SOC Manager (IT Cyber Security Manager 2) jobs in United States
cer-icon
Apply on Employer Site
company-logo

Oregon Department of Human Services · 3 days ago

SOC Manager (IT Cyber Security Manager 2)

The Oregon Department of Human Services is seeking a SOC Manager to lead the Security Operations Center. This role involves overseeing the day-to-day operations, ensuring continuous monitoring and response to threats, and guiding a team of SOC analysts to enhance the security posture of the State of Oregon.

AssociationGovernmentNon Profit
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Lead the day-to-day operations of the State of Oregon’s Security Operations Center
Ensure continuous monitoring, detection, analysis, and response to threats that impact enterprise systems and critical public services
Guide and grow a team of SOC analysts, maintaining 24x7 readiness
Translate the SOC Director’s vision and enterprise direction into operational excellence
Lead the charge during high-impact incidents, ensuring clear thinking, calm leadership, and teamwork
Coordinate response efforts with Network, Endpoint, Cloud, Vulnerability, and agency partners across the state
Protect Oregonians’ data and continuously strengthen security posture

Qualification

Cybersecurity operationsSOC technologiesIncident responseThreat detectionMicrosoft DefenderCloud securityVulnerability managementSecurity frameworksTeam buildingLeadershipCommunication

Required

Six years of supervision, management, or progressively related experience; OR
Three years of related experience and a bachelor's degree in a related field
Related qualifying information systems experience in: Microsoft Defender for Endpoint, Identity, Office 365, and Cloud Apps, Attack surface reduction (ASR), device timeline, evidence & response actions, Live response sessions and EDR forensics; Qualifying Bachelor degree in Information Technology, Computer Science, or closely related field
A strong foundation in cybersecurity operations, with the ability to understand, oversee, and guide threat detection, incident response, vulnerability management, and security monitoring across on-premises, cloud, and hybrid environments
Operational fluency with modern SOC technologies and workflows, including SIEM, EDR/XDR, log management, alerting, case management, and investigation platforms, with the ability to ask the right questions, challenge assumptions, and make informed decisions when not hands-on in the tools
The mindset of a cyber operations leader, able to direct investigations, validate analyst conclusions, prioritize response actions, and ensure incidents are managed effectively from triage through recovery
A deep understanding of how enterprise identity, endpoints, networks, cloud services, and security controls interconnect, and how attackers move across them, utilizing the MITRE Att&ck Methods
Proven ability to build, mentor, and sustain high-performing SOC teams, fostering trust, accountability, resilience, and calm leadership in high-pressure, 24x7 environments
The judgment to balance risk, impact, and operational tempo, ensuring the right resources are focused on the most critical threats and that staff are supported and not burned out
The ability to evaluate and improve SOC processes, playbooks, tooling, and staffing models, turning gaps and lessons learned into practical operational improvements
Strong communication and leadership presence, with the ability to translate technical realities into clear guidance for executives, agency partners, and incident commanders
Experience coordinating complex incident response efforts across multiple teams, agencies, and external partners, bringing clarity, structure, and confidence during major events
Extensive experience (typically 7+ years in cybersecurity, including leadership or senior operational roles within a SOC, IR, or security operations environment)
Familiarity with security frameworks and best practices (NIST CSF, incident response lifecycle, MITRE ATT&CK) and how to apply them at an operational and programmatic level

Preferred

CISSP: (Certified Information Systems Security Professional)
SC-200: Microsoft Security Operations Analyst
SC-100: Cybersecurity Architect
AZ-500: Azure Security Engineer
CompTIA CySA+ or Security+
GIAC (GCIA, GCIH, GMON) for advanced threat hunting

Benefits

Comprehensive Health Coverage: Low-cost medical, vision, and dental plans for you and your family. Additional benefits include life insurance, short- and long-term disability, deferred compensation savings plans, and flexible spending accounts for health and childcare.  Optional benefits including life insurance, disability, FSA, and more
Generous Paid Time Off: 11 holidays, 3 personal business days, monthly sick leave and vacation leave that increases with years of service.
Career Development: Opportunities for professional growth and advancement.
Get There - Oregon’s easy-to-use carpool matching tool and trip planner.
Public Service Loan Forgiveness: You may qualify for the PSLF program.
Hybrid Work Opportunity: This position supports a hybrid work schedule. You can expect to work in the office 1 day per week, with work arrangements periodically reviewed to ensure business needs are met.

Company

Oregon Department of Human Services

company-logo
The Oregon Department of Human Services (ODHS) provides direct services to more than 1.5 million Oregonians each year.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Alan Schoenwald
Senior Human Resources Business Partner
linkedin
leader-logo
Ashlee Parpart
Lead Recruitment Business Partner
linkedin
Company data provided by crunchbase