Cybersecurity SOC Team Lead
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Security Manager
Benefits
- Competitive compensation
- Medical, Dental, and Vision insurance
- 401(k) Retirement Savings Plan with substantial company match
- Life and Travel Insurance
- Tuition Assistance
- Wellness Reimbursement Program
- Paid Holidays and Vacation
We are seeking a diligent and experienced Cybersecurity SOC Team Lead to join our team. In this role, you will be working within a group of highly motivated Information Technology and Cybersecurity professionals committed to keeping Central Hudson safe. The Cybersecurity SOC Team Lead leads a team of SOC Analysts and assists them in their daily operations as they proactively seek out adversaries.
The Team Lead is an escalation point for the SOC Analysts and a Liaison with our Cybersecurity Engineers. A Cybersecurity SOC Team Lead must possess various technical skill sets and experience to assure security events are analyzed and managed appropriately from the detection to the remediation phase of an event or incident. The ideal candidate will have a strong understanding of modern security principles, excellent analytical skills, and the ability to communicate effectively with internal stakeholders and vendors alike.
does a Cybersecurity SOC Team Lead do?
- Oversees daily SOC activities, ensuring timely detection and response to security incidents
- Continuously reviews and enhances SOC processes, including playbooks, response procedures, and threat hunting practices
- Supervises, mentors, and develops the SOC Analysts
- Initial escalation and notification point for SOC Analysts
- Leads post‑incident reviews and ensures lessons learned are documented and applied
- Prepares detailed reports on SOC performance and incident trends
- Assists Cybersecurity Engineers with tuning false positive and/or true positive non‑actionable security events
- Represents the Security Operations Center at internal/external meetings
- Oversees and leads incident response and investigation activities, ensuring timely resolution
- Fosters a collaborative environment for sharing insights and strategies
- Provides timely updates on ongoing incidents and emerging threats
- Highlights key metrics and performance indicators
- Proactively hunts for threats and vulnerabilities within the corporate environment
- Generates detailed reports on security incidents, including findings, action taken, and recommendations for future prevention.
- Provides regular status updates to management and stakeholders
- Works closely with other IT and security teams to ensure comprehensive incident management and response
- Monitors news, security sites, and other threat actor activity channels for new/current threats and stays updated on emerging cybersecurity threats and technologies
- Promotes and raises awareness by educating others about the importance of cybersecurity
- Builds relationships with government and local agencies to promote collaborative information sharing
- Supervises employees working in a 24/7 shift environment, including nights, weekends, and holidays and participates as needed
- Participates in on‑call as needed to respond to security incidents outside of regular working hours
- Provides storm/emergency response support
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science or related field of study and 3 years of experience in cybersecurity. In lieu of a bachelor’s degree, an associate degree in the aforementioned fields and 5 years of cybersecurity operations or related experience or a high school diploma or equivalency degree and 7 years of cybersecurity operations or related experience will be considered
- In‑depth knowledge of security operations, including SIEM, SOAR, EDR, IDS/IPS, malware analysis, email security, and endpoint protection
- Demonstrated ability to develop, tune, and optimize use cases for alerting in a SIEM platform
- Proficiency in threat hunting techniques and methodologies to proactively identify and mitigate potential threats
- Proven hands‑on experience in working collaboratively with an Incident Response team, including the ability to manage and coordinate responses during cybersecurity events and incidents.
- Experienc…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).