- Provide comprehensive cybersecurity support services to protect critical consular systems and data for a large Federal Agency.
- Serve as the primary technical lead for all security operations and monitoring activities under the call order.
- Oversee 24/7 operational coverage.
- Coordinate directly with ISSOs to deliver technical security evidence, remediation actions, and operational data supporting RMF and A&A activities.
- Ensure security operations activities align with ISSO-approved security baselines and Department policies.
- Implement and operate SIEM processes for covered Oracle systems.
- Configure SIEM to collect security events from Oracle systems.
- Develop correlation rules for Oracle-specific security events.
- Monitor SIEM alerts and investigate security anomalies.
- Provide SIEM data and alerts to ISSOs for incident response coordination.
- Conduct OSINT monitoring for Oracle-specific threats.
- Monitor Oracle security advisories and vulnerability disclosures.
- Track threat intelligence related to Oracle database attacks.
- Provide weekly threat intelligence summaries to ISSOs.
- Perform digital forensics and log analysis for covered systems.
- Analyze Oracle audit logs, AVDF reports, and PUM access logs.
- Investigate security anomalies and suspicious activities.
- Provide forensic findings to ISSOs and incident response teams.
- Support ISSO-led incident response activities.
- Execute technical incident response actions as directed by ISSO.
- Provide system logs, forensic data, and technical analysis.
- Implement incident containment and remediation measures per ISSO direction.
- Document incident response actions and provide them to ISSO for incident reports.
- Perform operational security posture assessments.
- Conduct technical security reviews of Oracle system configurations.
- Identify security weaknesses and configuration vulnerabilities.
- Provide assessment findings to ISSO for POA&M development.
- Implement ISSO-directed security improvements.
- Maintain long-term storage of security logs and audit data.
- Retain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements.
- Ensure log data availability for ISSO-led compliance audits and assessments.
- Provide historical log data to ISSO upon request for correlation and analysis.
Requirements
- Minimum of SEVEN (7)+ years of overall work experience.
- Bachelors degree from an accredited university.
- Must have active CISSP, GCIA or equivalent certification
- Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred.
- US Citizenship is contractually required.
- Strong familiarity with SIEM platforms, endpoint detection and response (EDR) tools, and SOAR workflow automation.
- Demonstrated ability to develop and maintain detection use cases, playbooks, and investigative procedures.
- Experience defining and reporting SOC metrics and KPIs to measure effectiveness and drive operational improvements.
- Excellent written and verbal communication skills with the ability to communicate technical details to non-technical stakeholders and executive leadership.
- Proven leadership skills: coaching, performance management, scheduling for 24/7 operations, and handling escalations under pressure.
- Travel required up to 10%.
- Master’s in computer science, IT, cybersecurity or related field preferred.
- Experience working with the Department of State preferred.
Core Competencies
Demonstrates extensive expertise in cybersecurity operations, particularly in SIEM processes, incident response, and threat intelligence related to Oracle systems. Proven ability to lead technical security initiatives and communicate effectively with both technical and non-technical stakeholders.
Highest-signal resume keywords
- CISSP Certification
- SIEM Platform Expertise
- Incident Response Coordination
- Oracle Security Monitoring
- Leadership in 24/7 Operations
Hard Skills
- Cybersecurity Support Services
- Digital Forensics
- Log Analysis
- Threat Intelligence Analysis
- Security Operations Monitoring
- Configuration Vulnerability Assessment
- Detection Use Case Development
- Incident Containment Measures
- Operational Security Posture Assessment
- Technical Security Review
Soft Skills
- Excellent Communication Skills
- Leadership Skills
- Coaching and Performance Management
- Ability to Handle Escalations Under Pressure
Certifications & Qualifications
- CISSP
- GCIA
Industry Keywords
- Federal Agency
- Department of State
- Risk Management Framework (RMF)
- Authorization and Accreditation (A&A)
- Oracle Systems
- OSINT Monitoring
- Compliance Audits
Tools & Technologies
- SIEM Platforms
- Endpoint Detection and Response (EDR) Tools
- SOAR Workflow Automation
#J-18808-Ljbffr
Security Operations Manager Arbeitgeber: Jobtailor
Als Front Office Supervisor in unserem dynamischen Team bieten wir Ihnen die Möglichkeit, in einem unterstützenden und freundlichen Arbeitsumfeld zu wachsen. Wir legen großen Wert auf die berufliche Entwicklung unserer Mitarbeiter und bieten regelmäßige Schulungen sowie die Chance, Verantwortung zu übernehmen. Unsere Lage ermöglicht es Ihnen, Teil einer lebendigen Gemeinschaft zu sein, während Sie gleichzeitig die Standards unseres Franchise-Partners einhalten und unseren Gästen einen unvergesslichen Aufenthalt bieten.