SOC Manager

Cherokee FederalWashington, DC

About The Position

The SOC Manager is an experienced cybersecurity operations leader with a strong technical background in network-security monitoring, incident detection, investigation, response, and threat analysis. This position manages SOC personnel and daily operations while coordinating closely with ISSOs, incident-response teams, system owners, and infrastructure teams.

Requirements

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field.
  • Minimum of 8 years of relevant cybersecurity experience.
  • CISSP, GCIA, or equivalent advanced cybersecurity or intrusion-analysis certification.
  • Active Top Secret (TS) security clearance is required. Candidates must possess the required clearance to be considered for this position.
  • U.S. citizenship required.
  • Must be available during required Department of State core hours and for mission-critical incidents.
  • Must pass pre-employment qualifications of Cherokee Federal.

Nice To Haves

  • Federal SOC or Department of State cybersecurity experience preferred.
  • Experience with Splunk, Microsoft Sentinel, Elastic, QRadar, or comparable SIEM platforms preferred.
  • Experience with EDR, IDS/IPS, packet analysis, malware analysis, threat hunting, and digital forensics preferred.
  • Familiarity with NIST incident-response guidance, MITRE ATT&CK, CISA reporting requirements, and federal continuous monitoring preferred.
  • Experience coordinating with ISSOs, Security Control Assessors, system owners, cloud teams, and vulnerability-management teams preferred.
  • Equivalent certifications may include GCIH, GCED, GMON, GCFA, GSLC, CASP+/SecurityX, or other advanced incident-response, intrusion-analysis, or security-operations certifications, subject to customer approval.

Responsibilities

  • Manage a Security Operations Center or lead enterprise cybersecurity operations.
  • Supervise SOC analysts, incident responders, threat hunters, and security engineers.
  • Lead security monitoring, alert triage, escalation, investigation, containment, and incident reporting.
  • Develop SOC procedures, playbooks, escalation paths, metrics, and operational reports.
  • Monitor indicators of compromise and coordinate incident response across technical teams.
  • Perform network traffic analysis, intrusion analysis, log analysis, and threat detection.
  • Work with SIEM, endpoint detection and response, network detection, IDS/IPS, and threat-intelligence platforms.
  • Coordinate vulnerability and incident data with ISSOs for risk assessments, POA&Ms, SSP updates, and continuous monitoring.
  • Brief leadership on active threats, incidents, operational risks, and remediation status.
  • Support 24x7 operational continuity, shift coverage, and incident escalation as required.
  • Perform other job-related duties as assigned.

Benefits

  • Medical
  • Dental
  • Vision
  • 401K
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service