Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Operations Center​/SOC Lead image - Rise Careers
Job details

Security Operations Center​/SOC Lead

Position: Security Operations Center (SOC) LeadLeidos has a current job opportunity for a Security Operations Center (SOC) Lead on the DISA GSM-O program in Alexandria, VA.POSITION SUMMARY:Through the J6 Penetration Handling, Incident, System Health (PHISH) support services task order on the GSM-O contract, we provide IT products, services and solutions to the Pentagon and other DoD offices and agencies for them to meet mission and business requirements. Our Cybersecurity team performs cyber defensive actions in support of J6 to prevent, detect, respond and recover from adversarial activities.The SOC consists of a variety of highly-skilled, technical staff performing cyber incident handling, fusion analysis, non-compliance reporting, user activity monitoring, and malware and forensic analysis. Furthermore, the SOC Lead coordinates 24x7 staffing to support mission-critical operations, including incident response, and manages surge support.PRIMARY RESPONSIBILITIES:• Plan, direct, and manage day-to-day activities across the Security Operations Center as well as high-tempo, high-visibility incident response, when required.• Ensure SOC personnel adhere to documented processes and procedures for triage, analysis, incident response, and reporting.• Drive implementation and adoption of new tools, capabilities, frameworks, and methodologies across all teams within the SOC.• Accountable for the timeliness and quality of reporting produced by the SOC.• Instill and reinforce industry best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and SOC operations.• Promote and drive implementation of automation and process efficiencies.BASIC QUALIFICATIONS:• Active TS/SCI security clearance required.• Bachelor's degree and 10+ years of prior cybersecurity experience. Additional work experience or Cyber courses/certifications may be substituted in lieu of degree.• 4+ years of supervising and/or managing teams.• 5+ years of intrusion detection and/or incident handling experience.• DoD 8570 IAT III and CSSP Incident Responder certifications required upon start.• Advanced knowledge in planning, directing, and managing Computer Incident Response Team (CIRT) and/or Security Operations Center (SOC) operations in an organization in a large, complex environment.• Significant experience supervising and leading employees of various labor categories and technical skill levels in efforts similar in size and scope as the JSP DCO mission.• Mature understanding of industry accepted standards for incident response actions and best practices related to SOC operations.• Strong written and verbal communication skills, and the ability to create technical reports based on analytical findings.• Strong analytical and troubleshooting skills.• Must be a US Citizen.PREFERRED QUALIFICATIONS:• Deep technical understanding of core current cybersecurity technologies as well as emerging capabilities.• Hands-on cybersecurity experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization including prior experience performing large-scale incident response.• Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and methods of exploitation with an understanding of intrusion set tactics, techniques and procedures (TTPs).• Familiarity or experience in Intelligence Driven Defense, Cyber Kill Chain methodology, and/or MITRE ATT&CK framework.Original Posting: April 16, 2025Pay Range: Pay Range $ - $The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.#J-18808-Ljbffr
Leidos Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Leidos DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Leidos
Leidos CEO photo
Tom Bell
Approve of CEO

Average salary estimate

Estimate provided by employer
$112500 / ANNUAL (est.)
min
max
$100K
$125K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Operations Center​/SOC Lead, Leidos

If you're a passionate cybersecurity expert looking to take your career to the next level, Leidos has an exciting opportunity for you as a Security Operations Center (SOC) Lead in Alexandria, VA. In this pivotal role, you'll be at the forefront of protecting vital systems for the Pentagon and other DoD offices. You’ll lead a dynamic team of skilled professionals dedicated to performing cyber incident handling, fusion analysis, and forensic analysis among other critical activities. Daily, you'll plan and manage the SOC's operations, ensuring that each team member adheres to documented processes for triage, analysis, and reporting. Your leadership will drive the implementation of new tools and methodologies that not only enhance our operational efficiency but also foster a culture of best practices in incident response. As the SOC Lead, you will coordinate 24/7 staffing and help steer high-visibility incident response efforts, making sure we're at our best when it matters most. You'll have the chance to promote automation and improve processes, ensuring our operations are not just reactive but proactively securing our landscapes. With your solid background in cybersecurity, alongside a TS/SCI clearance, you’ll be the guiding force in protecting against adversarial activities while cultivating a sharp, responsive, and resilient SOC team. Ready to make a difference in the field of cybersecurity with Leidos?

