SOC Watch Officer

External job listingat Revolutional

Title: SOC Watch OfficerLocation: Chandler, AZTerms: Full-timeSalary Range: $130-160k DOEClearance: Active Secret required; Top Secret/SCI eligibility requiredTravel: 0-20% Position Descr...

External source - not verifiedyesterdayOpen until: Sep 18, 2026

Salary

Not provided

Location

Chandler, United States

Employment type

Full time

Workplace

Not provided

SOC Watch Officer

Chandler, United States

Job description

Title: SOC Watch OfficerLocation: Chandler, AZTerms: Full-timeSalary Range: $130-160k DOEClearance: Active Secret required; Top Secret/SCI eligibility requiredTravel: 0-20%
Position DescriptionAs a SOC Watch Officer at Revolutional, you are the senior authority on the floor during your watch. You are responsible for the operational integrity of a 24/7/365 security operations mission — overseeing analyst activity, managing active security events, and making real-time decisions that protect a large-scale federal network environment.
You are not a passive supervisor. You monitor what your analysts are working, catch what they miss, direct response actions on active incidents, and ensure nothing falls through the cracks across your shift. When events escalate, you are the first line of senior judgment before it reaches the SOC Team Lead.
ResponsibilitiesMaintain situational awareness across all active monitoring queues, open incidents, and security events during assigned watchSupervise SOC analysts on shift; direct workload, review analyst actions, and ensure response quality and timeliness meet program standardsMake real-time operational decisions on event triage, escalation, and response prioritization during your watchServe as the shift escalation point for complex or high-severity events; determine when incidents require SOC Team Lead or program leadership notificationEnsure accurate, timely documentation of all security events, analyst actions, and incident status throughout the shiftConduct shift turnover briefings; communicate open incidents, active threats, and watch floor status to incoming personnel with full fidelityMonitor SOC tooling and sensor coverage during watch; escalate gaps, outages, or anomalies that affect detection capabilityEnforce adherence to SOC playbooks, standard operating procedures, and incident handling protocols across the shift teamSupport incident response activities through containment and remediation, coordinating with relevant technical teams as neededContribute to after-action reviews, shift reports, and continuous improvement of watch floor operations
What You Bring (Requirements)Baseline RequirementsBachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)3 or more years of supervisory experience in a security operations or related technical environmentSubstantial hands-on security operations experience, including monitoring, detection, and incident response in enterprise network environmentsActive Secret clearance; Top Secret/SCI eligibility required
Technical & Domain CapabilitiesDeep familiarity with SOC operations: continuous monitoring, alert triage, log analysis, and threat detection across complex network environmentsExperience managing or directing analyst teams during active security incidentsProficiency with SIEM platforms, EDR tools, and network monitoring technologies used in enterprise SOC environmentsUnderstanding of incident response procedures from detection through containment and remediationFamiliarity with FISMA, NIST incident response frameworks, and federal security operations standardsWorking knowledge of network security architectures including LANs, WANs, and cloud environments
Core StrengthsDecisive under pressure — you make sound calls on active incidents without waiting for perfect informationStrong situational awareness: you track multiple active events simultaneously and know which ones need your attention firstEffective shift supervisor who holds analysts accountable and maintains operational discipline across the watch floorClear communicator who writes clean incident documentation and delivers crisp shift handoffs
CertificationsOne certification from each of the following groups is required:Group 1 — Security OperationsCASP+ (CompTIA Advanced Security Practitioner), CCSP (Certified Cloud Security Professional), SSCP (Systems Security Certified Practitioner), GMON (GIAC Continuous Monitoring), GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), or GECD (GIAC Enterprise Cloud Defense)Group 2 — DoD 8570 CSSPAny certification qualifying under the DoD 8570 CSSP Analyst, Infrastructure Support, or Incident Responder categoriesNote: 6 years of equivalent hands-on security operations experience may be considered in lieu of one certification requirement.
Nice to Have (Differentiators)Experience as a watch officer or shift lead in a federal civilian, defense, or intelligence SOC environmentFamiliarity with tier-less SOC operations and cross-functional incident coordinationBackground in threat hunting, APT detection, or kill-chain-based response methodologiesExperience with Zero Trust monitoring or cloud-based security operationsActive TS/SCI clearance

Is this your job posting?

Claim it for free and receive video applications on CazVid.

Similar jobs