{"schemaVersion":"jobsearcher.job.v1","id":"a4bd348bb5ef88590ca72f3f","url":"https://jobsearcher.com/jobs/a4bd348bb5ef88590ca72f3f","canonicalUrl":"https://jobsearcher.com/jobs/a4bd348bb5ef88590ca72f3f","title":"AOUSC - SOC Manager","description":"cFocus Software seeks a SOC Manager to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.\nQualifications:\nActive Public Trust clearance\nB.S. Computer Science, Information Technology, or a related field\n7+ years’ experience in an active incident responder position; two (2) years of recent (within the last five (5) years) experience providing technical direction to a SOC (over 5,000 endpoints).\n2+ years of experience implementing IR in a federal environment in accordance with federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide.\n2+ years of experience using Splunk SIEM to correlate cybersecurity alerts.\n3+ years’ experience in auditing using operating system (Linux and Windows) to perform cybersecurity services.\nStrong technical writing skills to effectively communicate complex analytical findings and produce clear, concise, well-structured reporting to include executive audience level reports,\nThis role aligns to the NICE work role PD-WRL-001 (Defensive Cybersecurity).\nActive SANS GCIH or GCIA certification\n\nDuties:\nProvide operational leadership and management oversight for 24x7x365 SOC operations supporting Judiciary cybersecurity activities.\nManage cybersecurity triage, incident response, containment, remediation, recovery, and post-incident review activities.\nEnsure operational adherence to the Judiciary Security Operations Center Incident Response Plan (JSOCIRP), SOC Standard Operating Procedures (SOPs), and AO-defined escalation procedures.\nOversee alert triage activities utilizing Splunk Enterprise Security, Microsoft Sentinel, ServiceNow, Jira, and other approved Government systems.\nEnsure timely acknowledgment, triage, escalation, and handling of cybersecurity alerts in accordance with SLA requirements and incident prioritization timelines.\nLead operational coordination during Priority 1 and Priority 2 cybersecurity incidents and ensure timely government notification and escalation.\nOversee development and maintenance of cybersecurity triage work instructions, incident handling SOPs, response action procedures, and operational documentation.\nManage SOC analysts, incident responders, and forensic personnel to ensure staffing coverage, operational readiness, and quality performance.\nReview and validate cybersecurity incident reports, post-incident reviews (PIRs), forensic reports, malware analysis reports, and operational status reporting.\nCoordinate with AO leadership, federal staff, watch officers, branch chiefs, and stakeholders regarding cybersecurity incidents, operational risks, and emerging threats.\nEnsure accurate documentation of all cybersecurity activities, artifacts, timelines, and communications within ServiceNow and other authorized systems.\nManage operational metrics including Mean Time to Acceptance (MTTA), Mean Time to Triage (MTTT), containment timelines, remediation timelines, and quality assurance metrics.\nConduct weekly technical meetings and provide operational briefings, metrics, trends, risk assessments, and remediation recommendations.\nDevelop and maintain Common Operational Picture (COP) awareness and cybersecurity operational reporting for AO stakeholders.\nSupport continuous improvement initiatives by identifying detection gaps, process inefficiencies, workflow improvements, and operational enhancements.\nCoordinate cybersecurity forensics and malware analysis activities including evidence preservation, malware analysis, root cause analysis, and artifact review.\nEnsure operational compliance with NIST SP 800-53, NIST SP 800-61, NIST Cybersecurity Framework (CSF) 2.0, and ITIL v4 principles.\nSupport transition-in and transition-out activities including onboarding, operational readiness, training, and knowledge transfer.\nProvide executive-level and technical-level cybersecurity briefings, reports, and presentations.\nSupport enterprise security awareness reporting and development of operational KPIs.\n0hOjI1Mezk","company":"Cfocus Software","rawCompany":"cfocus software","city":"Washington","state":"DC","isRemote":false,"isActive":true,"createdAt":"2026-05-24T15:14:37.154Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"},{"code":"15-1244.00","title":"Network and Computer Systems Administrators","slug":"network-and-computer-systems-administrators"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"AOUSC - SOC Manager","description":"cFocus Software seeks a SOC Manager to join our program supporting the Administrative Office of the United States Courts (AOUSC). This position is Hybrid with the onsite location being in Washington, DC. This position requires a Public Trust clearance.