True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
Job Responsibilities
Supervise and mentor SOC AnalystsAssign and balance workload across analysts and shiftsMonitor queue health, SLA compliance, and alert backlogConduct regular performance check-insAddress quality gaps and provide corrective guidanceReinforce adherence to documented playbooks and proceduresPrimary Focus: Ensure consistent and effective analyst performance.Hands-On Monitoring & InvestigationPerform daily alert triage alongside SOC AnalystsConduct investigations on moderate to high-severity alertsLead or directly support complex or multi-system investigationsValidate alert classifications and case documentationParticipate in shift coverage as neededPrimary Focus: Maintain technical engagement and operational credibility.Serve as the first escalation point for analystsLead investigations for high-severity incidentsCoordinate response actions with internal stakeholdersEnsure timely and accurate communication during incidentsDrive investigations to clear, defensible conclusionsPrimary Focus: Maintain operational control during critical events.Investigation Quality & Case GovernanceReview analyst investigations for accuracy and completenessApprove or return cases prior to closureEnsure proper evidence collection and timeline documentationEnforce consistent tagging, classification, and case hygienePrimary Focus: Protect the integrity of SOC output.Process & Continuous ImprovementMaintain and update SOC playbooks and workflowsIdentify inefficiencies in monitoring or case handlingProvide feedback on alert tuning and automation improvementsCapture and integrate lessons learnedStakeholder CoordinationRespond to formal information requests within defined SLAsServe as liaison between SOC analysts and leadershipSupport audits, reporting, and compliance requirementsParticipate in shift handoffs and operational planningPrimary Focus: Maintain trust and communication across teams.Workload Segmentation (Approximate) 30% – Direct Monitoring & Investigation Work 25% – Escalation & High-Severity Incident Leadership 20% – Team Management & Performance Oversight 15% – Investigation Quality Review & Case Governance 10% – Process Improvement & DocumentationPercentages may shift during major incidents or staffing changes.
Job Qualifications
Onsite is required Prior experience as a SOC Analyst or Senior AnalystDemonstrated ability to lead or coordinate investigationsExperience mentoring or supervising analystsStrong knowledge of: SIEM platforms (Splunk or equivalent) EDR tools, Network, authentication, and endpoint telemetryStrong documentation and communication skillsAbility to make sound decisions in time-sensitive situationsCompTIA Security+ or CySA+ (or equivalent) Experience in incident response or threat huntingFamiliarity with NIST, CIS, CJIS, or similar frameworksExperience with case management multiple platformsScripting/query experience (SPL, KQL, SQL, Python)Experience in regulated or government environmentsGCIH, GCIA, GCED or equivalentCore Competencies include: Technical leadership, operational accountability, coaching and mentorship, analytical problem-solving, process discipline, clear written and verbal communication, ability to lead under pressureRole Notes:This is both a management and technical role.The Team Lead is expected to maintain hands-on investigative capability.Operational response takes priority during active incidents.Decisions made in accordance with approved documentation are supported.The Team Lead is accountable for team output, not just individual cases.This role serves as the primary contact point with state wide cybersecurity collaboration. Managing weekend coverage may be necessary.
We’re actively searching for talented security and technology practitioners who are ready to experience the True Zero difference. As a True Zero team member, you'll enjoy:
- Competitive salary, paid twice per month
- Best in class medical coverage
- 100% of medical premiums covered by True Zero
- Company wide new business incentive programs
- Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.)
- 3 weeks of PTO starting + 11 Paid Holidays Annually
- 401k Program with 100% company match on the first 4%
- Monthly reimbursement of Cell Phone and Home Internet costs
- Paternity/Maternity Leave
- Investment in training and certifications to broaden and deepen your technical skills