Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
FG
Florida Gulf Coast University
Security Operations Center Lead
Career Insights for Security Operations Center Analyst
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Florida data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Security Operations Center Analyst monitors and analyzes security events and instances within an organization's IT infrastructure. Responds to real-time cybersecurity threats, configuring and deploying security infrastructures, and monitoring of ongoing security issues.
$102,475 / year median in Florida
Job Description
Security Operations Center Lead Job Summary The Security Operations Center Lead is responsible for leading the day-to-day operations of the University's Security Operations Center, including cybersecurity monitoring, alert triage, incident response coordination, operational reporting, and continuous improvement of SOC processes. This position serves as the primary operational lead for the SOC and provides technical supervision, mentorship, and professional development for undergraduate and graduate student analysts. The position ensures that security events are investigated, documented, escalated, and remediated in accordance with approved procedures, response playbooks, and institutional priorities. The lead collaborates closely with Information Technology Services, the Information Security Office, Help Desk, Client Services, and other university stakeholders and external partners to protect University systems, data, services, and users while supporting the broader mission of cybersecurity education, workforce development, and institutional risk reduction. FGCU is building a culture of curiosity, commitment and collaboration. We value employees who successfully work with others and drive positive change through critical thinking and decisive action. If you thrive in an environment of innovation, accountability and mutual respect, you will find a good home here. Job Description Typical duties may include but are not limited to: Leads day-to-day Security Operations Center (SOC) activities, including security monitoring, alert triage, investigation, escalation, incident response coordination, operational reporting, and analyst shift oversight. Participates in after-hours incident response, emergency escalation, and on-call support as needed to address significant cybersecurity events or operational requirements. Recruits, hires, trains, mentors, and supervises undergraduate and graduate student analysts. Provides ongoing coaching, performance feedback, and career development support. Develops and maintains a structured student analyst training program covering alert triage, SIEM operations, threat detection, MITRE ATT&CK methodologies, digital forensics fundamentals, investigation procedures, and incident response workflows. Develops or supports cybersecurity exercises, tabletop scenarios, and incident response drills to evaluate readiness and improve coordination among SOC personnel, ITS teams, and university stakeholders. Establishes analyst progression standards, operational guardrails, and escalation thresholds to ensure student analysts operate within approved authority and documented procedures. Performs security monitoring, investigation, and incident response activities as needed to maintain SOC operations during periods of reduced student staffing or elevated operational demand. Reviews, validates, and directs security investigations, ensuring security events are properly analyzed, documented, escalated, and communicated in accordance with established policies, procedures, and response playbooks. Serves as the operational lead during significant cybersecurity incidents, coordinating response activities with Information Technology Services (ITS), university leadership, legal counsel, human resources, communications personnel, and external partners as appropriate. Maintains and improves detection, monitoring, and response capabilities across security technologies, including SIEM, endpoint detection and response (EDR), cloud security platforms, and related cybersecurity tools. Develops, maintains, and updates SOC playbooks, standard operating procedures, workflows, and documentation to support consistent and effective security operations. Manages relationships with managed security service providers (MSSPs), incident response vendors, and other external security partners to support monitoring, investigation, and response activities. Supports security operations and incident response activities involving regulated or sensitive institutional data, including data subject to
Experience with SOAR platforms. CISSP, CISM, Security+, GCIH, GCIA, CISA, or similar certifications.
FERPA, GLBA, PCI DSS, HIPAA
where applicable, and university policies. Escalates actionable cybersecurity risks, incidents, and operational concerns to the Chief Information Security Officer (CISO) and other designated stakeholders. Maintains security operations documentation and reports on security metrics, incident trends, operational performance, and student program outcomes. Conducts or supports audits, compliance activities, and security reviews. Conducts post-incident reviews and broader security process evaluations to identify lessons learned, document corrective actions, and recommend improvements to detection logic, response procedures, communication workflows, and operational controls to enhance overall SOC effectiveness and operational efficiency. Communicates technical security findings, risks, and operational impacts in clear, non-technical language suitable for university leadership and business stakeholders. Contributes to broader information security initiatives including cloud security, identity and access management, security awareness, and emerging technology governance efforts.Other Duties:
Performs other job-related duties as assigned.Additional Job Description Required Qualifications:
This position requires nine years of directly related full-time experience or, as an alternative, a Bachelor's degree from an accredited institution in Cybersecurity, Computer Science, Informatics, Information Systems, or related field and five years of full-time experience directly related to the job functions. Experience with SOC operations, security monitoring, incident response, or related cybersecurity functions, including conducting cybersecurity investigations, alert triage, or security event analysis. Experience with enterprise SIEM, EDR, or similar platforms. Experience utilizing Microsoft security tools, including Microsoft Entra ID, Microsoft Sentinel, Active Directory, Microsoft Defender, Microsoft 365 security features or comparable enterprise security tools. Any appropriate combination of relevant education, experience, and/or certifications may be considered.Preferred Qualifications:
Five years full time experience in cybersecurity operations, incident response, or threat detection. Two years experience in managing, coaching, or mentoring technical staff or junior analysts Familiarity withNIST CSF, NIST
800-53, FERPA, and HIPPA. Experience working in Higher Education. Familiarity with Higher Education technologies, including Banner, Workday, Canvas, Blackboard, and research computing infrastructure. Experience designing security training or formal curricula. Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Entra ID, Microsoft Purview, or related Microsoft security technologies.Experience with SOAR platforms. CISSP, CISM, Security+, GCIH, GCIA, CISA, or similar certifications.