\nQualifications:\nActive Public Trust clearance\nB.S. Computer Science, Information Technology, or a related field\n7+ years’ experience in an active incident responder position; two (2) years of recent (within the last five (5) years) experience providing technical direction to a SOC (over 5,000 endpoints).\n2+ years of experience implementing IR in a federal environment in accordance with federal incident handling guidelines as specified in NIST CSWP-29: CSF, and NIST SP-800-61 Computer Security Incident Handling Guide.\n2+ years of experience using Splunk SIEM to correlate cybersecurity alerts.\n3+ years’ experience in auditing using operating system (Linux and Windows) to perform cybersecurity services.\nStrong technical writing skills to effectively communicate complex analytical findings and produce clear, concise, well-structured reporting to include executive audience level reports,\nThis role aligns to the NICE work role PD-WRL-001 (Defensive Cybersecurity).\nActive SANS GCIH or GCIA certification\n\nDuties:\nProvide operational leadership and management oversight for 24x7x365 SOC operations supporting Judiciary cybersecurity activities.\nManage cybersecurity triage, incident response, containment, remediation, recovery, and post-incident review activities.\nEnsure operational adherence to the Judiciary Security Operations Center Incident Response Plan (JSOCIRP), SOC Standard Operating Procedures (SOPs), and AO-defined escalation procedures.\nOversee alert triage activities utilizing Splunk Enterprise Security, Microsoft Sentinel, ServiceNow, Jira, and other approved Government systems.\nEnsure timely acknowledgment, triage, escalation, and handling of cybersecurity alerts in accordance with SLA requirements and incident prioritization timelines.\nLead operational coordination during Priority 1 and Priority 2 cybersecurity incidents and ensure timely government notification and escalation.\nOversee development and maintenance of cybersecurity triage work instructions, incident handling SOPs, response action procedures, and operational documentation.\nManage SOC analysts, incident responders, and forensic personnel to ensure staffing coverage, operational readiness, and quality performance.\nReview and validate cybersecurity incident reports, post-incident reviews (PIRs), forensic reports, malware analysis reports, and operational status reporting.\nCoordinate with AO leadership, federal staff, watch officers, branch chiefs, and stakeholders regarding cybersecurity incidents, operational risks, and emerging threats.\nEnsure accurate documentation of all cybersecurity activities, artifacts, timelines, and communications within ServiceNow and other authorized systems.\nManage operational metrics including Mean Time to Acceptance (MTTA), Mean Time to Triage (MTTT), containment timelines, remediation timelines, and quality assurance metrics.\nConduct weekly technical meetings and provide operational briefings, metrics, trends, risk assessments, and remediation recommendations.\nDevelop and maintain Common Operational Picture (COP) awareness and cybersecurity operational reporting for AO stakeholders.\nSupport continuous improvement initiatives by identifying detection gaps, process inefficiencies, workflow improvements, and operational enhancements.\nCoordinate cybersecurity forensics and malware analysis activities including evidence preservation, malware analysis, root cause analysis, and artifact review.\nEnsure operational compliance with NIST SP 800-53, NIST SP 800-61, NIST Cybersecurity Framework (CSF) 2.0, and ITIL v4 principles.\nSupport transition-in and transition-out activities including onboarding, operational readiness, training, and knowledge transfer.\nProvide executive-level and technical-level cybersecurity briefings, reports, and presentations.\nSupport enterprise security awareness reporting and development of operational KPIs.\n0hOjI1Mezk","datePosted":"2026-05-24T15:14:37.154Z","dateModified":"2026-05-24T15:14:37.154Z","hiringOrganization":{"@type":"Organization","name":"Cfocus Software","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a4bd348bb5ef88590ca72f3f"},"url":"https://jobsearcher.com/jobs/a4bd348bb5ef88590ca72f3f"}}