Security Operations Lead
Listed on 2026-08-04
-
IT/Tech
Cybersecurity, Security Management & Operations
Security Operations Lead
The Security Operations Lead will oversee all SOC functions and lead a blended team of SOC Analysts and Security Engineers to ensure rapid detection, investigation, and response to security threats. This role is responsible for driving threat hunting, leading major incidents, engineering detection capabilities, and maturing SOC operations to stay ahead of evolving adversary behaviors. The Lead acts as the central coordination point during security events and sets the strategic direction for the SOC to ensure continuous, mission‑critical security coverage.
Key Responsibilities SOC Leadership & Operations- Lead day‑to‑day SOC operations, including queue management, alert triage oversight, escalation handling, on‑call rotations, and daily situational reporting.
- Mentor and develop SOC analysts across tiers; refine SOPs, workflows, and response playbooks.
- Drive threat hunting activities focused on identifying patterns, outliers, and TTP‑aligned behaviors across host, network, email, and cloud logs.
- Oversee SIEM dashboarding, alert tuning, log source health, and rule/correlation development to strengthen detection depth.
- Coordinate with Security Engineering to ensure logging fidelity, sensor coverage, and integration of new technologies.
- Lead the full lifecycle of incident response: identification, containment, eradication, recovery, forensics support, and post‑incident reporting.
- Perform or direct deep‑dive investigations using SIEM, NDR, EDR, packet analysis tools, and forensic artifacts.
- Provide expert investigative support for large‑scale or complex incidents where technical detections may not be available.
- Guide analysts during high‑severity incidents and act as the primary interface with client leadership and internal stakeholders.
- Oversee threat intelligence intake and ensure IOCs, adversary behaviors, and campaign indicators are integrated into SOC detections.
- Develop and optimize SIEM correlation rules, dashboards, and monitoring logic.
- Enhance playbooks and automation pipelines to improve consistency and reduce analyst workload.
- Ensure ongoing alignment to evolving threat actor TTPs, including insider threat and APT‑style behaviors.
- Integrate new data sources into SOC detection pipelines and validate alert efficacy.
- 8 years of cybersecurity experience, with 3+ years leading SOC or IR teams.
- Hands‑on experience triaging alerts, logs, events, and incident artifacts across enterprise environments.
- Strong experience with one or more of the following technologies: SIEM (Splunk, Elastic, etc.), NDR (Extra Hop), EDR/XDR (Trellix), and packet analysis tools.
- Demonstrated ability to lead incident response for high‑severity cybersecurity events.
- Advanced experience in threat hunting, analytics, and adversary behavior profiling.
- Certifications such as CISSP, GCIH, GCIA, GCED, CEH, or similar.
- Experience building SIEM/SOAR automations and custom detection content.
- Familiarity with malware triage, static/dynamic analysis, and IOC development.
- Experience leading SOCs supporting federal missions or high‑tempo operational environments.
- Exposure to cloud security monitoring (Azure, AWS, GCP) and SaaS logging integrations.
The pay range for the states of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Washington, Vermont, the District of Columbia, and the city of Cleveland is:
$126,300—$243,100 USD
Equal Employment Opportunity StatementWe believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by federal, state, or local law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.
For details, view a copy of the Accenture Federal Services…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).