SOC Operations Manager
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Security Management & Operations
Revolutional delivers advanced technology solutions and mission support to federal agencies across civilian, health, and national security environments. We apply modern capabilities, including AI/ML, cloud, cybersecurity, and IT modernization to solve complex challenges, enable faster and more secure operations, and drive measurable mission outcomes.
We are redefining how federal technology gets built and delivered by operating with a product mindset, prioritizing speed, ownership, and execution over bureaucracy.
SOC Operations ManagerLocation: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote optional, local preferred)
Terms: Full-time
Salary: $150-190k DOE
Clearance: Active Secret required
Travel: 0-10%
Project DescriptionThis position supports a large-scale federal security operations program delivering 24/7/365 continuous monitoring, intrusion detection, incident response, and threat intelligence across a complex enterprise network environment. The SOC operates under demanding federal cybersecurity compliance requirements and supports multiple government stakeholders across classified and unclassified networks.
Position DescriptionAs a SOC Operations Manager at Revolutional, you lead the Tier 2 Threat Watch Officer function and are the senior operational authority for event validation, incident assessment, and analyst oversight during your watch. You validate and confirm security events, assess operational impact, correlate anomalies across IDS, IPS, and SIEM platforms, and make real‑time recommendations that shape the program’s defensive posture.
You are a technically deep operator and a credible team leader. You oversee Tier 1 staff, author intrusion detection signatures, monitor High Value Assets, and maintain current threat awareness that you actively apply to improve the program’s detection and response capabilities. When events require interagency coordination, you are the person who initiates and manages that engagement.
What You Will Own- Tier 2 Threat Watch Officer function and operational leadership
- Security event validation, impact assessment, and escalation decisions
- IDS/IPS/SIEM anomaly correlation and network configuration recommendations
- Intrusion detection signature authorship and maintenance
- High Value Asset monitoring and protection oversight
- Tier 1 analyst oversight, performance, and operational discipline
- Interagency coordination for significant security events
- Current threat awareness and its application to enterprise security posture
- Lead the Tier 2 Threat Watch Officer function; serve as the senior operational authority for event triage, validation, and incident assessment during assigned watch periods
- Validate and confirm security events; assess operational impact and determine appropriate response actions, escalation paths, and stakeholder notifications
- Correlate anomalies across IDS, IPS, and SIEM platforms to distinguish genuine threats from false positives and identify complex, multi‑vector attack patterns
- Recommend network configuration changes to mitigate identified threats, close detection gaps, and strengthen defensive posture
- Author and maintain intrusion detection signatures to improve detection fidelity against current and emerging threat actors and TTPs
- Monitor High Value Assets and ensure heightened detection coverage, alert fidelity, and response readiness for critical systems
- Coordinate with law enforcement, counterintelligence, and interagency partners on significant security events requiring external collaboration or notification
- Oversee Tier 1 SOC analysts; direct workload, validate analyst actions, enforce SOC procedures, and provide real‑time coaching during active events
- Maintain current awareness of the threat landscape, adversary…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).