Security Operations Center (SOC) Manager

Gunnison Consulting Group Inc
Washington, DC, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$160,000.0 - $175,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Cyber Security Intrusion Detection and Prevention Linux System Administration Security Information and Event Management Malware Information Technology Splunk

Job description

  • Provide leadership and oversight for 24x7x365 Security Operations Center activities supporting a federal customer
  • Direct all phases of incident response, including triage, investigation, containment, remediation, recovery, and post-incident reviews
  • Ensure adherence to incident response procedures, SOC playbooks, and escalation protocols
  • Oversee alert monitoring and triage operations using approved security platforms and enterprise tools
  • Enforce response timelines and service level agreements for alert handling and escalation
  • Lead coordination and communication during high-severity cybersecurity incidents
  • Supervise SOC analysts, incident responders, and forensic personnel, ensuring appropriate staffing and performance
  • Review and validate incident reports, forensic findings, malware analyses, and post-incident documentation
  • Coordinate with federal customer stakeholders on operational risks, incident status, and threat landscape updates
  • Ensure accurate documentation of incidents, timelines, and communications within authorized systems
  • Track and report on operational metrics such as MTTA, MTTT, containment timelines, and remediation efficiency
  • Conduct regular briefings to provide updates on incidents, trends, risks, and operational performance
  • Maintain awareness of the overall security posture and operational status through development of a common operational picture
  • Support forensic and malware analysis activities, including evidence handling and root cause investigations
  • Ensure compliance with NIST SP 800-53, NIST SP 800-61, NIST CSF, and ITIL v4 practices
  • Lead continuous improvement efforts to enhance SOC processes, workflows, and detection capabilities
  • Support onboarding, transition, and knowledge transfer activities
  • Deliver executive and technical presentations to stakeholders

Requirements

Do you have experience in Windows?, Do you have a Bachelor’s degree?, * Bachelor’s degree in Computer Science, Information Technology, or related field

  • Minimum of 7 years of experience in incident response, including at least 2 years providing technical leadership for SOC operations supporting large enterprise environments
  • At least 2 years implementing incident response processes within a federal environment aligned to NIST CSWP-29 (Cybersecurity Framework) and NIST SP 800-61
  • Minimum of 2 years of experience using Splunk SIEM for alert correlation and analysis
  • At least 3 years of experience performing system-level auditing and cybersecurity analysis across Windows and Linux environments
  • Strong technical writing and reporting capabilities for both technical and executive audiences
  • Certification required: GCIH or GCIA

Clearance Requirement: Ability to obtain and maintain a Public Trust.

The salary range for this position depends upon multiple factors including location, the individual’s knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements.

Benefits & conditions

1 Columbus Circle NE, Washington, DC 20002 Hybrid work $160,000 - $175,000 a year - Full-time, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance
  • Disability insurance
  • Profit sharing
  • Paid holidays, Salary: $160,000 - $175,000/year, Gunnison Consulting Group’s total compensation package also includes bonus and profit-sharing opportunities, depending on company and employee performance. Available employee benefits include:
  • 3 weeks of Personal Leave your first year
  • 11 paid Holidays each year
  • 5 days of Flexible Time Off each year
  • 401(k) company match at 50% up to 10% of your salary
  • Medical, Dental and Vision Insurance
  • Life and Disability Insurance
  • Public Transportation Subsidies
  • Certifications and Training Allowance - Up to $5,000/year!

About the company

Why Join Gunnison?

  • Gunnison takes on ambitious projects. We target fun, challenging work that requires creative thinking and innovation.
  • Quality is our top priority.
  • Gunnison employee benefits meet or exceed what other companies in the Washington, D.C. metropolitan area offer.
  • There is a great sense of camaraderie at Gunnison. This is an atmosphere we will maintain as we continue to grow.
  • We are growing rapidly and the opportunity for individual professional growth with Gunnison is outstanding.
  • We hire for careers at Gunnison, not to fill a position.

Equal Opportunity Employer. Must be eligible for employment in the United States. We are unable to sponsor candidates at this time.

In 1994 Gunnison began serving the greater Washington, D.C. metro area, focused on tackling our customers’ most ambitious technology projects. By creating a culture dedicated to enabling our customers and employees to achieve more than they ever thought they could, the company has thrived for over 25 years.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Boosting security operations center productivity with intelligent data analysis

Chris Wysopal Chris Wysopal +2 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all