SOC Team Lead - Incident Response
Job
Insight Global, LLC
Arlington Heights, IL (In Person)
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
82
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
at Insight Global, LLC in Arlington Heights, Illinois, United States Job Description Job Description The SOC Team Lead
To learn more about how we collect, keep, and process your private information, please review
- Incident Response is a senior, customer facing leadership role responsible for overseeing day to day security monitoring, incident handling, and escalation processes across the Security Operations Center. This role provides technical leadership, manages escalated incidents, guides SOC Analysts I
- III , drives process improvement, and ensures the SOC's incident response capabilities operate with accuracy, consistency, and speed.
- Lead escalated security incidents from identification through containment, eradication, and recovery, acting as the technical SME during active investigations.
- Own incident bridges and coordinate across Network, Compute, Client Operations, and external partners as required.
- Perform advanced analysis on alerts, logs, malware indicators, lateral movement patterns, and threat intelligence during IR engagements.
- Create and maintain incident timelines, evidence collections, and response documentation.
- Ensure all incidents follow established SLAs, communication plans, and reporting standards. SOC Team Oversight & Mentorship (15%)
- Assign, coordinate, and check work performed by SOC Analysts; supervise contract resources as required
- Provide coaching and mentorship to junior and mid level analysts to strengthen triage quality, analytical depth, and playbook execution.
- Support onboarding of new SOC analysts, ensuring they are trained in IR procedures, tooling, and operational workflows. Management Duties (10%)
- Conducts core people leadership activities, including performance reviews, goal setting, and supporting professional development for direct reports.
- Facilitates regular one on one meetings, team meetings, coaching sessions, and feedback conversations to ensure alignment and employee engagement.
- Oversees day to day team operations, ensuring workload balance, adherence to processes, and continuous improvement of team performance and capabilities. Process Development & Documentation (10%)
- Drive development and continuous refinement of IR playbooks, runbooks, escalation matrices, evidence handling procedures, and communication templates.
- Develop and update technical procedures and guidelines to ensure a consistent SOC response posture.
- Partner with Security Engineering, Architecture, and Threat Intelligence teams to improve detection logic, tuning, and response automation. Client & Stakeholder Communication (10%)
- Serve as the SOC's primary technical interface for IR related discussions with customer stakeholders, presenting findings to both technical and executive audiences.
- Participate in customer meetings, security reviews, and incident readouts; contribute to recommended improvements and risk mitigation strategies. Security Operations Enhancement (5%)
- Assist in evaluating tools, detection technologies, and workflow enhancements to improve SOC performance.
- Participate in research, continuous learning, and improvement initiatives to maintain team alignment with emerging threats and best practices.
To learn more about how we collect, keep, and process your private information, please review
Insight Global's Workforce Privacy Policy:
https://insightglobal.com/workforce-privacy-policy/. Skills and Requirements- 5+ years of experience in SOC operations
- Experience in threat detection, incident response and malware analysis
- Strong experience in CrowdStrike and Splunk
- Familiarity or experience in other tools such as Proofpoint, Zscaler, Cribl, Corelight, Akamai WAF , Open CTI and/ or SOAR
- Demonstrated leadership capability, including incident command experience or team lead responsibilities.
- Bachelor's Degree in Cybersecurity, Computer Science, or related field
- Relevant certifications desired: o
SANS / GIAC
:GCIH , GCIA , GCFA , GCFE , GREM , GSEC
oOffensive Security:
OSCP , OSWE
oISC2 / ISACA
:CISSP , CISM , CISA
o Other IR/ SOC focused certifications To view full details and how to apply, please login or create a Job Seeker accountSimilar jobs in Arlington Heights, IL
UnitedStates
Arlington Heights, IL
Posted2 days ago
Updated22 hours ago
Endeavor Health
Arlington Heights, IL
Posted2 days ago
Updated22 hours ago
NorthShore University HealthSystem
Arlington Heights, IL
Posted2 days ago
Updated22 hours ago
Salina Public Schools
Arlington Heights, IL
Posted2 days ago
Updated22 hours ago
Similar jobs in Illinois
Ingenovis Health
Monmouth, IL
Posted2 days ago
Updated22 hours ago
Midwest Arbor Corporation
Spring Grove, IL
Posted2 days ago
Updated22 hours ago