Security Operations Center; SOC Team Lead
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Security Manager
Date:
Feb 20, 2026
Location:
AUSTIN, TX
Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more.
Explore more details on the Benefits of Working at HHS webpage.
Functional
Title:
Security Operations Center (SOC) Team Lead Job Title: Cybersecurity Analyst IV Agency: Health & Human Services Comm Department: CHIEF INFO SECURITY OFFICE Posting Number: 14089 Closing Date: 04/21/2026 Posting Audience: Internal and External Occupational Category: Computer and Mathematical Salary Range: $8,488.33 - $14,356.00 Pay Frequency: Monthly
Salary Group: TEXAS-B-29 Shift: Day Additional Shift: Days (First)
Telework
Travel: Regular Full Time/Part Time: Full time FLSA Exempt/Non-Exempt: Exempt
Facility
Location:
Job Location City: AUSTIN Job Location Address: 4601 W GUADALUPE ST Other Locations: MOS Codes: ,,,,,,,,8858,14N,14NX,170A 170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D 26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT CYB
10,CYB
11,CYB
12,CYB
13,CYB
14,IS,ISM,ISS,IT,ITS
Brief
Job Description:
This position is open to permanent residents or US citizens only.
Job Summary: The Security Operations Center (SOC) Team Lead is a critical leadership position responsible for the daily coordination, performance, and operational effectiveness of the Security Operations Center for the Texas Health and Human Services Commission (HHSC). This role provides tactical and operational oversight of security monitoring, incident response, and vulnerability management activities to ensure the confidentiality, integrity, and availability of HHSC information systems.
Essential Job Functions (EJFs)
- Leadership and Team Coordination:
Provide daily leadership, technical guidance, and mentorship to SOC personnel, including Analysts, Vulnerability Management staff, and SIEM Engineers. - Coordinate a hybrid workforce of onsite and remote staff, ensuring seamless communication, effective handoffs between shifts, and team accountability.
- Serve as the primary technical escalation point for Tier II and Tier III security incidents, providing hands-on direction during complex or high-risk events.
- Act as the lead incident responder or incident commander for major cybersecurity incidents in accordance with HHSC policies.
- Promote a culture of continuous learning by identifying skill gaps and overseeing technical training programs for SOC personnel.
- Manage scheduling and shift rotations to ensure 24/7/365 coverage, including after-hours, weekends, and holidays.
- Maintain and report key operational metrics (KPIs) to leadership to demonstrate SOC health and effectiveness.
- Support audit and compliance activities by providing necessary documentation and evidence of security operations.
- Collaborate on the review and validation of the Cybersecurity Incident Response Plan to ensure it remains actionable for the team.
- SOC Operations & Technical Oversight:
Drive the continuous improvement of incident response processes, Standard Operating Procedures (SOPs), and automated playbooks. - Monitor and optimize security alerting across the Microsoft security stack, including M365, Microsoft Defender for Endpoint (MDE), Defender for Cloud Apps (MDCA), and DLP solutions.
- Guide investigations related to Zero Trust Network Access (ZTNA) technologies to ensure secure remote access aligns with agency policy.
- Ensure Identity and Access Management (IAM) platforms (Okta, SailPoint, Login.gov) are monitored effectively with clear escalation paths for anomalies.
- Supervise proactive security functions, including vulnerability management, threat hunting, and the fine-tuning of security tools.
- Coordinate with system owners to ensure vulnerabilities are prioritized, remediated, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).