HHS - SOC Lead/Incident Response Manager Job at cFocus Software Incorporated, Rockville, MD

aXkxNzhoeEJySmhpeTByV3o4U2tBb0VtdEE9PQ==
  • cFocus Software Incorporated
  • Rockville, MD

Job Description

cFocus Software seeks a SOC Lead/Incident Response Manager to join our program supporting the Department of Health and Human Services (HHS) This position is remote. This position requires the ability a Public Trust clearance.
Qualifications:
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
  • Minimum 8 years of cybersecurity experience with at least 3 years in SOC or Incident Response leadership.
  • Demonstrated experience managing enterprise SOC operations and incident response programs.
  • Strong knowledge of NIST SP 800-61, NIST SP 800-53, NIST SP 800-37, FISMA, and federal cybersecurity policies.
  • Hands-on experience with SIEM, EDR, SOAR, threat intelligence platforms, and forensic tools.
  • Experience managing incidents involving PII/PHI and regulatory reporting requirements.
  • Ability to communicate complex technical issues to executive and non-technical audiences.
  • Experience operating in a federal or highly regulated environment.
  • Active CISSP, GCIA, GCIH, GCED, CISM, or CEH
Duties:
  • Lead and manage SOC and Incident Response operations in alignment with HRSA Incident Response Plans, SOC SOPs, playbooks, and workflows.
  • Ensure compliance with NIST SP 800-61, FISMA, OMB, DHS CISA, HHS, and HRSA incident response requirements.
  • Oversee incident triage, investigation, containment, remediation, and recovery activities within defined SLAs.
  • Serve as primary escalation point for Critical and High severity incidents, including ransomware and PII/PHI breaches.
  • Coordinate incident response activities with HRSA SOC, CSIRC, system owners, ISSOs, legal counsel, privacy officials, and leadership.
  • Develop, maintain, and continuously improve SOC SOPs, incident response playbooks, workflows, and response guidelines.
  • Manage incident communications, stakeholder notifications, and executive briefings during active incidents.
  • Ensure timely incident reporting, forensic documentation, and post-incident reports.
  • Lead threat hunting, IOC management, detection rule tuning, and SIEM correlation improvement activities.
  • Oversee digital forensic investigations and ensure proper chain-of-custody handling.
  • Monitor SOC tools and infrastructure health; coordinate upgrades, patches, and integrations.
  • Support federal cyber exercises, tabletop exercises, and incident response drills.
  • Ensure 24x7 on-call support coverage and adherence to response SLAs.
  • Provide metrics, dashboards, and reports on SOC performance, incident trends, and threat intelligence.
  • Identify opportunities for automation and efficiency improvements across SOC operations.

Job Tags

Full time, Remote work,

Similar Jobs

New Relic

Copy Writer Job at New Relic

Copy Writer Location Remote in Los Angeles, CA : Your Opportunity Are you a talented copywriter who can spark brilliant ideas, but also mine technical detail for the golden thread of a compelling message? Someone who can be serious about technologybut not always? Then... 

Trevor's Liquor

Sales Associate Job at Trevor's Liquor

 ...may be the place for you! Trevor's is looking for enthusiastic Sales Associates to join our team. Responsibilities Deliver...  ...or older ~ Experience in a retail setting ~ Familiarity with beer, wine, liquor and cigars preferred ~ Communication and relationship... 

Serioplast

Plastic Extrusion Operator Job at Serioplast

 ...Serioplast , a Global Leader in Rigid Plastic Packaging , is Looking for a Injection Molding Technician for the plants in St. Louis, Missouri! Are you a professional technologist looking for an exciting opportunity to thrive in a fast-paced, global environment... 

Deeply Rooted Music School

Music Teacher - Piano Job at Deeply Rooted Music School

 ...Seeking Piano Teachers About us Deeply Rooted Music School (DRMS) serves the Arvada, Lakewood, Westminster, North West Denver, and surrounding areas with quality music education. At DRMS, we empower our students to express themselves through music with collaboration... 

General Dynamics Information Technology

Incident Manager - Active top secret required Job at General Dynamics Information Technology

 ...REFERENCE ONLY): In this role, the selected candidate will manage the functionality and efficiency of a group of computers running...  ...Transform technology into opportunity as a Full Time, On-Site Incident Manager and Site Help Desk Manager with GDIT. A career in IT means...