About the role
cFocus Software seeks a SOC Lead to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance. Qualifications: * Active TS/SCI clearance * B.S. Computer Science, Information Technology, or a related field * Experience leading SOC personnel or comparable defensive cybersecurity operations. * Experience directing alert triage, threat hunting, investigations, and incident response. * Ability to manage operational priorities, analyst development, coverage, and handoffs. * Knowledge of networks, endpoints, cloud environments, logs, and common cyberattack techniques. * Experience with security monitoring, endpoint detection, vulnerability tools, and detection tuning. * Ability to coordinate remediation and response across operations, engineering, and cybersecurity teams. * Understanding of evidence handling, secure configurations, compliance records, and operational risk. * Strong judgment and communication skills for timely Government reporting and incident coordination
Duties: * Lead SOC analysts and assigned response personnel; prioritize work, coach staff, review investigations, and maintain clear accountability for operational actions. * Plan assigned staffing, coverage, on-call rotations, and handoffs to support required on-site and global response capabilities. * Support SOC stand-up planning, tool configuration, sensor integration with command and control (C2) nodes, and enterprise scanning readiness. * Coordinate centralized defensive operations, including monitoring, penetration testing support, threat hunting, cyber orders and taskers, and incident response. * Oversee alert triage and analysis of security events and trends; validate findings, assess mission impact, and direct approved mitigation actions. * Lead data and intelligence-driven threat hunting and anomaly investigations across DC3 information technology (IT) and operational technology (OT) environments. * Direct incident detection, investigation, escalation, and approved containment, eradication, and recovery; keep Government stakeholders informed under established procedures. * Review investigation evidence, incident timelines, and reports for accuracy and completeness; ensure response actions and handoffs are documented. * Coordinate weekly vulnerability assessments with certified specialists; prioritize findings and track remediation with infrastructure, application, and cybersecurity teams. * Maintain effective C2 coordination with Cybersecurity Service Providers (CSSPs), the AFCYBER Operations Center, and applicable higher headquarters authorities. * Manage assigned cyber orders and taskers, coordinate implementation, and support required compliance documentation and Plans of Action and Milestones (POA&Ms). * Assess SOC tools, telemetry coverage, and resource needs; recommend procurement and operational improvements through approved Government processes. * Maintain incident response procedures, escalation guides, and operational documentation; incorporate lessons learned and submit required updates for Government approval. * Coordinate with ISSOs and the ISSM to provide monitoring evidence and remediation status supporting RMF, authorization, and enterprise risk activities. * Recommend improvements based on emerging threats, cybersecurity practices, and technologies, including benefits, risks, and implementation approaches.