Point your AI agent at freehire and let it find you a job.

Get the CLI →

ECS FEDERAL LLC

NewBe an early applicant

Security Operations Center (SOC) Manager

Posted Updated
Discussion

Everforth ECS is seeking a Security Operations Center (SOC) Manager to work in our Fairfax, VA office in a hybrid remote/on-site capacity.

Everforth ECS is seeking an experienced, outcome-driven Security Operations Center (SOC) Manager to work in our Fairfax, VA office in support of DoW environment U.S. Coalition Mission Partner Environments (MPE), each with a unique set of data and applications. The SOC Manager will oversee personnel responsible for 24x7x365 SOC services that provide proactive and real-time monitoring, detection, analysis, quantification, response, and reporting capabilities for cybersecurity events and incidents in accordance with Federal laws and regulations. These services include continuous cybersecurity monitoring of Enclave IT systems and assets; investigation of security alerts; incident triage; root cause analysis; and full-spectrum incident response activities – including containment, remediation, and recovery – to ensure complete system restoration. The SOC Manager will drive the Enclaves’ full recovery from cyber incidents and ensure adherence to Federal incident management and reporting requirements that are central to these security operations. The SOC Manager will report directly to the Defense & Intel Business Unit’s Platforms Solutions Division Vice President.

Primary Responsibilities:

  • Build, deploy, and maintain a comprehensive SOC program leveraging best practices and compliant with client standards and requirements.
  • Oversee the Secure Unclassified Network (SUNet) SOC and coordinate all SOC activities including Tier support.
  • Serve as the primary incident commander for all SOC cybersecurity incidents.
  • Support the development of SOC plans, policies, and standard operating procedures (SOP).
  • Act as the primary SOC liaison with external agencies, mission partners, and third-party vendors during joint investigations and coordinated incident response efforts.
  • Represent SOC capabilities and readiness during stakeholder meetings, program reviews, and federal oversight briefings.
  • Integrate cyber threat intelligence (CTI) into SOC detection engineering and incident triage workflows to improve fidelity and contextual relevance of alerts.
  • Define, track, and analyze SOC Key Performance Indicators (KPIs) – such as Mean Time to Detect (MTTD), Mean Time to Repair (MTTR), analyst utilization, and false positive rates – to ensure compliance with Service Level Agreements (SLA) and drive continuous improvement.
  • Develop dashboards and reporting mechanisms to communicate Key Performance Indicator (KPI) trends, SOC effectiveness, and incident lifecycle insights to executive stakeholders and customers.
  • Provide guidance on active Plans of Action and Milestones (POA&M).
  • Lead the implementation and continuous improvement of Security Orchestration, Automation, and Response (SOAR) capabilities by developing automated playbooks to streamline triage, enrichment, and containment workflows, while tracking effectiveness through automation coverage, time savings, and reduced analyst fatigue.
  • Manage project tracking schedules, risk registers, and risk and issue mitigation strategies for SOC and incident response activities.
  • Ensure quality and timeliness of SOC deliverables.
  • Provide hands-on guidance, training, mentoring, and support to junior staff.
  • Other duties, as assigned.

Salary: $190,000 - $225,000

General Description of Benefits

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available