About this opportunity
Openkyber, LLC lists this SOC Architect opportunity in workfromhome, Georgia. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Position Title: SOC Team Lead ( 3rd Shift) Location: Remote Duration:12+months Interview: video Location Information Remote 3rd shift (12:00 AM 9:00 AM CST) Position Responsibilities: As a SOC Team Lead, you will play a pivotal role in building operational excellence within a dynamic Security Operations Center. You will manage and mentor a team of analysts, ensuring clear, consistent, and high-quality execution of security monitoring, investigation, detection engineering, incident response, and cross-team coordination. Your leadership will advance the SOC's maturity in detection fidelity, threat hunting, documentation, and escalation readiness. This is a hands-on leadership role, balancing day-to-day operational focus with process ownership, analyst development, and quality improvements under time-sensitive and high-stakes circumstances. You will be responsible for end-to-end execution, including shift scheduling, escalation protocols, investigation quality, and continual process improvements across your assigned shift.
Team Leadership & People Management: Directly manage, coach, and develop SOC analysts; providing mentorship, fostering performance improvement, and guiding career development.
Shift Operations & Escalation Readiness: Own shift scheduling, coverage, escalation protocols, and investigation quality for your assigned hours, ensuring consistent service delivery and incident triage.
Operational Excellence: Oversee day-to-day SOC execution, including monitoring queue health, ensuring investigation consistency and documentation, and driving escalation discipline.
Process Improvement: Identify workflow inefficiencies, streamline response procedures, and implement measurable improvements across tools, documentation, automation, and analyst routines.
Detection Engineering: Define detection priorities from threat intelligence and incident data, manage tuning across SIEM, SOAR, EDR, and log analytics platforms, and strengthen alert fidelity while reducing false positives.
Incident Response Governance: Govern incident identification, escalation, and documentation in alignment with incident management procedures; ensure all findings are defensibly documented and artifacts are properly managed.
Cross-Functional Coordination: Maintain clear coordination with internal functions such as GRC, IAM, Infrastructure, Cloud, AppSec, and Vulnerability Management, ensuring swift and well-documented handoffs and actionable remediation guidance.
Communication & Documentation: Deliver clear, audit-ready documentation of investigations and incidents; provide accurate operational context to support policy, leadership, and audit discussions.
Success in this role will mean:
Your team operates efficiently with minimal friction, conducts thorough investigations, and consistently produces high-quality documentation.
Detection content and system tuning are prioritized and managed for optimum fidelity and reduced alert fatigue.
Incident response is handled, documented, and escalated in accordance with established procedures, standing up to audit scrutiny.
Collaboration between SOC and other technical or risk teams is clear and effective, supporting rapid remediation and continuous maturation of the security posture.
The SOC improves in speed, accountability, and consistency over time as threat and response requirements evolve.
Qualifications:
5+ years in SOC operations, detection engineering, threat hunting, incident response, or related operational security roles, including at least 2 years in a team lead, senior analyst, or coordination function.
Demonstrated ability to balance robust security practices with business context in a risk-managed environment.
Hands-on knowledge of incident response, SOC operations, detection engineering, and threat intelligence processes.
Experience leading workflow improvements, analyst development, and operational or technical enhancements.
Strong communication skills and a commitment to thorough, consistent, and audit-ready documentation of SOC activities.
Bachelor's degree in computer science, cybersecurity, or a related discipline, or equivalent experience and professional certifications.
Preferred: Experience developing or owning SOC SOPs, SLAs, incident governance, or operating in compliance/audited environments; proficiency in cross-team coordination and ownership models.
#J-18808-Ljbffr
Worksite address
workfromhome, GA, 30383, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.