> Markdown version of [/jobs/ext/2219671-manager-security-operations-centre-soc](https://www.wearedevelopers.com/jobs/ext/2219671-manager-security-operations-centre-soc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Security Operations Centre (SOC) - **Company:** Blueprint School Network, Inc. - **Location:** Fairview, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), .NET Framework, PHP (Programming Language), Microsoft Windows, Antivirus Softwares, Apple Mac Systems, Software System Penetration Testing, Unix, C++ (Programming Language), CompTIA Security+, Cyber Security, Information Leak Prevention, Digital Forensics, Perl (Programming Language), Event Logging, Intrusion Detection and Prevention, Python (Programming Language), Kali Linux, Microsoft Security Essentials, Network Intrusion Detection Systems, Network Monitoring, Packet Analyzer, Network Protocols, Nmap, Ruby, Web Application Security, Security Information and Event Management, Snort (Software), Transport Layer Security, Network Access Control, Computer Network Operations, Information Technology, Metasploit, IDA Pro, Landesk, Nessus, Malware Detection, Vulnerability Analysis, Programming Languages - **Published:** August 25, 2026 - **Apply:** https://bluevoyant.applytojob.com/apply/jsL4QddnQd/Manager-Security-Operations-Centre-SOC?source=GS ## About the Role * Experience working within a global organization, partnering with distributed teams across multiple regions and time zones * Prior experience managing managers or team leads, with direct accountability for team performance and development * Ability to handle high-pressure situations in a productive and professional manner * Ability to work directly with customers to understand requirements for and feedback on security services, including managing escalations to protect client relationships * Advanced written and verbal communication skills, with the ability to present complex technical topics in clear and easy-to-understand language * Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distributed team * Able and willing to work in a 24/7/365 environment Technical Expertise: * Knowledge of and experience with the Microsoft Security Stack (Defender, Sentinel etc) * Knowledge of and experience with intrusion detection/prevention systems and SIEM software * Advanced knowledge and understanding of network protocols and devices * Advanced experience with Mac OS, Windows, and Unix systems * Ability to analyze event logs and recognize signs of cyber intrusions/attacks * Strong knowledge of: SIEM, Packet Analysis, SSL Decryption, Malware Detection, HIDS/NIDS, Network Monitoring Tools, Case Management System, Knowledge Base, Web Security Gateway, Email Security, Data Loss Prevention, Anti-Virus, Network Access Control, Encryption, and Vulnerability Identification Nice to Have: * Experience partnering with or managing teams based in the Philippines * Experience in network/host vulnerability analysis, intrusion analysis, digital forensics, penetration testing, or related areas * 8+ years of hands-on SOC/TOC/NOC experience * Certifications such as GCIA, GCIH, GCFA, GCFE, CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, or MCSE * Familiarity with tools such as IDA Pro, PEiD, PEview, Procmon, Snort, Bro, Kali Linux, Metasploit, NMAP, and Nessus * Familiarity with GPO, Landesk, or other IT infrastructure tools * Understanding of and/or experience with one or more programming languages: .NET, PHP, Perl, Python, Java, Ruby, C, C++ Education: Bachelor's degree in Information Security, Computer Science, or another technology / engineering-related field preferred. Candidates with proven experience in security/network operations will also be considered., Are you able and willing to commute to the College Park, MD office 2-3 days per week?* Do you have prior experience managing managers or Team Leads, with direct accountability for their performance and development? Have you led a team of 40+ employees, such as within a Security Operations Center, NOC, or similar 24/7 technical environment?* Do you have experience managing customer escalations, with a focus on client retention?* Do you have knowledge of and experience with intrusion detection/prevention systems and SIEM software?* Are you able and willing to work in a 24/7/365 environment (including outside standard business hours as needed)?* Do you have experience partnering with distributed teams across multiple regions and time zones? ## Description BlueVoyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of roughly 60 employees, playing a critical role in protecting client relationships and driving retention. This is a client-facing leadership role responsible for shaping how customers experience the SOC - from escalation handling through the metrics and reporting that inform leadership decisions. The role carries strong potential for growth into a higher-level leadership position as the team and business scale, making it a great fit for an ambitious leader who wants to build and shape a growing organization. What You'll Do: * Lead, develop, and manage a team of Team Leads, Trainers, and Security Analysts, providing strategic direction, coaching, and performance management * Assume full responsibility and accountability for ensuring all SOC customers receive world-class service * Own the management of customer escalations, with the primary goal of client retention, partnering closely with Client Success on remediation plans and client communication * Provide oversight and management of Team Leads and the wider Analyst team, ensuring consistent quality and performance across the SOC * Lead post-incident review meetings to capture lessons learned following the resolution of critical events * Ensure key Security Operations actions incorporate relevant customer impact considerations by engaging key stakeholders and communicating known/suspected implications of technical decisions * Validate that Security Operations activities adequately address customer requirements across all MSS services * Oversee operations in deterring, identifying, monitoring, investigating, and analyzing network intrusions * Supervise complex event investigation and incident declaration, ensuring events are properly identified, analyzed, and escalated to incidents * Ensure the team's incident investigation, handling, response, and documentation meet quality and SLA standards * Assist in the advancement of security policies, procedures, and automation * Develop incident response reporting and policy updates as needed * Partner cross-functionally with Client Success, Content Engineering, Threat Hunt, and Product leadership to drive service improvements and represent the SOC's priorities * Develop and maintain SOC performance metrics, delivering regular reporting on team performance, incident trends, and customer outcomes to leadership * Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure continued business as usual * Maintain a strong awareness of the current threat landscape ## Related Videos - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Coffee with Developers - Robby Russell](https://www.wearedevelopers.com/videos/917-coffee-with-developers-robby-russell) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)