Haystack
← Back to Jobs
Remote
Technology
SS

SOC LEAD

Spear StaffingUnited States🇺🇸United StatesPosted 15 Sept 2026

Why This Role Stands Out

This remote SOC Lead role offers significant growth opportunities within a reputable company, allowing you to develop advanced cybersecurity skills while leading a team. You'll thrive here if you are a proactive and experienced cybersecurity professional eager to make a substantial impact. Apply now to advance your career in a flexible, supportive environment.

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
Swift

Job Description

 

Position Title: SOC Team Lead ( 3rd Shift)

Location: Remote

Duration:12+months

Interview: video

 

Location Information  

Remote –  3rd shift (12:00 AM–9:00 AM CST)

 

Position Responsibilities:

As a SOC Team Lead, you will play a pivotal role in building operational excellence within a dynamic Security Operations Center. You will manage and mentor a team of analysts, ensuring clear, consistent, and high-quality execution of security monitoring, investigation, detection engineering, incident response, and cross-team coordination. Your leadership will advance the SOC's maturity in detection fidelity, threat hunting, documentation, and escalation readiness.

This is a hands-on leadership role, balancing day-to-day operational focus with process ownership, analyst development, and quality improvements under time-sensitive and high-stakes circumstances. You will be responsible for end-to-end execution, including shift scheduling, escalation protocols, investigation quality, and continual process improvements across your assigned shift.

 

Essential Skills, Experience

·        Team Leadership & People Management: Directly manage, coach, and develop SOC analysts; providing mentorship, fostering performance improvement, and guiding career development.

·        Shift Operations & Escalation Readiness: Own shift scheduling, coverage, escalation protocols, and investigation quality for your assigned hours, ensuring consistent service delivery and incident triage.

·        Operational Excellence: Oversee day-to-day SOC execution, including monitoring queue health, ensuring investigation consistency and documentation, and driving escalation discipline.

·        Process Improvement: Identify workflow inefficiencies, streamline response procedures, and implement measurable improvements across tools, documentation, automation, and analyst routines.

·        Detection Engineering: Define detection priorities from threat intelligence and incident data, manage tuning across SIEM, SOAR, EDR, and log analytics platforms, and strengthen alert fidelity while reducing false positives.

·        Incident Response Governance: Govern incident identification, escalation, and documentation in alignment with incident management procedures; ensure all findings are defensibly documented and artifacts are properly managed.

·        Cross-Functional Coordination: Maintain clear coordination with internal functions such as GRC, IAM, Infrastructure, Cloud, AppSec, and Vulnerability Management, ensuring swift and well-documented handoffs and actionable remediation guidance.

·        Communication & Documentation: Deliver clear, audit-ready documentation of investigations and incidents; provide accurate operational context to support policy, leadership, and audit discussions.

Success in this role will mean:

·        Your team operates efficiently with minimal friction, conducts thorough investigations, and consistently produces high-quality documentation.

·        Detection content and system tuning are prioritized and managed for optimum fidelity and reduced alert fatigue.

·        Incident response is handled, documented, and escalated in accordance with established procedures, standing up to audit scrutiny.

·        Collaboration between SOC and other technical or risk teams is clear and effective, supporting rapid remediation and continuous maturation of the security posture.

·        The SOC improves in speed, accountability, and consistency over time as threat and response requirements evolve.

Qualifications:

·        5+ years in SOC operations, detection engineering, threat hunting, incident response, or related operational security roles, including at least 2 years in a team lead, senior analyst, or coordination function.

·        Demonstrated ability to balance robust security practices with business context in a risk-managed environment.

·        Hands-on knowledge of incident response, SOC operations, detection engineering, and threat intelligence processes.

·        Experience leading workflow improvements, analyst development, and operational or technical enhancements.

·        Strong communication skills and a commitment to thorough, consistent, and audit-ready documentation of SOC activities.

·        Bachelor’s degree in computer science, cybersecurity, or a related discipline, or equivalent experience and professional certifications.

·        Preferred: Experience developing or owning SOC SOPs, SLAs, incident governance, or operating in compliance/audited environments; proficiency in cross-team coordination and ownership models.

 

 

Similar jobs