180K-240KAPI Integration | AWS | Access Control | Access Management | AtlassianSenior-level Full TimeRemote, United States R1d ago
-
Product Security Engineer USD 208K-312KAPI Security | Access Control | Advanced Security | Authentication & Authorization | Bug BountyMid-level Full TimeRemote - United States R1d ago
-
Security Engineer, Cloud USD 208K-312KAWS | AWS IAM | AWS Security | Access Management | CI/CDEvent support | Flexible time off | Healthcare | Mentorship | Remote workSenior-level Full TimeRemote - United States R1d ago
-
Forward Deployed Engineer - Security Clearance Required USD 170K-200KAzure DevOps | Bitbucket | CI/CD | Cloud infrastructure | ContainerizationEmployee assistance program | Flexible PTO | Home office stipend | Internal mobility | Learning and development stipendMid-level Full TimeTampa, FL - Hybrid R1d ago
-
Engineer IV, Cybersecurity USD 180K-205KAWS | Access Management | Artificial Intelligence | Azure | DevSecOps401k match | Dental insurance | Disability insurance | Life insurance | Medical insuranceSenior-level Full TimeMD - Gaither Rd., Rockville Corp …1d ago
-
Virtru Security Engineer USD 99K-225KAnsible | CI/CD | Cloud Security | Compliance validation | Data ClassificationDependent care | Paid leave | Professional development | Tuition assistance | Work-life programsMid-level Full TimeUSA, IL, Scott AFB (W Martin …1d ago
-
Temporary Senior Associate, Cyber Engineering USD 56K-84KAPIs | AWS | Azure | Containers | Incident ResponseFlexible scheduleSenior-level Full Time TemporaryUSA-NC-Virtual, United States R1d ago
-
Lead Engineer – Operational Technology Network Security USD 100K-151KAccess Management | Armis | Asset visibility | Check Point | CiscoAdoption Assistance | Backup dependent care | Employee resource groups | Infertility coverage | Mentorship programsSenior-level Full TimeUSA - PA - Conshohocken - …1d ago
-
Security Engineer and Firewall SME USD 77K-176KAWS Network | AWS Network Firewall | Alerting | Ansible | App-IDDependent care | Hybrid work option | Paid leave | Professional development | Remote work optionSenior-level Full TimeUndisclosed Location - USA, DC, Washington, …1d ago
-
Cybersecurity Manager/ISSO USD 124K-165K800-53 | ACAS | Continuous Monitoring | Control Validation | DISA SCAPSenior-level Full TimeUSA MD Andrews AFB - Andrews …1d ago
-
Security Operations Center Analyst USD 99K-225KEvent analysis | IT Forensics | Incident Response | Incident investigation | Security incident24/7 shift work | Dependent care | Paid leave | Professional development | Remote or hybrid or onsite work flexibilityEntry-level Full TimeUSA, NC, Fort Bragg (2175 Reilly …1d ago
-
NextGen Command Center Lead, Top Secret USD 170K-230KCISA compliance | Command and control | Crisis Action | Crisis Action Team Coordination | Crisis management401k company match | Career growth opportunities | Dental insurance | Health insurance | Hybrid work optionsSenior-level Full TimeUSA VA Herndon - 13857 Mclearen …1d ago