> Markdown version of [/jobs/ext/472116-security-operations-center-soc-manager](https://www.wearedevelopers.com/jobs/ext/472116-security-operations-center-soc-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Operations Center (SOC) Manager - **Company:** Gunnison Consulting Group Inc - **Location:** Washington, DC, United States - **Experience:** Experienced - **Salary:** $160,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Intrusion Detection and Prevention, Linux System Administration, Security Information and Event Management, Malware, Information Technology, Splunk - **Published:** June 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=34c40a74970ede03 ## About the Role Do you have experience in Windows?, Do you have a Bachelor's degree?, * Bachelor's degree in Computer Science, Information Technology, or related field * Minimum of 7 years of experience in incident response, including at least 2 years providing technical leadership for SOC operations supporting large enterprise environments * At least 2 years implementing incident response processes within a federal environment aligned to NIST CSWP-29 (Cybersecurity Framework) and NIST SP 800-61 * Minimum of 2 years of experience using Splunk SIEM for alert correlation and analysis * At least 3 years of experience performing system-level auditing and cybersecurity analysis across Windows and Linux environments * Strong technical writing and reporting capabilities for both technical and executive audiences * Certification required: GCIH or GCIA Clearance Requirement: Ability to obtain and maintain a Public Trust. The salary range for this position depends upon multiple factors including location, the individual's knowledge, skills, competencies, and experience, and contract-specific budget constraints and organizational requirements. ## Description * Provide leadership and oversight for 24x7x365 Security Operations Center activities supporting a federal customer * Direct all phases of incident response, including triage, investigation, containment, remediation, recovery, and post-incident reviews * Ensure adherence to incident response procedures, SOC playbooks, and escalation protocols * Oversee alert monitoring and triage operations using approved security platforms and enterprise tools * Enforce response timelines and service level agreements for alert handling and escalation * Lead coordination and communication during high-severity cybersecurity incidents * Supervise SOC analysts, incident responders, and forensic personnel, ensuring appropriate staffing and performance * Review and validate incident reports, forensic findings, malware analyses, and post-incident documentation * Coordinate with federal customer stakeholders on operational risks, incident status, and threat landscape updates * Ensure accurate documentation of incidents, timelines, and communications within authorized systems * Track and report on operational metrics such as MTTA, MTTT, containment timelines, and remediation efficiency * Conduct regular briefings to provide updates on incidents, trends, risks, and operational performance * Maintain awareness of the overall security posture and operational status through development of a common operational picture * Support forensic and malware analysis activities, including evidence handling and root cause investigations * Ensure compliance with NIST SP 800-53, NIST SP 800-61, NIST CSF, and ITIL v4 practices * Lead continuous improvement efforts to enhance SOC processes, workflows, and detection capabilities * Support onboarding, transition, and knowledge transfer activities * Deliver executive and technical presentations to stakeholders ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)