Virginia Tax is seeking a dedicated Security Operations Team Lead based in Richmond, VA, to oversee and enhance our critical cyber defense capabilities. In this role, you will lead and mentor a team of security analysts responsible for monitoring, detecting, and responding to threats against systems and data essential to the Commonwealth’s mission. The Security Operations Team Lead is responsible for guiding a team of security analysts in protecting the organization’s systems, data, and infrastructure. This role provides leadership, develops team processes and playbooks, refines security posture, and ensures effective response to cyber threats. The ideal candidate will bring strong technical expertise, proven incident response capabilities, and experience working across multiple teams and technologies. The ideal candidate brings not only strong technical and leadership skills, but also a forward-looking mindset that helps Virginia Tax continue progressing as a cybersecurity leader within the Commonwealth of Virginia. About the Role As the Security Operations Team Lead, you will be part of a mission driven cybersecurity team dedicated to protecting the agency's systems and data. You will demonstrate strong leadership and deep technical expertise while supervising and developing Security Analysts responsible for frontline monitoring and incident response, you will: Lead daily security monitoring and incident response activities, ensuring threats are identified, analyzed, prioritized, and remediated in alignment with agency standards. Provide hands-on leadership by guiding analysts through investigations, escalations, containment actions, and coordinated response efforts. Prioritize and tune SIEM alerts, refine detection logic, and reconcile daily monitoring results to maintain a robust and accurate security posture. Oversee log ingestion health and data integrity across Splunk and other monitoring platforms, validating sources, diagnosing ingestion issues, and coordinating with system owners to restore visibility. Leverage AI-assisted security analytics tools to enhance threat detection accuracy, reduce false positives, and accelerate triage within the SOC environment. Evaluate and implement AI-driven automation to improve alert correlation, anomaly detection, and incident enrichment while ensuring compliance with agency security standards. Oversee CyberArk Privileged Access Management (PAM) operations, including least privilege enforcement, credential rotation, privileged account monitoring, and secure onboarding of service accounts. Manage CyberArk or BeyondTrust Endpoint Privilege Management (EPM) processes, including elevation rule design, policy tuning, auditing, and balancing security controls with user productivity. Support cloud security operations through services such as CloudTrail and Security Hub, ensuring effective detection of misconfigurations, anomalies, and unauthorized activity. Collaborate with system administrators, application teams, cloud teams, and third-party vendors to integrate security controls, strengthen infrastructure, and ensure secure system configurations. Develop, maintain, and improve security playbooks, workflows, and procedures to ensure consistency, readiness, and alignment with frameworks such as SEC 530, NIST, CIS Controls, and MITRE ATT&CK. Drive continuous improvement through integration of threat intelligence, periodic security posture assessments, and enhancement of detection and response capabilities across the SOC.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed