Team Lead, Security Operations Center (SOC) - 3rd Shift
Listed on 2026-08-10
-
IT/Tech
Security Management & Operations, Cybersecurity
SOC Team Lead
Our Security Operations Center (SOC) is seeking a SOC Team Lead to own day-to-day SOC execution, strengthen how the team operates, and advance the maturity of our detection and response capabilities. This role manages a team of analysts directly and is responsible for ensuring the SOC runs with clarity, consistency, and measurable results across security monitoring, detection engineering, threat hunting, incident response governance, and cross-functional coordination.
This role is available on 3rd shift (Monday – Friday, 12:00 AM–9:00 AM CST) and owns coverage, escalation readiness, and investigation quality for its shift. It's ideal for a leader who can balance hands-on security operations with people management, process ownership, and analyst development; improving how the SOC runs day-to-day while keeping incidents handled, documented, and escalated in line with established procedures.
Key Responsibilities
Team Leadership & People Management
- Lead a team of SOC analysts as their direct manager, including coaching, performance management, and career development.
- Own shift coverage, scheduling, and escalation readiness so the SOC maintains consistent quality across the shift's hours.
- Develop analysts through mentorship and reinforcement of structured, evidence-based investigation practices.
SOC Operations Leadership (Execution, Quality & Continuous Improvement)
- Own day-to-day SOC execution: queue health, triage consistency, escalation discipline, and documentation quality.
- Set and reinforce expectations for how alerts, investigations, and incidents are handled across the team.
- Identify and resolve workflow inefficiencies that slow response or create friction for analysts.
- Turn recurring pain points into measurable process, automation, or documentation improvements.
Detection Engineering Direction & Threat-Informed Defense
- Set detection engineering priorities based on threat intelligence, control gaps, incident learnings, and monitoring weaknesses.
- Oversee tuning across SIEM, SOAR, EDR, NDR, and log analytics platforms to improve fidelity and reduce noise.
- Ensure new detections, use cases, behavioral analytics, and ATT&CK-aligned content are actionable and fit SOC workflows.
- Partner with platform owners and engineering teams to improve telemetry quality and close detection gaps.
- Feed hunt findings, incident patterns, and control observations back into the detection pipeline.
Incident Response Governance
- Ensure incidents are identified, tracked, escalated, and reported per established incident management procedures.
- Reinforce severity-based response expectations, communications requirements, and required response artifacts across the incident lifecycle.
- Ensure investigation timelines, decisions, evidence, and outcomes are documented clearly and defensibly.
- Coordinate with leadership and partner teams during higher-severity incidents and retrospectives.
- Operationalize audit log review, logging-failure escalation, and incident reporting obligations.
Cross-Functional Coordination
- Coordinate with GRC, IAM, Infrastructure, Cloud, App Sec, Vulnerability Management, and other partner teams during investigations, follow-up, and control improvement.
- Clarify ownership boundaries and keep handoffs timely and documented.
- Translate SOC findings into remediation guidance and actionable follow-up for partner teams.
- Support policy, audit, and leadership discussions with accurate operational context.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).