The SOC/NOC Operations Manager shall be responsible for oversight and management of integrated 24x7x365 Security Operations Center (SOC) and Network Operations Center (NOC) monitoring operations supporting enterprise cybersecurity and operational monitoring requirements. The role shall oversee operational workflows, escalation procedures, staffing coverage, shift coordination, event handling consistency, operational reporting, and incident response readiness activities.
The SOC and NOC monitoring functions shall operate as a fully integrated operational model and may include management of remotely staffed teams. The SOC/NOC Operations Manager shall also oversee threat hunting activities, annual tabletop exercise (TTX) planning and execution, and maintenance of standard operating procedures (SOPs), operational playbooks, and knowledge base documentation.
Minimum Qualifications
CISSP (Certified Information Systems Security Professional)
And/or relevant incident response or security operations certifications such as:
GCIA
GCIH
GSOM
CISM
Equivalent SOC leadership certification
Required Experience
- Demonstrated experience managing 24x7x365 SOC operations within federal or comparable enterprise environments
- Experience supporting integrated SOC/NOC operational models
- Experience overseeing Splunk SIEM operations, including monitoring, alert management, and triage workflows
- Experience managing shift-based analyst teams with multiple analysts per shift
- Demonstrated experience supporting incident response lifecycle management and escalation procedures
- Experience conducting or overseeing cybersecurity tabletop exercises (TTX)
- Experience developing and maintaining SOPs, operational playbooks, and knowledge base documentation
Preferred Qualifications
- Minimum of five (5) years managing federal SOC operations
- Hands-on experience with Splunk Enterprise Security administration oversight
- Experience integrating Microsoft Defender XDR with Splunk
- Experience managing enterprise threat hunting programs
- Familiarity with CISA Incident Response Playbooks
- Familiarity with OMB M-21-31 and OMB M-22-01 requirements
- GSOM, CISM, or similar advanced SOC management certification in addition to CISSP