Security Operations Center (SOC) Desk Manager
POSITION OVERVIEW
The Security Operations Center (SOC) Desk Manager plays a critical leadership role within MAD Security’s 24/7 SOC.
This position bridges the gap between strategic SOC leadership and day-to-day operations, ensuring Tier 1 and Tier 2 analysts deliver exceptional, timely, and compliant managed detection and response services to MAD Security clients.
The SOC Desk Manager oversees daily operational execution, team performance, client servicing, and adherence to SLAs, driving consistency, accuracy, and professionalism across SOC operations.
This role ensures every alert, escalation, and client communication reflects MAD Security’s high standards and core values of passion for high standards and constant improvement, integrity, professionalism, accountability, and coachability.
PRIMARY DUTIES and ESSENTIAL FUNCTIONS
Leadership, Management, and Accountability (LMA)
- Lead and manage SOC Desk operations, providing day-to-day supervision and mentorship for Tier 1 and Tier 2 SOC Analysts.
- Implement MAD Security’s vision for operational excellence by fostering accountability, discipline, and teamwork.
- Conduct performance reviews, provide ongoing coaching, and create growth pathways for SOC Analysts.
- Ensure operational coverage across shifts, managing scheduling, and ensuring SLAs are consistently met.
- Uphold MAD Security’s core values and ensure they are demonstrated throughout SOC operations.
SOC Operations Workflows Management
- Oversee the execution of MAD Security’s SOC playbooks, workflows, and standard operating procedures (SOPs).
- Ensure consistent application of alert triage, escalation, investigation, and response activities.
- Collaborate with the SOC Technical Lead to identify and correct workflow inefficiencies and automation opportunities.
- Maintain situational awareness of all active incidents and ensure appropriate escalation and communication protocols are followed.
- Ensure accuracy and timeliness in ticket handling and incident documentation.
SOC Operations Reporting Management
- Generate and review daily, weekly, and monthly SOC performance reports.
- Track and analyze key SOC metrics, including alert volumes, response times, incident closure rates, and SLA adherence.
- Provide data-driven insights to the SOC Manager to inform continuous improvement initiatives.
- Ensure the integrity and accuracy of SOC data across SIEM, SOAR, and ticketing systems.
SOC Operations Client Servicing Management
- Serve as the primary operational liaison for assigned client accounts, ensuring consistent communication, responsiveness, and satisfaction.
- Oversee the quality and professionalism of SOC notifications, incident reports, and remediation guidance.
- Escalate recurring client issues or service-impacting challenges to the SOC Manager for resolution.
- Support onboarding of new SOC clients, ensuring operational readiness and alignment with MAD Security’s service standards.
- Maintain awareness of client-specific requirements, including compliance needs (DFARS, NIST 800-171, and CMMC).
SOC SLA Management
- Monitor all SOC SLAs for response, escalation, and resolution, ensuring compliance with contractual obligations.
- Proactively identify risks to SLA performance and coordinate corrective actions.
- Maintain clear visibility into SOC performance metrics and drive accountability for meeting or exceeding targets.
- Continuously refine processes to improve efficiency, accuracy, and client satisfaction.
REQUIRED QUALIFICATIONS
- 5+ years of cybersecurity experience, including 2+ years in a SOC environment.
- 1–2 years of leadership or shift lead experience in a 24/7 operational security setting.
- Strong familiarity with SIEM, EDR/XDR, SOAR, and ticketing systems.
- Working knowledge of NIST, DFARS, and CMMC requirements.
- Experience managing operational SLAs and client-facing service delivery.
SUPERVISOR RESPONSIBILITIES
- Directly supervises Tier 1 and Tier 2 SOC Analysts.
- Collaborates with SOC Technical Lead and SOC Manager to ensure smooth handoff between technical escalation and client communication responsibilities.
LOCATION AND WORK ENVIRONMENT
While performing the duties of this job, the employee regularly works onsite in an office setting.
PHYSICAL DEMANDS
The physical demands described herein are representative of those which must be met by an employee to successfully perform the Primary Duties of this Job Description.
TRAVEL
Minimal travel required (<10%).
OTHER DUTIES
Please note this Job Description is intended to describe the general nature and level of work to be performed by the employee(s) assigned to this Job Title. It is not designed to contain nor be interpreted as a comprehensive and/or all-inclusive list of duties, responsibilities, and qualifications. MAD Security, LLC reserves the right to amend and/or change responsibilities to meet business and organizational needs, as necessary, with or without notice.
ABOUT MAD SECURITY, LLC
Founded in 2010, MAD Security is a Service-Disabled Veteran-Owned Small Business (SDVOSB) and a leading Managed Security Services Provider (MSSP). We specialize in safeguarding the defense industrial base, maritime, and government contractors with tailored cybersecurity solutions. Our robust services include SOC-as-a-Service (SOCaaS), Managed Detection and Response (MDR), Incident Response, GRC Gap Assessments, User Awareness Training, and Penetration Testing.
MAD Security integrates NIST frameworks into every solution, ensuring compliance with the highest federal standards while simplifying cybersecurity challenges for our clients. Recognized as a Top 250 MSSP for four consecutive years, we excel in providing proactive threat detection and mitigation through our award-winning Security Operations Center (SOC).
As a CMMC Registered Provider Organization (RPO), we have guided numerous contractors through CMMC Level 2 readiness, achieving milestones like perfect SPRS scores of 110 for clients. Our commitment to passion, integrity, and professionalism positions us as a trusted partner for defense and government organizations.
To learn more, visit www.madsecurity.com.