Frequently Asked Questions (FAQs) for Security Operations Center​/SOC Lead Role at Leidos
What are the key responsibilities of the Security Operations Center (SOC) Lead at Leidos?

The Security Operations Center (SOC) Lead at Leidos has an array of critical responsibilities, primarily focused on managing the day-to-day activities of the SOC, planning incident response efforts, and ensuring adherence to cybersecurity processes. This role entails driving the implementation of new tools and methodologies, overseeing staffing for 24/7 operations, and producing high-quality reporting related to cybersecurity incidents.

Join Rise to see the full answer
What qualifications are required for the SOC Lead position at Leidos?

To qualify for the SOC Lead position at Leidos, candidates must possess an active TS/SCI security clearance, a bachelor's degree, and over 10 years of prior cybersecurity experience. Additionally, a minimum of 4 years in a supervisory or management role and 5 years of intrusion detection or incident handling experience are required. Relevant certifications such as DoD 8570 IAT III and CSSP Incident Responder are mandatory.

Join Rise to see the full answer
What skills are necessary for a Security Operations Center (SOC) Lead at Leidos?

A successful SOC Lead at Leidos must exhibit strong leadership capabilities in managing diverse teams and be well-versed in incident response, cybersecurity analysis, and operational best practices. Essential skills include excellent written and verbal communication abilities, analytical thinking, and troubleshooting skills, alongside a deeper understanding of industry standards and cybersecurity technologies.

Join Rise to see the full answer
How does Leidos ensure the effectiveness of incident response in the SOC?

Leidos emphasizes the importance of adhering to documented processes and procedures for incident response within their Security Operations Center. The SOC Lead plays a vital role in instilling best practices and in implementing automation and process efficiencies, ensuring that the SOC is ready to detect, respond, and recover from cybersecurity threats effectively.

Join Rise to see the full answer
What makes the SOC Lead position at Leidos an appealing opportunity?

Working as a SOC Lead at Leidos is appealing due to the unique opportunity to lead a team responsible for national security. The role offers involvement in innovative cybersecurity practices, access to advanced technologies, and the chance to collaborate with top professionals in the field, all while executing missions that protect critical national infrastructure.

Join Rise to see the full answer
Common Interview Questions for Security Operations Center​/SOC Lead
What strategies would you implement to enhance the effectiveness of the Security Operations Center?

To enhance effectiveness, I would focus on automation of repetitive tasks, implementing thorough training programs for staff, and continuously evaluating the tools we use for incident detection and response. It's vital to adopt frameworks like the MITRE ATT&CK to guide our incident response strategies.

Join Rise to see the full answer
Can you describe your experience with incident response in previous roles?

Certainly! In my previous roles, I led incident response teams through various cybersecurity incidents, ensuring adherence to industry standards. I implemented structured processes for triage and analysis, which resulted in reduced response times and improved outcomes for our operational environment.

Join Rise to see the full answer
How do you manage stress in high-pressure situations typical of SOC operations?

I manage stress by staying organized and maintaining open communication with my team. Establishing a clear action plan beforehand means that when incidents occur, we can respond promptly without panic. Regular debriefs post-incident help in learning and improving future responses.

Join Rise to see the full answer
What is your approach to team management in the SOC environment?

My approach to team management involves fostering an environment of trust and accountability, where team members feel empowered to share insights and suggest improvements. Consistent feedback and recognition of individual achievements also play key roles in maintaining morale and motivation.

Join Rise to see the full answer
Explain the significance of compliance and reporting in SOC operations.

Compliance is critical in SOC operations as it ensures we adhere to legal and regulatory requirements, mitigating risks to the organization. Effective reporting not only documents incidents for accountability but also provides valuable insights for improving processes and strategies against future threats.

Join Rise to see the full answer
How do you stay current with evolving cybersecurity threats?

I stay current with evolving threats through continual education—subscribing to industry publications, joining webinars, and participating in cybersecurity forums and networks. Engaging with peers and thought leaders in the field also provides insights into trends and emerging threats.

