> Markdown version of [/jobs/ext/1299739-soc-operations-lead-managed-detection-response-mdr-lead](https://www.wearedevelopers.com/jobs/ext/1299739-soc-operations-lead-managed-detection-response-mdr-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Operations Lead / Managed Detection & Response (MDR) Lead - **Company:** cFocus Software Incorporated - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cloud Computing Security, Computer Telephony Integration, Event Logging, Intrusion Detection and Prevention, Microsoft Security Essentials, Security Information and Event Management, Cloud Platform System, Mitre Att&ck, Mttr, Cybercrime, Microsoft Sentinel, Splunk - **Published:** July 16, 2026 - **Apply:** http://cfocussoftware.applytojob.com/apply/jobs/details/GvJnGpPjbH ## About the Role * 10+ years of cybersecurity operations experience. * 5+ years leading enterprise SOC or MDR environments. * Experience supporting federal civilian or DoD environments. * Experience managing large-scale SOC operations in environments exceeding: + 10,000+ users, + enterprise cloud environments, + and large SIEM deployments. * Experience with: + Splunk Enterprise Security, + Microsoft Sentinel, + CrowdStrike, + EDR/XDR platforms, + SOAR technologies, + and cloud security monitoring. * Deep understanding of: + MITRE ATT&CK, + incident response, + detection engineering, + and threat-informed defense. * Strong executive briefing and oral presentation skills. Preferred Certifications * CISSP * GCIA * GCIH * GMON * GSOC * Splunk Architect/Admin certifications * Microsoft Security certifications ## Description The SOC Operations Lead will oversee 24x7x365 Security Operations Center (SOC) and Managed Detection & Response (MDR) operations supporting a large federal enterprise environment. The Lead will direct SOC analysts, incident responders, and MDR personnel responsible for security monitoring, alert triage, incident analysis, escalation, containment coordination, reporting, and continuous operational improvement. The ideal candidate possesses deep experience leading enterprise SOC operations supporting federal agencies, including SIEM operations, endpoint detection and response (EDR), cloud security monitoring, incident coordination, and executive cyber reporting., * Lead enterprise SOC and MDR operations supporting on-premises and cloud environments. * Oversee 24x7 monitoring, detection, triage, and escalation activities. * Direct operational workflows for: + SIEM monitoring, + alert management, + incident coordination, + case management, + and operational reporting. * Manage analyst teams supporting: + Splunk, + Microsoft Sentinel, + CrowdStrike, + Sysmon, + Windows event logging, + and cloud telemetry platforms. * Develop and maintain SOC SOPs, playbooks, runbooks, escalation matrices, and reporting procedures. * Lead operational metrics reporting including: + MTTD, + MTTR, + false positive rates, + automation effectiveness, + analyst productivity, + and incident impact assessments. * Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams. * Brief executives and government leadership on significant incidents, operational trends, and emerging threats. * Support proposal development, oral presentations, staffing, and transition planning. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)