SOC Operations Team Lead
Job Description
DMI is a leading global provider of digital services working at the intersection of public and private sectors. With broad capabilities across IT managed services, cybersecurity, cloud migration and application development, DMI provides on-site and remote support to clients within governments, healthcare, financial services, transportation, manufacturing, and other critical infrastructure sectors. DMI has grown to over 2,100+ employees globally and has been continually recognized as a Top Workplace in both regional and national categories.
About the Opportunity
DMI, LLC is seeking a SOC (Security Operations Center) Operations Team Lead for a State government customer.
Duties and Responsibilities:
- Supervise SOC analysts ensuring they are prepared for each shift.
- Track tickets through the operations/lifecycle from creation, escalation, closure, root cause, and when necessary, after-action reporting.
- Manage SOC ticket backlog by coordinating with other organizations and state agencies when tickets are escalated/transferred outside the SOC.
- In conjunction with the State SOC Manager, coordinate analysts leave/attendance to ensure sufficient staffing for all shifts.
- Participate in incident response and escalation to ensure that there is timely identification of critical issues.
- Monitor/approve timesheets in company timekeeping system.
- Monitor SOC analysts' performance and conduct personnel reviews for DMI staff. Provide performance feedback on non-DMI employees.
- Participate in SOC analyst interviews as vacancies occur.
- Contribute to the development and maintenance of SOC Standard Operating Procedures (SOPs) and other work documents.
- Participate in post-incident activities and contribute to lessons learned to improve security operations.
- Provide sound technical recommendations that enable remediation of security issues.
- Partner with security engineering to develop and refine SOC monitoring tools.
- Utilize advanced threat models, SIEM use cases, and incident response playbooks.
Qualifications
Education and Years of Experience:
- Bachelor's degree and 10-12 years' experience.
- 3-5 years' experience as a Team Leader or Manager.
- 3-5 years' experience as a SOC or Operations Center analyst
Required:
- Experience working independently to resolve complex issues.
- CompTIA CySA+ certification/ or a CompTIA Security+ (or other relevant IAT Level II/III Certification) along with one of the following:
- CEH
- CFR
- CCNA Cyber Ops
- GCIA
- GCIH
- GICSP
- Cloud+
- SCYBER
- PenTest+
- Team player capable of productively contributing to the client mission by supporting fellow teammates in a dynamic growing and changing environment.
- Capable of working independently, establishing priorities, and managing task completion within set SLAs.
- Able to communicate effectively through writing, speaking, and presenting to client technical representatives.
Desired:
- Experience analyzing intrusion events such phishing emails, malware, privileges misuse, traffic indicating potential malicious activities such DoS/DDoS, brute force, data loss through exfiltration/ inadvertent disclosure.
- Applied experience of threat analysis model/frameworks such Cyber Kill Chain, MITRE ATT&CK, Diamond Model, Pyramid of Pain etc.
- Working knowledge of advanced threat Tactics, Techniques and Procedures (TTPs).
- Applied experience with a variety of Opensource threat research tools/platforms such as Virus Total
- Working knowledge of network and security architecture principles such as zero trust or defense-in-depth
- Experience with proprietary security protection/detections tools such as Firewall, Host and Network IDS/IPS, Anti-Virus, EDR, URL Filtering Gateways, Email Filtering Gateways, DLP tools, and SIEM tools such as Splunk etc.
Min Citizenship Status Required: US Citizen
Physical Requirements: No Physical requirement needed for this position
Location: Crownsville, MD
Working at DMI
DMI is a diverse, prosperous, and rewarding place to work. Being part of the DMI family means we care about your wellbeing. As such, we offer a variety of perks and benefits that help meet various interests and needs, while still having the opportunity to work directly with a number of our award-winning, Fortune 1000 clients. The following categories make up your DMI wellbeing:
- Community - Blood drives, volunteering opportunities, Holiday parties, summer picnics, Tech Chef, Octoberfest just to name a few ways DMI comes together as a community
- Convenience/Concierge - Virtual visits through health insurance, pet insurance, commuter benefits, discount tickets for movies, travel, and many other items to provide convenience
- Development - Annual performance management, continuing education, and tuition assistance, internal job opportunities along with career enrichment and advancement to help each employee with their professional and personal development
- Financial - Generous 401k match for both pre-tax and post-tax (ROTH) contributions along with financial wellness education, EAP, Life Insurance and Disability help provide financial stability for each DMI employee
- Recognition - Great achievements do not go unnoticed by DMI through Annual Awards ceremony, service anniversaries, peer-to-peer acknowledgment through Spotlight, employee referral
- Wellness - Healthcare benefits, Wellness programs provide employees with several wellness options
Employees are valued for their talents and contributions. We all take pride in helping our customers achieve their goals, which in turn contributes to the overall success of the company. The company does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans, and to treat qualified individuals without discrimination based on their physical or mental disability or veteran status. DMI is an Equal Opportunity Employer Minority/Female/Veterans/Disability. DMI maintains a drug-free workplace.
No Agencies Please
Applicants selected may be subject to a government security investigation and must meet eligibility requirements for access to classified information. US citizenship may be required for some positions.
Date Posted
10/09/2023
Views
1
Similar Jobs
Team Lead, Expansion Account Executive - Personio
Views in the last 30 days - 0
Personio a human resources platform is seeking a Team Lead Expansion Account Executive with 5 years of experience in B2B software sales The role invol...
View DetailsSenior Lead, Talent Acquisition - Sales (Relocation to Munich) (d/f/m) - Personio
Views in the last 30 days - 0
Personio a leading HR platform is seeking a Senior Lead Talent Acquisition professional to drive growth in the Revenue and Success functions across Eu...
View DetailsOperations Functional Support Specialist - Dynamics 365 Finance & Operations (IN) - Cencora
Views in the last 30 days - 0
Cencora is seeking a Functional Support Specialist with 25 years of experience in Microsoft Dynamics 365 Finance Operations particularly in Operation...
View DetailsLead Data Analyst - Mitigation - WISE
Views in the last 30 days - 0
Wise is a global technology company seeking an Operations Analyst with 4 years of experience in analytics particularly in operational team analytics T...
View DetailsLead Technical Support Engineer - HERE Technologies
Views in the last 30 days - 0
This role Senior Technical Support Engineer at HERE Technologies involves supporting a diverse portfolio of products and services acting as a technica...
View DetailsPrincipal / Lead Software Engineer- RUST (Algorithmic and Mathematics) - m/w/d - HERE Technologies
Views in the last 30 days - 0
HERE Technologies is seeking a Principal Software Engineer to lead the development of extended services for their VRP solver Tour Planning The role in...
View Details