Join Rise to see the full answer
Describe your experience with cybersecurity technologies and tools.

I have extensive experience with a variety of cybersecurity tools, including SIEM systems for real-time analytics, intrusion detection systems, and forensic tools for incident investigations. My hands-on experience has allowed me to select and implement the most effective technologies for our operational needs.

Join Rise to see the full answer
What steps would you take if a significant security breach occurred?

In the event of a significant breach, the first step would be to execute our incident response plan, ensuring all relevant personnel are notified. I would lead the team in gathering evidence, containing the breach, and conducting a full analysis to understand the root cause and impact, followed by reporting and remediating the vulnerabilities.

Join Rise to see the full answer
How would you implement process improvements within SOC operations?

To implement process improvements, I would first gather feedback from my team about current challenges. Using data from incidents, I would identify patterns or recurring issues, and then collaborate with team members to brainstorm solutions, testing and refining approaches to best meet our operational goals.

Join Rise to see the full answer
What do you consider the most important quality for a SOC Lead?

The most important quality for a SOC Lead is the ability to lead with a calm and focused demeanor in high-stress situations. This quality ensures that team members feel supported and instills confidence in our processes during critical incidents, enabling us to respond effectively.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 12 days ago

Leidos invites an experienced Kafka Cloud Architect to spearhead innovative data streaming solutions in Woodlawn, MD.

Photo of the Rise User
Leidos Hybrid Washington, District of Columbia, United States
Posted 7 days ago

Join Leidos as a System Administrator to ensure the security, stability, and performance of vital IT systems for a Federal Law Enforcement Agency.

Photo of the Rise User
Posted 9 days ago

Join Arcadia as a Technical Solutions Lead and drive impactful solutions in the healthcare technology sector.

Photo of the Rise User
Posted 13 days ago

Play a pivotal role in transforming digital visions into reality as a Cybersecurity Program Coordinator at Uni Systems.

Photo of the Rise User

Frederick Community College is looking for a Chief Information Officer to lead their IT division and drive transformation through education.

Utilize your extensive ServiceNow expertise to design and implement tailored IT solutions for a dynamic federal environment.

Photo of the Rise User

We are looking for a Help Desk Technician III to join Montgomery County’s IT team, providing essential support to various departments.

Photo of the Rise User
ServiceNow Remote 60 Dawson Street, Dublin, Ireland
Posted 12 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

As a Senior Problem Manager at ServiceNow, you'll play a critical role in identifying and resolving issues within our cloud platform while working closely with technical teams.

Photo of the Rise User
ServiceNow Remote Remote, West Palm Beach, Florida, United States
Posted 10 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity

As a Principal Solution Architect at ServiceNow, you will play a pivotal role in empowering organizations with innovative AI-enhanced Workflow solutions.

Photo of the Rise User

Join Minnesota State College and Universities as an Information Technology Specialist 4 to enhance their Workday Prism processes and data operations.

Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. At Leidos, our mission is to make the world safer, healthier, and mor...

405 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
April 22, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
6 people applied to DevOps Engineer 3 at Granicus
Photo of the Rise User
80 people applied to Cybersecurity Intern at Dewberry
Photo of the Rise User
Someone from OH, Alliance just viewed Store Representative - Mid-Shift at Serv-U-Success
Photo of the Rise User
Someone from OH, Eastlake just viewed (REMOTE) Account Executive at Trellis
Photo of the Rise User
12 people applied to Junior Security Engineer at Epic
Photo of the Rise User
Someone from OH, Elyria just viewed Security Officer - Factory Patrol at Allied Universal
C
14 people applied to ISSE/ ISSO at Centuria
Photo of the Rise User
Someone from OH, Cincinnati just viewed Staff Software Test Engineer, Platform at Clari
Photo of the Rise User
Someone from OH, Perrysburg just viewed Sourcing Leader, Minerals & Cullet at Owens Corning
Photo of the Rise User
Someone from OH, North Royalton just viewed Remote AI Voice Trainer (High-Quality Microphone Required) at Datadog
C
Someone from OH, Akron just viewed Phlebotomy Technician - Outpatient at CCF