1

Security Operations Center Lead Jobs (NOW HIRING)

Security Operations Center Operator

Kennett Square, PA · On-site

$17.50 - $21.50/hr

Security Operations Center Operator Shift: Day shift (7 AM-3 PM or 8 AM-4 PM) Schedule: 8-hour rotating shifts with 2 days off per week; must work weekends and major holidays (Thanksgiving, Christmas ...

The Security Operations Center (SOC) Level 1 Operator is a CCTV, alarm monitoring, and dispatch specialist. The Level 1 Operator will monitor several screens observing cameras, monitor access control ...

$20 - $24.75/hr

Description The Security Operations Center (SOC) is responsible for monitoring, assessing, and responding to security events within a 24/7 Security Operations Center environment. This role supports ...

Everforth ECS is seeking a Security Operations Center Analyst to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax . Please Note: This position is contingent upon ...

We are seeking a curious and driven Junior SOC Analyst to join our 24/7 Security Operations Center team. In this entry-level role, you will serve as the first line of defense monitoring security ...

next page

Showing results 1-20

Security Operations Center Lead information

See salary details

$28K

$67.7K

$162K

How much do security operations center lead jobs pay per year?

As of Jun 6, 2026, the average yearly pay for security operations center lead in the United States is $67,675.00, according to ZipRecruiter salary data. Most workers in this role earn between $43,000.00 and $81,500.00 per year, depending on experience, location, and employer.

What is the difference between Security Operations Center Lead vs Security Analyst?

AspectSecurity Operations Center LeadSecurity Analyst
CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, GIAC Security Essentials
Work EnvironmentLead team, coordinate incident response, oversee security operationsMonitor security alerts, analyze threats, implement security measures
Employer & Industry UsageSecurity teams in various industries, often in managerial contextsSecurity teams, IT departments across industries

The Security Operations Center Lead typically oversees security teams, manages incident response, and coordinates security efforts, requiring leadership skills and certifications like CISSP. In contrast, a Security Analyst focuses on monitoring security alerts, analyzing threats, and implementing security measures. Both roles are essential in cybersecurity but differ mainly in responsibility level and scope.

What are the key skills and qualifications needed to thrive as a Security Operations Center Lead, and why are they important?

To thrive as a Security Operations Center (SOC) Lead, you need a deep understanding of cybersecurity principles, incident response, and threat analysis, typically supported by a degree in information security or related field and relevant certifications like CISSP or CISM. Familiarity with SIEM platforms, intrusion detection/prevention systems, and other security monitoring tools is essential. Leadership, strong problem-solving, and effective communication skills help you guide teams and coordinate responses under pressure. These competencies ensure robust security monitoring, timely incident mitigation, and cohesive team performance in protecting organizational assets.

What are some common challenges faced by a Security Operations Center (SOC) Lead, and how can they be managed effectively?

A Security Operations Center Lead often faces challenges such as managing a high volume of security alerts, coordinating incident response across teams, and ensuring continuous coverage for 24/7 operations. Effective communication, setting clear escalation procedures, and prioritizing alerts based on risk are key strategies for addressing these issues. Additionally, ongoing training and fostering a collaborative team environment help maintain a high level of preparedness and morale, enabling the SOC to respond efficiently to security threats.

What does a Security Operations Center (SOC) Lead do?

A Security Operations Center (SOC) Lead oversees the day-to-day operations of a team responsible for monitoring, detecting, and responding to cybersecurity threats within an organization. They coordinate incident response efforts, manage SOC analysts, and ensure that security protocols and tools are effective and up-to-date. Additionally, a SOC Lead often collaborates with other IT and security teams, provides training, and helps develop strategies to improve the organization’s overall security posture.
More about Security Operations Center Lead jobs
What cities are hiring for Security Operations Center Lead jobs? Cities with the most Security Operations Center Lead job openings:

Security Operations Center Analyst

ArdentMC

Manhattan, NY • Remote

Full-time

Medical, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Overview At Ardent , we hire people who want more than a job — they want to serve a mission that matters. Our teams support the federal government's most critical national security and defense priorities, helping protect the nation, strengthen resilience, and advance the technologies and capabilities that keep America secure. For veterans, cleared professionals, and purpose-driven innovators, Ardent is a place to continue serving alongside a team that understands the importance of the mission and the people behind it.

We also know top talent has choices, which is why we back our mission with benefits and flexibility that stand out: competitive pay, comprehensive health coverage, flexible PTO, federal holidays off, tuition reimbursement, professional development support, wellness stipends, and a culture that values and rewards hard work, dedication, and adaptability. If you want to build something meaningful, while enjoying the kind of flexibility and support that you need to do your best work — Ardent is where your next mission begins. Ardent is seeking a Security Operations Center (SOC) Analyst to join our team.

This is a remote position . Position Description Ardent is seeking a Security Operations Center (SOC) Analyst to support 24x7 security monitoring, alert triage, and incident response activities across enterprise environments. This role combines Tier I and Tier II responsibilities, including initial alert validation, advanced investigation, and coordination of incident response efforts to ensure timely detection, analysis, and remediation of security threats.

Responsibilities and Duties Monitor security alerts and events in a 24x7 SOC environment. Perform initial triage and validation of alerts to determine severity and impact. Conduct advanced alert investigation and analyze security events across identity, endpoint, and network telemetry.

Handle Tier I escalation workflows and support Tier II incident response activities. Coordinate incident containment efforts and escalate complex incidents to Tier III as needed. Monitor log ingestion pipelines and ensure data sources are functioning properly.

Document incidents, findings, and response actions in accordance with SOC procedures. Contribute to daily reporting and provide accurate shift handoff documentation. Identify trends, anomalies, and potential threats through continuous monitoring and analysis.

Collaborate with cross-functional teams to support incident resolution and improve detection capabilities. Requirements Bachelor's degree in Cybersecurity, Information Technology, or a related field, or equivalent work experience. Minimum of 4 years of experience in a Security Operations Center (SOC) or cybersecurity operations role.

Experience with security monitoring tools, SIEM platforms, and incident response processes. Strong understanding of alert triage, escalation procedures, and incident handling workflows. Experience analyzing logs, alerts, and telemetry from identity, endpoint, and network systems.

Ability to work in a 24x7 operational environment, including shift-based coverage. Must hold at least one of the following certifications or equivalent: GCIA, GCIH, CISSP, CEH, or similar cybersecurity certification. Preferred Qualifications Experience with Microsoft Sentinel or Microsoft security platforms.

Relevant cloud security certifications (e.g., AWS security). Familiarity with log ingestion pipelines and monitoring data health. Privacy certifications such as CIPP/US or CIPM.

Experience supporting federal or regulated environments. Equal Opportunity Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran\'s status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.

#J-18808-Ljbffr