← All Positions
SOC Team Lead (2nd shift (4:00 PM–1:00 AM CST)/3rd shift (12:00 AM–9:00 AM)
Job Description

ECCO Select is a talent acquisition and consulting company specializing in people, process and technology solutions. We provide the talent behind the technology enabling our clients to achieve their goals. For more information about ECCO Select, visit us at www.eccoselect.com.

Position Title:     SOC Team Lead (2nd or 3rd Shift)

Location Information  

Remote – 2nd shift (4:00 PM–1:00 AM CST) or 3rd shift (12:00 AM–9:00 AM CST)

Position Responsibilities:

As a SOC Team Lead, you will play a pivotal role in building operational excellence within a dynamic Security Operations Center. You will manage and mentor a team of analysts, ensuring clear, consistent, and high-quality execution of security monitoring, investigation, detection engineering, incident response, and cross-team coordination. Your leadership will advance the SOC's maturity in detection fidelity, threat hunting, documentation, and escalation readiness.

This is a hands-on leadership role, balancing day-to-day operational focus with process ownership, analyst development, and quality improvements under time-sensitive and high-stakes circumstances. You will be responsible for end-to-end execution, including shift scheduling, escalation protocols, investigation quality, and continual process improvements across your assigned shift.

 

Essential Skills, Experience

  • Team Leadership & People Management: Directly manage, coach, and develop SOC analysts; providing mentorship, fostering performance improvement, and guiding career development.
  • Shift Operations & Escalation Readiness: Own shift scheduling, coverage, escalation protocols, and investigation quality for your assigned hours, ensuring consistent service delivery and incident triage.
  • Operational Excellence: Oversee day-to-day SOC execution, including monitoring queue health, ensuring investigation consistency and documentation, and driving escalation discipline.
  • Process Improvement: Identify workflow inefficiencies, streamline response procedures, and implement measurable improvements across tools, documentation, automation, and analyst routines.
  • Detection Engineering: Define detection priorities from threat intelligence and incident data, manage tuning across SIEM, SOAR, EDR, and log analytics platforms, and strengthen alert fidelity while reducing false positives.
  • Incident Response Governance: Govern incident identification, escalation, and documentation in alignment with incident management procedures; ensure all findings are defensibly documented and artifacts are properly managed.
  • Cross-Functional Coordination: Maintain clear coordination with internal functions such as GRC, IAM, Infrastructure, Cloud, AppSec, and Vulnerability Management, ensuring swift and well-documented handoffs and actionable remediation guidance.
  • Communication & Documentation: Deliver clear, audit-ready documentation of investigations and incidents; provide accurate operational context to support policy, leadership, and audit discussions.

Success in this role will mean:

  • Your team operates efficiently with minimal friction, conducts thorough investigations, and consistently produces high-quality documentation.
  • Detection content and system tuning are prioritized and managed for optimum fidelity and reduced alert fatigue.
  • Incident response is handled, documented, and escalated in accordance with established procedures, standing up to audit scrutiny.
  • Collaboration between SOC and other technical or risk teams is clear and effective, supporting rapid remediation and continuous maturation of the security posture.
  • The SOC improves in speed, accountability, and consistency over time as threat and response requirements evolve.

Qualifications:

  • 5+ years in SOC operations, detection engineering, threat hunting, incident response, or related operational security roles, including at least 2 years in a team lead, senior analyst, or coordination function.
  • Demonstrated ability to balance robust security practices with business context in a risk-managed environment.
  • Hands-on knowledge of incident response, SOC operations, detection engineering, and threat intelligence processes.
  • Experience leading workflow improvements, analyst development, and operational or technical enhancements.
  • Strong communication skills and a commitment to thorough, consistent, and audit-ready documentation of SOC activities.
  • Bachelor’s degree in computer science, cybersecurity, or a related discipline, or equivalent experience and professional certifications.
  • Preferred: Experience developing or owning SOC SOPs, SLAs, incident governance, or operating in compliance/audited environments; proficiency in cross-team coordination and ownership models.

ECCO Select is committed to hiring and retaining a diverse workforce. Our policy is to provide equal opportunity to all people without regard to race, color, religion, national origin, ancestry, marital status, veteran status, age, disability, pregnancy, genetic information, citizenship status, sex, sexual orientation, gender identity or any other legally protected category. Veterans of our United States Uniformed Services are specifically encouraged to apply for ECCO Select opportunities.

Equal Employment Opportunity is The Law
This Organization Participates in E-Verify

Interested in this role? Submit your application and a recruiter will be in touch.

Apply Now →
Job Details
Location Remote
Type Contract
Posted June 22, 2026
Job ID 11391
Submit Your Application
Applying for: SOC Team Lead (2nd shift (4:00 PM–1:00 AM CST)/3rd shift (12:00 AM–9:00 AM)

Job Application

This field is for validation purposes and should be left unchanged.
Max. file size: 50 MB.

Voluntary Self-Identification

Right to Represent(Required)