1

Dod Soc Operations Lead Jobs (NOW HIRING)

SOC Lead

Alexandria, VA · On-site

$131K - $237K/yr

Leidos has a current job opportunity for a Security Operations Center (SOC) Lead on the DISA GSM-O ... DoD 8140 Program Manager (801) Intermediate compliance required upon start (includes: SecurityX ...

SOC Lead

Alexandria, VA · On-site

$131K - $237K/yr

Leidos has a current job opportunity for a Security Operations Center (SOC) Lead on the DISA GSM-O ... DoD 8140 Program Manager (801) Intermediate compliance required upon start (includes: SecurityX ...

SOC Lead

Alexandria, VA · On-site

$131K - $237K/yr

Leidos has a current job opportunity for a Security Operations Center (SOC) Lead on the DISA GSM-O ... DoD 8140 Cyber Defense Analyst (511) Intermediate requirements required upon start. * Advanced ...

SOC Lead

Alexandria, VA · On-site

$131K - $237K/yr

Description Leidos has a current job opportunity for a Security Operations Center (SOC) Lead on the ... DoD 8140 Program Manager (801) Intermediate compliance required upon start (includes: SecurityX ...

SOC Operations Manager Location: Washington, DC, Ft. Collins, CO, or Kansas City, MO (remote ... Lead the Tier 2 Threat Watch Officer function; serve as the senior operational authority for event ...

next page

Showing results 1-20

Dod Soc Operations Lead information

See salary details

$12

$27

$64

How much do dod soc operations lead jobs pay per hour?

As of Sep 11, 2026, the average hourly pay for dod soc operations lead in the United States is $27.95, according to ZipRecruiter salary data. Most workers in this role earn between $18.27 and $31.01 per hour, depending on experience, location, and employer.

What is a DoD SOC Operations Lead?

DoD SOC Operations Leads are professionals responsible for managing and overseeing the day-to-day operations of Security Operations Centers (SOCs) within the U.S. Department of Defense (DoD). They coordinate cybersecurity monitoring, incident response, and threat analysis activities to protect DoD networks and systems. These leads supervise SOC analysts, ensure the implementation of security protocols, and maintain compliance with federal security standards. Their role is crucial in swiftly detecting and mitigating cyber threats to safeguard national security.

What are the key skills and qualifications needed to thrive as a DoD SOC Operations Lead?

To thrive as a DoD SOC Operations Lead, you need expertise in cybersecurity operations, incident response, and a comprehensive understanding of security frameworks, often supported by a bachelor’s degree in IT or cybersecurity and certifications like CISSP or Security+. Proficiency with SIEM tools (such as Splunk or ArcSight), intrusion detection systems, and DoD-specific security platforms is typically required. Leadership, strong communication, and decision-making skills are essential for coordinating teams and managing high-pressure security incidents. These skills ensure effective threat detection, incident management, and mission-critical protection of Department of Defense information systems.

How does a DoD SOC Operations Lead typically collaborate with other teams to ensure effective threat response?

As a DoD SOC Operations Lead, you will regularly coordinate with incident response teams, IT departments, and external stakeholders to streamline communication during security events. Collaboration often involves leading cross-functional meetings, sharing intelligence on emerging threats, and ensuring that playbooks and response protocols are up-to-date. Strong interpersonal and leadership skills are crucial, as you’ll be responsible for aligning SOC activities with broader organizational security strategies and ensuring rapid, unified responses to incidents.

What are popular job titles related to Dod Soc Operations Lead jobs?

For Dod Soc Operations Lead jobs, the most frequently searched job titles are:

Infographic showing various Dod Soc Operations Lead job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 11% Part Time, and 1% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $58,139 per year, or $28 per hour.

AOUSC - SOC Operations Lead / Managed Detection & Response (MDR) Lead

Washington, DC • On-site

cFocus Software Incorporated
51 - 200 employees

Full-time

Re-posted 28 days ago


Job description

Position Title
SOC Operations Lead / Managed Detection & Response (MDR) Lead
Position Overview
The SOC Operations Lead will oversee 24x7x365 Security Operations Center (SOC) and Managed Detection & Response (MDR) operations supporting a large federal enterprise environment. The Lead will direct SOC analysts, incident responders, and MDR personnel responsible for security monitoring, alert triage, incident analysis, escalation, containment coordination, reporting, and continuous operational improvement.
The ideal candidate possesses deep experience leading enterprise SOC operations supporting federal agencies, including SIEM operations, endpoint detection and response (EDR), cloud security monitoring, incident coordination, and executive cyber reporting.
Key Responsibilities
  • Lead enterprise SOC and MDR operations supporting on-premises and cloud environments.
  • Oversee 24x7 monitoring, detection, triage, and escalation activities.
  • Direct operational workflows for:
    • SIEM monitoring,
    • alert management,
    • incident coordination,
    • case management,
    • and operational reporting.
  • Manage analyst teams supporting:
    • Splunk,
    • Microsoft Sentinel,
    • CrowdStrike,
    • Sysmon,
    • Windows event logging,
    • and cloud telemetry platforms.
  • Develop and maintain SOC SOPs, playbooks, runbooks, escalation matrices, and reporting procedures.
  • Lead operational metrics reporting including:
    • MTTD,
    • MTTR,
    • false positive rates,
    • automation effectiveness,
    • analyst productivity,
    • and incident impact assessments.
  • Coordinate closely with Threat Hunting, CTI, Detection Engineering, and Incident Response teams.
  • Brief executives and government leadership on significant incidents, operational trends, and emerging threats.
  • Support proposal development, oral presentations, staffing, and transition planning.
Required Qualifications
  • 10+ years of cybersecurity operations experience.
  • 5+ years leading enterprise SOC or MDR environments.
  • Experience supporting federal civilian or DoD environments.
  • Experience managing large-scale SOC operations in environments exceeding:
    • 10,000+ users,
    • enterprise cloud environments,
    • and large SIEM deployments.
  • Experience with:
    • Splunk Enterprise Security,
    • Microsoft Sentinel,
    • CrowdStrike,
    • EDR/XDR platforms,
    • SOAR technologies,
    • and cloud security monitoring.
  • Deep understanding of:
    • MITRE ATT&CK,
    • incident response,
    • detection engineering,
    • and threat-informed defense.
  • Strong executive briefing and oral presentation skills.
Preferred Certifications
  • CISSP
  • GCIA
  • GCIH
  • GMON
  • GSOC
  • Splunk Architect/Admin certifications
  • Microsoft Security certifications