SOC Manager (Hands-On) - Remote (USA)

ECHELON RISK, LLC
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services ARM Architecture Build Automation Microsoft Azure Microsoft Online Services Software as a Service Cloud Computing Cyber Security Query Languages Identity and Access Management Intrusion Detection and Prevention
+31 more
Intrusion Detection Systems Python (Programming Language) Network Security Pcap Log Analysis Microsoft Security Essentials Microsoft Office Network Protocols Windows PowerShell Phishing Kusto Query Language Security Information and Event Management Software Vulnerability Management EndPointSecurity Scripting Google Cloud Office365 Mitre Att&ck Mttr QRadar Azure Security Center Falcon Platform Cybercrime Microsoft Sentinel Cortex XSOAR Platform CIS Benchmarks Splunk SentinelOne Expertise Qualys Security Orchestration, Automation & Response Vulnerability Analysis

Job description

In this role, you will provide leadership and mentorship to SOC analysts while remaining actively involved in day-to-day security operations, detection engineering, threat hunting, incident response, and continuous improvement initiatives. You will serve as a technical escalation point for complex security incidents, help define SOC processes and best practices, and work closely with clients to strengthen their security posture., + Establish and refine SOC processes (tiering, shift coverage, escalation paths, QA, SLAs/OLAs).

  • Drive runbook discipline, training plans, and continuous improvement for service quality. Own SOC KPIs (MTTD/MTTR, detection efficacy, false-positive rate, case aging, CSAT/NPS).
  • Detection & response (hands-on): *

  • Build and tune detections in SIEM/XDR; develop correlation rules, parsers, and dashboards.
  • Lead investigations and major incidents end-to-end; conduct post-incident reviews and reporting. Perform proactive threat hunting aligned to MITRE ATT&CK and emerging TTPs.
  • Tooling & platform engineering: *

  • Deploy, integrate, and operate EDR/MDR (CrowdStrike, SentinelOne, Blackpoint), Microsoft 365/Windows Defender, SIEM, SOAR, email security, vulnerability scanners, and NSM tools.
  • Engineer log onboarding/normalization across cloud (AWS, Azure, M365, GCP), network, endpoint, identity, and SaaS sources. Build automation/orchestration playbooks to reduce MTTD/MTTR and analyst toil.
  • Service delivery & client engagement: *

  • Serve as technical point of contact for customers; present posture reviews and improvement plans.
  • Define and meet service SLAs; contribute to SOWs, service catalogs, and onboarding playbooks.
  • Coordinate with customer IT/CISO teams, vendors, and legal/compliance during incidents.

  • Risk, compliance & continuous improvement: *

  • Map detections, controls, and reporting to frameworks/standards (NIST CSF/800-53, CIS Controls, SOC 2, ISO 27001).
  • Drive vulnerability and exposure management with risk-based prioritization.
  • Run tabletop exercises, purple-team activities, and lessons learned., + EDR/XDR/MDR: CrowdStrike, SentinelOne, Blackpoint, Microsoft Defender for Endpoint, Cortex XDR, etc.
  • Microsoft ecosystem: Microsoft 365, Windows Defender / Defender for Endpoint, Defender for Office 365, Azure security telemetry (KQL, Log Analytics, Sentinel).
  • SIEM: Splunk, Microsoft Sentinel, Elastic, QRadar, Exabeam, or similar.
  • SOAR: Splunk SOAR, Cortex XSOAR, Sentinel automation.
  • Email security & awareness: Mimecast, KnowBe4, Material Security, M365 Defender for Office 365.
  • Vulnerability management: Tenable, Qualys, or Rapid7.
  • NSM/IDS: Zeek, Suricata, commercial IDS/IPS.
  • IR leadership: Proven track record leading medium/major incidents (ransomware, BEC, insider, cloud credential abuse).
  • Cloud: Experience securing and monitoring AWS/Azure/GCP and M365 (identity and endpoint telemetry).
  • Process: Built or matured playbooks, runbooks, use-case catalogs, and service reporting. Demonstrated KPI/OKR management.

Requirements

Do you have experience in Team leadership?, Do you have a Bachelor’s degree?, As the SOC Manager, you will lead and mature our Security Operations Center (SOC) capabilities within our MSSP practice. This is a player-coach role that combines technical leadership, operational oversight, and hands-on security operations. The ideal candidate brings 7-10 years of MSSP experience, including at least 5 years working directly within a SOC environment, along with a strong security engineering background across EDR/MDR, SIEM, Microsoft 365 Security, Crowdstrike and Email Security., Deep knowledge of SOC operations (triage, incident lifecycle, evidence handling, documentation).

  • Strong grasp of Windows/*nix/AD/M365, identity security (SSO/MFA), network protocols, and cloud telemetry.
  • Expertise in detection engineering and query languages (SPL, KQL, Elastic DSL, AQL).
  • Familiarity with adversary emulation and frameworks (MITRE ATT&CK, D3FEND, CIS Controls).
  • Understanding of email security (phishing, BEC), vulnerability scanning/patching, and network security monitoring (IDS/IPS, PCAP).
  • Proficiency with SOAR concepts and playbook design (enrichment, containment, ticketing).
  • Scripting/automation (PowerShell, Python, or equivalent) for enrichment, triage, and response.
  • Clear written/verbal communication for executive briefings and technical reports.
  • Applicants must have authorization to work in the United States without current or future visa sponsorship

Specific Qualifications:

  • Experience: 7-10 years in MSSP settings; 5+ years on a SOC team; 2-4+ years in a lead/technical lead capacity., * Certifications (nice to have): CISSP, GIAC (GCIA/GCIH/GCFA/GCDA/GMON), OSCP, Azure/Microsoft security (SC-200/SC-100), Splunk, CrowdStrike CCFR/CCFA, or similar.
  • Availability: Able to participate in escalation/on-call rotation and support off-hours incidents as needed.
  • Education: BS in CS/Cybersecurity or equivalent experience (experience > degree where applicable)

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Vision insurance
  • Health savings account
  • Dental insurance
  • Flexible spending account
  • Life insurance, We are committed to creating an inclusive environment for our team with unquestioned integrity. If you have a special need that requires accommodation, please let your recruiter know. One of our core values in “People with Personality” and we want to allow you the space to bring your full self to work.

We currently offer the following benefits:

  • Access to medical, dental, and vision insurance through Cigna, with the majority of the employee cost covered by the employer
  • Employer funding to HSA accounts and FSA access
  • Access to a 401(k) through Vanguard with a guaranteed employer contribution
  • Flexible vacation policy that allows you to manage your schedule and rest and recharge when you need to.
  • 11 holidays with flexibility based on what is important for you and those you love
  • Employer-paid short-term and long-term disability, employer-paid life insurance, and access to additional life insurance, hospital coverage, accidental coverage, discounted mental health support, and more
  • Support for individual development through certifications, continued learning, conferences, and more

About the company

About us: At Echelon Risk + Cyber, we believe in defending fundamental human rights to security and privacy. We are seeking a highly skilled and hands-on SOC Manager to join our dynamic team at Echelon Risk + Cyber, a leading cybersecurity consulting firm. Our next team member will be ready to roll up their sleeves, identify opportunities for our clients and for Echelon internally, and operate with unquestioned integrity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

4:01 min

Implementing the barbell strategy and focusing on recovery time

Jan de Vries Jan de Vries · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all