About this Attack Sensing & Warning Lead role at Accenture Federal Services
Who you'll be:
We are seeking an Attack Sensing & Warning (AS&W) Lead to direct Tier I monitoring/reporting and Tier II analysis operations within a federal agency's Security Operations Center (SOC). In this high-tempo leadership role, you will oversee the team responsible for triaging security events, drafting executive-level cyber incident reports, and ensuring round-the-clock detection coverage across the enterprise. You will set the tone for timely and accurate identification, escalation, and communication of emerging threats, while collaborating with Detection Engineering to enhance the SOC's sensors and alerting logic.
What you'll need:
- Lead the AS&W team in providing incident response capabilities in alignment with DHS 4300A and the SOC's Incident Response Plan (IRP).
- Oversee the categorization, prioritization, and reporting of security events in accordance with SOC Standard Operating Procedures (SOPs).
- Direct the drafting of executive-level cyber incident reports for Government review, ensuring compliance with all required checklists and playbook thresholds.
- Collaborate with Detection Engineering to configure and maintain alerts across all SOC monitoring tools.
- Support the development of meaningful metrics and Key Performance Indicators (KPIs) detailing SOC operational status and performance.
- Manage the daily 0600 SOC Report and Daily Call cadence with government stakeholders, ensuring timely and accurate reporting.
- Direct triage and support for Information/Data Spillage Incident Response efforts, coordinating handling and sanitization recommendations.
- Lead the biannual review and update of SOC SOPs, ensuring continued compliance with applicable federal policy.
- Coach and develop Tier I and Tier II analysts on triage methodology, escalation criteria, and reporting standards.
What you need:
- US Citizenship required.
- 10+ years of experience, with a BS degree (or 4 years additional experience), or an MS degree (or 2 years additional experience).
- A minimum of five (5) years of professional experience in security, information risk management, or information systems risk assessment.
- Deep knowledge of vulnerability assessments, intrusion prevention/detection, access control, policy enforcement, application security, protocol analysis, firewall management, incident response, DLP, encryption, and advanced threat protection.
Nice to have:
- Prior shift-lead or supervisory experience in a 24x7 SOC environment.
- Experience drafting incident reports for executive or Congressional-level review.
- Familiarity with MITRE ATT&CK-aligned detection content development.
Required Certifications:
- Active Certified Information Systems Security Professional (CISSP) recommended, consistent with other Task Leads on this program.
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Connecticut, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Ohio, Vermont, Virginia, Washington, and the District of Columbia. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.