Leidos seeks a SOC Lead to guide a high-performing cyber operations team protecting critical government and commercial environments. In this role, you'll own end-to-end security monitoring, incident response, and threat detection, leveraging advanced SIEM, EDR, and analytics tools. You'll mentor analysts, refine playbooks, and drive continuous improvement in detection and response. At Leidos, you'll join a mission-driven, collaborative culture focused on integrity, innovation, and real-world impact, with robust benefits, flexible work options, and strong support for ongoing professional growth.
Responsibilities
- Lead day-to-day Security Operations Center (SOC) activities and analyst team performance
- Monitor, analyze, and respond to security events, incidents, and alerts across complex environments
- Develop, tune, and maintain SIEM rules, playbooks, and detection content to improve threat coverage
- Coordinate incident response, containment, and remediation with internal teams and external stakeholders
- Create and maintain SOC procedures, runbooks, and documentation aligned to best practices
- Provide technical guidance, mentoring, and training to SOC analysts and junior engineers
- Collaborate with engineering and architecture teams to enhance security controls and tool integrations
- Produce metrics, reports, and briefings for leadership on SOC performance and threat trends
Required Skills
- Security Operations Center management
- Security incident response
- SIEM configuration and tuning
- EDR tools and management
- Threat detection and hunting
- Security monitoring and analysis
- Playbook and runbook development
- Network security fundamentals
- Log analysis and correlation
- Cybersecurity frameworks (NIST, ISO 27001)