SOC Cyber Security Manager
Listed on 2026-08-15
-
IT/Tech
Cybersecurity
SOC Cyber Security Manager
GDIT has an opening for a SOC Cyber Security Manager supporting the Army National Guard (ARNG) on an IT Service Management contract that operates within the ITIL framework. This program delivers and protects ARNG's global IT services across networking, compute, storage, infrastructure, cybersecurity, applications, hosting, and program management. This role leads the team that defends those services.
As the SOC Cyber Security Manager, you'll combine hands-on technical leadership with people management—overseeing SOC operations, mentoring analysts, and ensuring alignment with ARNG and DoW cybersecurity standards and mission requirements.
Meaningful Work and Personal Impact
- Manage day-to-day SOC operations: monitoring, incident triage, response, and escalation.
- Lead, coach, and develop SOC analysts, including feedback, performance management, and career development in line with GDIT people manager requirements and training.
- Maintain SOC procedures, playbooks, and SOPs for consistent, high-quality event response.
- Set priorities, assign work, and ensure coverage across shifts.
- Serve as the primary SOC point of contact for ARNG stakeholders and GDIT teams.
Technical Cyber Defense & Forensics
- Oversee and, as needed, perform forensic analysis to identify intrusion indicators and threat actors.
- Use data from tools such as IDS, firewalls, SIEM, network logs, and endpoint security to analyze events and lead mitigation.
- Interpret and report events and anomalies per network defense directives, ensuring timely response and reporting.
- Direct evaluation, testing, recommendation, and maintenance of cybersecurity tools, policies, procedures, and access management.
Policy, Standards & Risk Management
- Ensure SOC plans, controls, and procedures align with DoW, Army, NIST, and ARNG cybersecurity standards.
- Identify risks and exposures, determine root causes, and drive corrective and preventive actions.
- Refine techniques for risk assessments, compliance audits, and incident investigations.
- Oversee data correlation and SIEM content design to enable effective threat detection and mapping to users, systems, and threat actors.
Stakeholder Coordination & Governance
- Coordinate cybersecurity inspections, tests, and reviews with all stakeholders.
- Oversee ARNG support for eMASS structure and workflow.
- Coordinate cybersecurity papers and plans with partners such as CYBERCOM, ARCYBER, Air National Guard Cyber, NSA, FBI, DOJ, and DHS.
- Support enforcement of DoW Cyberspace Workforce Framework and certification programs across the SOC team.
- Assist ARNG with streamlined processes for eMASS access requests in support of RMF.
Architecture, Vulnerability Management & Authorization Support
- Lead security architecture and vulnerability reviews with system owners and admins, including scans, configuration reviews, and documentation analysis.
- Oversee dissemination of approved policy and process documentation for system authorization (DoW, Army, NIST guidance).
- Collaborate with engineering and operations to recommend hardening and architectural improvements based on SOC findings.
What You'll Need to Succeed
- Preferred:
Bachelor's in cybersecurity, information assurance, computer science, or related field; or equivalent combination of education, certifications/training, and experience. - Typically 7+ years in cybersecurity, information assurance, or related fields.
- 2+ years leading or managing a cyber or SOC team (formal or informal leadership).
- Strong analytical, problem-solving, and decision-making skills.
- Proven experience with enterprise security tools (SIEM, IDS/IPS, firewalls, endpoint protection, vulnerability scanners).
- Demonstrated ability to manage and mentor staff, conduct reviews, and support career development; willingness to complete all required GDIT people manager training.
- Organized, reliable, able to manage multiple priorities in a fast-paced SOC.
- Strong customer-service orientation; comfortable with senior military and government stakeholders.
- Clear verbal and written communication in meetings, briefings, and incident reports.
- Preferred familiarity with DoW 2875, ACTCS, RMF, and eMASS.
- Self-motivated, quick learner, committed to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).