Cyber Ops Lead | SOC Lead
Programmers.io
ROLE_DESCRIPTION
5+ years of experience in a Security Operations Center or similar cyber defense role, including at least 1-2 years in a lead, senior analyst, or shift-lead capacity
Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
Working knowledge of SIEM, EDR, and case/ticket management tooling"
ESSENTIAL_SKILLS
- 5+ years of experience in a Security Operations Center or similar cyber defense role, including at least 1-2 years in a lead, senior analyst, or shift-lead capacity
- Demonstrated experience managing case/ticket queues and driving them to resolution in a fast-paced environment.
- Working knowledge of SIEM, EDR, and case/ticket management tooling
- Solid understanding of incident response fundamentals (triage, containment, escalation).
- Comfortable working cross-functionally with Technology Operations, IT, and Engineering teams.
- Strong written and verbal communication skills; able to translate technical detail for varied audiences.
- Willingness and ability to work on-site in Draper, UT, including participation in on-call/shift coverage as needed.
SKILLS_REQUIRED
Case & Queue Management
Own the SOC case queue: triage incoming alerts, tickets, and requests; assign priority and ownership; track cases through to resolution.
Maintain SLAs for case handling and escalation; identify and clear bottlenecks before they become backlogs.
Ensure consistent documentation, categorization, and closure quality across all cases.
SOC Leadership & Operations
Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
Coordinate shift coverage and on-call rotations to maintain continuous monitoring.
Serve as a senior escalation point for analysts on complex or ambiguous cases.
Drive continuous improvement Of detection content, playbooks, and standard operating procedures.
Partnering with Technology Operations
Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
Coordinate response and remediation activities that require Tech Operations involvement, ensuring clear handoffs and shared visibility into status.
Participate in change management and operational reviews where security input is needed.
Incident Response
Support incident response efforts, including initial triage, containment recommendations, and coordination across teams during active incidents.
Contribute to post-incident reviews and help translate lessons learned into process or tooling improvements.
Mentorship & Team Development
Mentor and provide day-to-day guidance to SOC analysts; support onboarding and skills development.
Help set expectations for case quality, communication, and escalation practices.
Reporting & Metrics
Track and report on SOC operational metrics (case volume, time-to-triage, time-to-resolution, escalation rates) to the Director, Cyber Defense & Strategy.
Flag trends or recurring issues that indicate a need for process, tooling, or staffing changes.
- ...Cyber Ops Lead I SOC Lead Draper, UT Hire Type: Fulltime 120K/annum + benefits Experience in a regulated industry (healthcare, financial services, or similar) handling sensitive data. Relevant certifications such as GCIH, GCIA, Security+, CySA+,...SuggestedFull timeShift work
- ...high-quality security data capabilities that strengthen the organization's resilience against evolving threats. Key Responsibilities Lead the implementation, configuration, and administration of enterprise logging and monitoring platforms, including Splunk, Elastic...Suggested
- ...alignment with regulatory requirements and industry best practices. Lead risk assessments, vulnerability management, and security... ...including annual tabletop exercises. Stay abreast of evolving cyber threats, regulatory changes, and technological advancements to proactively...SuggestedWork at office
- ...subjects into easy-to-understand material with a focus on visual aids. Maintain relevant cybersecurity knowledge and collaborate with cyber threat intel and incident response partners for understanding and inclusion of real and emerging threats as part of delivering...SuggestedTemporary workH1bWork at officeWork from homeFlexible hours3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Ops Lead | SOC Lead. Be the first to apply!



