Manager, Security Operations Center; SOC)
Listed on 2026-09-28
-
IT/Tech
-
Management
Position: Manager, Security Operations Center (SOC)
Location: Hybrid - College Park, MD (On-site 2-3 days per week)
Work Authorization: US Citizenship Required
Blue Voyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of roughly 60 employees, playing a critical role in protecting client relationships and driving retention.
This is a client-facing leadership role responsible for shaping how customers experience the SOC — from escalation handling through the metrics and reporting that inform leadership decisions. The role carries strong potential for growth into a higher-level leadership position as the team and business scale, making it a great fit for an ambitious leader who wants to build and shape a growing organization.
WhatYou'll Do
- Lead, develop, and manage a team of Team Leads, Trainers, and Security Analysts, providing strategic direction, coaching, and performance management
- Assume full responsibility and accountability for ensuring all SOC customers receive world-class service
- Own the management of customer escalations, with the primary goal of client retention, partnering closely with Client Success on remediation plans and client communication
- Provide oversight and management of Team Leads and the wider Analyst team, ensuring consistent quality and performance across the SOC
- Lead post-incident review meetings to capture lessons learned following the resolution of critical events
- Ensure key Security Operations actions incorporate relevant customer impact considerations by engaging key stakeholders and communicating known/suspected implications of technical decisions
- Validate that Security Operations activities adequately address customer requirements across all MSS services
- Oversee operations in deterring, identifying, monitoring, investigating, and analyzing network intrusions
- Supervise complex event investigation and incident declaration, ensuring events are properly identified, analyzed, and escalated to incidents
- Ensure the team's incident investigation, handling, response, and documentation meet quality and SLA standards
- Assist in the advancement of security policies, procedures, and automation
- Develop incident response reporting and policy updates as needed
- Partner cross-functionally with Client Success, Content Engineering, Threat Hunt, and Product leadership to drive service improvements and represent the SOC's priorities
- Develop and maintain SOC performance metrics, delivering regular reporting on team performance, incident trends, and customer outcomes to leadership
- Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure continued business as usual
- Maintain a strong awareness of the current threat landscape
- Ability and willingness to commute to the College Park, MD office 2-3 days per week
- Experience working within a global organization, partnering with distributed teams across multiple regions and time zones
- Prior experience managing managers or team leads, with direct accountability for team performance and development
- Ability to handle high-pressure situations in a productive and professional manner
- Ability to work directly with customers to understand requirements for and feedback on security services, including managing escalations to protect client relationships
- Advanced written and verbal communication skills, with the ability to present complex technical topics in clear and easy-to-understand language
- Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distributed team
- Able and willing to work in a 24/7/365 environment
- Knowledge of and experience with the Microsoft Security Stack (Defender, Sentinel etc)
- Knowledge of and experience with intrusion detection/prevention systems and SIEM software
- Advanced knowledge and understanding of network protocols and devices
- Advanced experience with Mac OS, Windows, and Unix systems
- Ability to analyze event logs and recognize signs of cyber intrusions/attacks
- Strong knowledge of: SIEM, Packet Analysis, SSL Decryption, Malware Detection, HIDS/NIDS, Network Monitoring Tools, Case Management System, Knowledge Base, Web Security Gateway, Email Security, Data Loss Prevention, Anti-Virus, Network Access Control, Encryption, and Vulnerability Identification
- Experience partnering with or managing teams based in the Philippines
- Experience in network/host vulnerability analysis, intrusion analysis, digital…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).