> Markdown version of [/jobs/ext/3040058-incident-detection-response-manager-soc-manager](https://www.wearedevelopers.com/jobs/ext/3040058-incident-detection-response-manager-soc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Detection/Response Manager (SOC Manager) - **Company:** ECS Corporate Services, LLC - **Location:** Fairfax, VA, United States - **Experience:** Experienced - **Salary:** $140,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Static Program Analysis, Cyber Security, Computer Telephony Integration, Information Technology Operations, Intrusion Detection and Prevention, Log Analysis, Networking Basics, Cloud Services, Security Information and Event Management, Traffic Analysis, Mitre Att&ck, Malware, Information Technology, Cybercrime, Security Orchestration, Automation & Response - **Published:** September 23, 2026 - **Apply:** https://www.jofdav.com/jobs/59834953-incident-detection-response-manager-soc-manager ## About the Role * 8+ years of IT experience, with 4+ years of dedicated incident response and SOC operations experience. * Remote but within close proximity to the NCR. * Active Public Trust 6c clearance, or the ability to obtain and maintain one. * At least one of the following certifications: GCIH, GCFA, GREM, or equivalent. * Hands-on experience with SIEM, SOAR, EDR, CDM, and malware analysis tools and platforms. * Strong experience with operating systems and networking fundamentals, including log analysis, traffic analysis, and endpoint forensics. * Experience with AWS native services and tools in a federal or enterprise cloud environment. * Demonstrated experience managing a SOC overseeing complex, large-scale federal or enterprise IT systems. * Strong command of incident response frameworks including NIST SP 800-61, SANS PICERL, and MITRE ATT&CK. * Practical malware analysis fundamentals, including static analysis, sandboxing, and Indicator of Compromise (IoC) extraction. * Experience with SOAR platforms to automate repetitive elements of incident response and improve analyst efficiency. * Proven ability to translate complex technical findings into clear, actionable language for both technical and executive audiences. * Strong written and verbal communication skills, with a track record of producing high-quality federal security documentation. ## Description Everforth ECS is seeking an Incident Detection/Response Manager (SOC Manager) who lives in close proximity to the National Capital Region (NCR) to join a premier, enterprise-scale cybersecurity program supporting a major federal civilian agency. Please Note: This position is contingent upon contract award. Salary Range: $140,000 - $160,000 This flagship initiative unifies 24x7x365 Security Operations (SOC), proactive threat hunting, and advanced Security Engineering and Architecture into a cohesive defensive mission. As a key leader on this program, you will drive the protection of highly sensitive, national-level financial, and personally identifiable information (PII). You will be at the forefront of modernizing the agency's cyber posture, implementing advanced automation, and ensuring continuous operational resilience across a massive, highly complex federal IT enterprise. As the Incident Detection/Response Manager, you will serve as the operational commander of a high-performing, around-the-clock Security Operations Center supporting a major federal civilian agency. You will direct Tier I, II, and III incident response operations, ensuring rapid detection, containment, and recovery across a large-scale federal IT enterprise. Working closely with threat hunting teams, security engineers, agency stakeholders, and external service providers, you will lead the SOC's day-to-day operations while driving continuous improvement in detection capabilities, response procedures, and overall security posture. When incidents occur, you become the incident commander, orchestrating response from the moment a threat is detected through containment, eradication, and recovery., * Manage SOC daily activities, including building and maintaining shift schedules and ensuring all documentation, including SOPs, Playbooks, and CONOPS, are current. * Manage Tier I, II, and III incident response operations across the federal enterprise, ensuring consistent, high-quality response at every level. * Coordinate containment, eradication, and recovery activities during active security incidents, serving as the primary incident commander and coordinating between the SOC team, IT operations, and relevant stakeholders. * Lead post-incident reviews and root cause analysis to identify lessons learned and drive continuous improvement in SOC processes and detection capabilities. * Ensure compliance with NIST SP 800-61 and federal incident response standard operating procedures across all SOC operations. * Manage SIEM event "notables" dashboards, ensuring timely triage, escalation, and resolution of security alerts. * Maintain the SOC coverage schedule per shift to ensure 24x7x365 operational readiness. * Maintain the call tree, including current contact information for all partner organizations and Cloud Service Providers (CSPs). * Apply MITRE ATT&CK framework to map attacker tactics, techniques, and procedures (TTPs) during investigations and incident response activities. * Encourage team collaboration by fostering a positive team culture, managing workloads effectively, and supporting professional development. * Collaborate with threat hunting, CTI, engineering, and architecture teams to ensure SOC operations are informed by the latest threat intelligence and detection capabilities. * Present incident findings, risk recommendations, and SOC performance metrics to both technical teams and senior government officials in a clear, actionable format. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)