Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Columbia Consulting Group

Security Operations Center Manager

Career Insights for Incident Analyst / Responder

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Connecticut data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.

$116,725 / year median in Connecticut

+7% projected growth

Explore Career

Job Description

Our client is seeking a Senior Security Engineer to serve as our SOC Lead. This is primarily a leadership position within the Security Operations Center; in addition, it is a role that safeguards our customers, protects our reputation, and upholds the trust that countless organizations place every single day. This person will balance technical depth and client success. You will guide our security analyst team, help engineer our detection strategies, shape our response posture, and represent the very best operational security excellence. Key Responsibilities Lead, mentor, and uplift a team of SOC analysts whose work directly protects customers. Serve as the senior escalation point for complex investigations, high-severity incidents, and real-time decision making. Develop training, playbooks, and performance goals to ensure analysts thrive. Refine and maintain detection and response workflows in tools such as Elastic Security, Microsoft Defender XDR, Microsoft Sentinel, CrowdStrike Falcon, and Torq (SOAR). Design and maintain the telemetry pipelines, normalization workflows, and automation triggers that power our SOC. Be a mentor to the analyst group. Customer Success & Relationship Management Serve as a point of contact for escalations and customer communications during major incidents. Excellent customer relations & communication skills are a must. Partner with the strategic consulting team and customer success teams to ensure client needs are met and exceeded. Represent the SOC internally and externally, championing best practices, emerging threats, and the importance of strong telemetry hygiene. Present SOC metrics, incident summaries, and operational improvements to customers in a clear, executive-ready format. Strategic Contributions Contribute to SOC2 compliance and internal process maturity. Provide feedback to Product and Engineering teams to improve Vancord's Vantage MDR. Stay ahead of emerging threats, industry best practices, and technology evolutions. Required Qualifications 5+ years of experience in a SOC, Incident Response, or security observability environment. 3+ years of senior-level technical experience guiding analysts, leading investigations, or operating as a technical lead. Strong knowledge of SIEM, EDR, SOAR, and security telemetry (Elastic, Sentinel, Defender, CrowdStrike, SentinelOne, etc.). Demonstrated ability to lead and mentor technical teams. Strong communication skills, with the ability to present to executives and customers under pressure. Experience building runbooks, playbooks, or process documentation. Experience managing vulnerabilities, threat intelligence, and emerging threats. Experience using programming languages such as Python to automate security tasks. A strong understanding of data pipelines, normalization, and security observability.
Preferred Qualifications Advanced Detection & Telemetry Engineering:
Expertise designing large-scale detection architectures, authoring advanced correlation logic, building ECS-aligned pipelines, and operating
SIEM/EDR
platforms such as Elastic, Defender, Sentinel, and CrowdStrike.
Automation & Tooling Mastery:
Proven ability to engineer SOC automation through SOAR platforms and Python-based tooling, including enrichment pipelines, ETL workflows, and data-stream integrations that measurably reduce manual workload and MTTR.
Threat Intelligence, Threat Hunting & Incident Command:
Deep experience conducting structured hunts, developing threat intelligence-driven detections, and leading major incident response events with clear executive communication and real-time decision making.
Security Architecture & MSSP/MDR Experience:
Strong understanding of cloud, endpoint, and identity telemetry; experience operating in high-velocity
MSSP/MDR
environments; and familiarity with
SOC2/ISO/NIST
frameworks, customer communications, and operational maturity programs.
Job Types:
Full-time, Contract Pay:
$70.00 per hour
Benefits:
401(k)
Work Location:
In person