Ariento Inc.
The SOC Team Lead leads the Security Operations Center team responsible for 24/7 on call monitoring, detection, analysis, and response to cybersecurity threats. This role ensures operational excellence, team development, and alignment with compliance frameworks such as NIST 800-171 and CMMC.
Key Responsibilities Leadership & Operations Oversee daily SOC operations, including shift coverage, alert ticketing system, vulnerability scanning, and incident response. Lead, mentor, and develop SOC analysts; provide coaching, feedback, and escalation support. Manage SOC workflows, performance metrics, and service delivery KPIs. Serve as the escalation point for critical incidents and coordinate cross-functional response. Manage vulnerability program to identify and remediate vulnerabilities across the technology stack. Technical & Incident Response Guide analysts through investigation, containment, and remediation activities. Ensure consistent use of SIEM, EDR, SOAR, and threat intelligence tools (e.g., Sumo Logic, Defender, Microsoft 365). Refine detection rules, playbooks, and response procedures. Conduct threat intelligence and vulnerability management. Compliance & Audit Readiness Execute and maintain security and compliance monitoring and audit functions. Support internal and client audits aligned with NIST 800-171, CMMC, and other standards. Own audit and control functions, ensuring separation of duties and documentation integrity. Support Client audits by providing artifacts and being interviewed. Maintain audit documentation suite and work with Clients to customize to their needs. Stakeholder Engagement Communicate incident details and SOC updates to internal and external stakeholders. Support onboarding of new SOC clients, including tuning and baselining. Collaborate with support and development teams to support broader security initiatives. Program & Process Improvement Identify opportunities to improve SOC effectiveness, automation, and efficiency. Contribute to service maturity, including documentation, KPIs, and operational standards. Conduct disaster recovery and incident response drills.
Army: 25A, 25B, 25D, 17A, 17C Navy: 1820, 1840,1880, IT, CWT Air Force: 17D, 17S, 1D7X1, 1N4X1, Marine Corps: 0602, 1702, 0671, 1721 Space Force: 17X, 14N, 5I4X1, 5C0X1
Required Qualifications Bachelor's Degree Eligible for a tier three security clearance Minimum of 1 year of leadership experience, including people management. Strong understanding of SIEM/EDR technologies, detection logic, and investigative methodologies. Experience with regulated environments (e.g., DoD, DFARS/CMMC, NIST 800-171). Hands-on experience with development or DevOps environments. Ability to Commute to Franklin Office - Franklin, TN 37064 or Ability to Relocate Franklin, TN 37064: Relocate before starting work (Required) Preferred Skills & Certifications Experience with Sumo Logic and Microsoft 365. Hands-on experience with cybersecurity assessment/audits. Experience with technical documentation. (runbooks, diagrams, security controls, system security plans, accreditation packages, etc.) Familiarity with MDR/SOC service environments. Certifications: CMMC Certified Assessor (CCA), CMMC Certified Professional (CCP)
Ability to Commute to Franklin Office - Franklin, TN 37064 or Ability to Relocate Franklin, TN 37064: Relocate before starting work (Required)
No reviews yet. Reviews unlock for candidates 30 days after adding this program to their tracker — integrity over volume.
Interview prep for this program▸
- ▸ "How many of your past SkillBridge interns received full-time offers?" — a serious program knows the number.
- ▸ "Who will my day-to-day mentor be, and what does week one look like?"
- ▸ "The listing says 121 - 150 days — can that flex to my approved window if my command shortens it?"
- ▸ "Is relocation expected for a full-time offer, or can I convert where I am?"
- ▸ "You list 25A, 25B, 25D — what did interns from those specialties end up doing here?"
- ▸ Confirm the eligibility notes above — ask exactly what they need from you and when.
- ✓ Your projected start window and separation date (from your profile)
- ✓ Your command's approval status — even "packet drafted" signals you're serious
- ✓ Your civilian-translated resume bullets (generate them here)
- ✓ A written training-plan ask — you'll need it for your packet anyway