Haystack
← Back to Jobs
Other
IN

SOC Operations Architect

InfojiniLong Beach, CA🇺🇸United StatesPosted Sep 16, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Long Beach, CA, United States
Posted
19 hours ago
Triage

Job Description

Job Description: 
•    The selected resource will support the launch preparation and implementation of systemwide security operations capability. 
•    This person will help translate the Cyber Fusion Center’s security operations model into practical SOC workflows, runbooks, escalation paths, detection requirements, and pilot-readiness activities. 
•    The resource will also provide CFC-side technical and operational expertise during vendor implementation by reviewing proposed designs and processes, identifying gaps, clarifying responsibilities, and helping ensure the resulting service can be operated and sustained effectively.
 
Key Responsibilities:
•    Develop and refine SOC workflows covering monitoring, detection, alert triage, investigation support, escalation, and campus handoff.
•    Review vendor operating processes, technical designs, integrations, workflows, and implementation assumptions.
•    Identify technical or operational gaps, unclear ownership, responsibility concerns, and implementation risks.
•    Help determine whether requirements should be addressed by the vendor, the CFC, individual campuses, or another CSU dependency.
•    Validate monitoring use cases, detection rules, alert quality, reporting, and operational metrics.
•    Review baseline telemetry from identity, endpoint, firewall, VPN, IDS/IPS, and related security sources.
•    Create and update SOC runbooks, severity mapping, escalation logic, and incident coordination procedures.
•    Support pilot readiness through workflow testing, tabletop exercises, scenario validation, issue tracking, and identification of operational gaps.
•    Coordinate with CFC leadership, vendor staff, campus security teams, and project partners on response ownership, escalation expectations, handoffs, and feedback loops.
 
Required Qualifications:
•    Senior-level experience in security operations, SOC operations, incident response, detection engineering, security architecture, or a related cybersecurity operations role.
•    Strong technical knowledge of SOC architecture and service integration, including telemetry flows, SIEM and platform integration, identity correlation, access models, alert lifecycles, and ITSM integration.
•    Experience overseeing MSSP, MDR, SOC, SIEM, or cybersecurity vendors.
•    Experience reviewing vendor designs and deliverables, challenging assumptions, clarifying responsibility boundaries, and identifying service or implementation gaps.
•    Experience in establishing, transitioning, or maturing security operations capabilities.
•    Hands-on experience developing or operating SOC workflows, including alert triage, escalation, investigation, incident handoff, and response coordination.
•    Strong knowledge of incident severity models, escalation criteria, detection use cases, and security operations metrics.
•    Experience creating runbooks, procedures, playbooks, workflow diagrams, or similar operational documentation.
•    Experience with SIEM, EDR, identity, firewalls, VPN, IDS/IPS, and related security telemetry sources.
•    Strong documentation and communication skills, with the ability to work effectively with technical teams, vendors, campuses, and leadership stakeholders.
•    Experience in higher education, public-sector, federated, or other multi-entity environments is preferred but not required.

 

Similar jobs