SOC Operations Architect / Senior SOC Lead - SOCOL 26-12208
Job Description
Job DescriptionSOC Operations Architect / Senior SOC Lead
Department: Information Security / Cyber Fusion Center
Assignment Term: Full-Time, up to 180 days
Schedule: Monday – Friday, 8:00 AM – 5:00 PM Pacific Time
Work Location: 100% Remote or Hybrid
Candidate Location: California
Interview: Zoom
Equipment: Laptop and required system access will be provided
Background Check: Required prior to start
Position Overview
We are seeking a Senior SOC Operations Architect / Senior SOC Lead to support the launch preparation and implementation of a systemwide security operations capability.
The selected candidate will translate the security operations model into practical SOC workflows, runbooks, escalation paths, detection requirements, and pilot-readiness activities. This individual will also provide technical and operational expertise throughout vendor implementation by reviewing proposed designs and processes, identifying gaps, clarifying responsibilities, and helping ensure the resulting security operations service can be effectively operated and sustained.
The ideal candidate will bring strong experience in SOC operations, security architecture, incident response, detection engineering, SIEM/MDR/MSSP environments, and security operations program implementation.
Key Responsibilities
- Develop and refine SOC workflows covering monitoring, detection, alert triage, investigation support, escalation, and organizational handoffs.
- Review vendor operating processes, technical designs, integrations, workflows, and implementation assumptions.
- Identify technical and operational gaps, unclear ownership, responsibility concerns, and implementation risks.
- Determine whether specific requirements should be addressed by the security operations provider, internal security teams, individual business units, or other dependencies.
- Validate monitoring use cases, detection rules, alert quality, reporting, and operational metrics.
- Review baseline telemetry from identity, endpoint, firewall, VPN, IDS/IPS, and other relevant security sources.
- Create and maintain SOC runbooks, severity classifications, escalation logic, and incident coordination procedures.
- Support pilot readiness through workflow testing, tabletop exercises, scenario validation, issue tracking, and identification of operational gaps.
- Coordinate with security leadership, vendor teams, security operations teams, and project stakeholders regarding response ownership, escalation expectations, handoffs, and feedback loops.
- Review and validate vendor deliverables to ensure alignment with operational requirements and security objectives.
- Assist with establishing repeatable processes that support the long-term operation and maturity of the SOC.
- Provide technical guidance on security monitoring, detection, incident coordination, and operational integration.
Required Qualifications
- Senior-level experience in security operations, SOC operations, incident response, detection engineering, security architecture, or a related cybersecurity operations role.
- Strong technical knowledge of SOC architecture and service integration, including:
- Security telemetry flows
- SIEM and security platform integration
- Identity correlation
- Access models
- Alert lifecycles
- ITSM integration
- Experience overseeing or working with MSSP, MDR, SOC, SIEM, or cybersecurity vendors.
- Demonstrated experience reviewing vendor designs and deliverables, challenging technical assumptions, clarifying responsibility boundaries, and identifying service or implementation gaps.
- Experience establishing, transitioning, implementing, or maturing security operations capabilities.
- Hands-on experience developing or operating SOC workflows, including:
- Alert triage
- Escalation
- Investigation
- Incident handoff
- Response coordination
- Strong understanding of incident severity models, escalation criteria, detection use cases, and security operations metrics.
- Experience creating runbooks, procedures, playbooks, workflow diagrams, and other operational documentation.
- Experience working with security technologies and telemetry sources such as:
- SIEM
- EDR
- Identity platforms
- Firewalls
- VPN
- IDS/IPS
- Strong written and verbal communication skills with the ability to collaborate effectively with technical teams, vendors, operational teams, and leadership stakeholders.
- Strong analytical, problem-solving, documentation, and organizational skills.
Preferred Qualifications
- Experience working in higher education, public-sector, federated, or other multi-entity environments.
- Experience supporting systemwide or enterprise-scale SOC implementations.
- Experience with security operations transformation, vendor transitions, or SOC service launches.
- Experience conducting tabletop exercises, pilot validation, and operational readiness assessments.
