Cyber Security Operations Senior Manager
What You'll Do
The Cyber Security Operations Senior Manager serves as the operational commander, technical mentor, and strategic leader for the Cyber Security Operations team. Reporting directly to the Chief Information Security Officer (CISO), this position is pivotal in safeguarding critical national security infrastructure while building and scaling a resilient, high-capability cyber defense organization. This is a "player-coach" leadership role designed for an operational cyber practitioner who is equally passionate about modern defensive technical strategy—such as Zero Trust Architecture (ZTA), Defense-in-Depth (DiD), threat hunting, and proactive detection engineering—and developing people. As manager, you will serve as a force multiplier: elevating the technical depth of the existing team, fostering a continuous learning environment, and translating complex adversary threat intelligence into actionable operational defenses. You will oversee Defensive Cyber Operations (DCO), Cyber Security Engineering, and Incident Response (CSIRT) activities in close collaboration with the Network Operations Center/Security Operations Center (NOC/SOC), Formal Authorization and Risk Management team, and Department of Energy (DOE)/National Nuclear Security Administration (NNSA) stakeholders to outpace evolving threats.
Responsibilities
- Team Leadership, Mentorship & Talent Growth:
- Build Team Depth & Capability: Serve as a dedicated mentor and technical coach to junior, mid-level, and senior analysts; design clear skill-development pathways, cross-training initiatives, and knowledge-sharing frameworks to expand the team's operational bench depth.
- Cultivate an Operational Culture: Lead, empower, and inspire a service-oriented cyber operations team, fostering an environment of curiosity, technical rigor, open communication, and shared accountability.
- Resource & Workload Management: Plan, prioritize, and coordinate staff assignments across operational shifts, incident response tasks, and long-term security engineering projects to maintain team health and operational readiness.
- Defensive Operations, Threat Hunting & Incident Command:
- Proactive Threat Hunting: Lead the strategy for active threat hunting using the MITRE ATT&CK framework to detect living-off-the-land (LotL) techniques, covert persistence, and anomalous activity before impact occurs.
- Incident Response Oversight: Oversee all Cyber Security Incident Response (CSIRT) activities (collaborating with delegated incident leads), acting as the senior operational escalation authority and crisis commander during high-severity cyber events.
- Playbook & Detection Modernization: Drive continuous improvement of incident playbooks, automated response workflows, and Security Information and Event Management (SIEM)/Extended Detection and Response (XDR) detection rules (specifically within Splunk) to maximize analyst efficiency and reduce time-to-detect/time-to-respond.
- Security Engineering & Practical Defense-in-Depth:
- Zero Trust & Hardening Strategy: Guide security engineering efforts to transition legacy network postures toward Zero Trust Architecture (ZTA) principles, enhanced micro-segmentation, and identity-bound access controls.
- Vulnerability & Exposure Management: Oversee enterprise vulnerability scanning, risk prioritization (e.g., United States Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEVs)), and mitigation strategies in partnership with Information Technology (IT) and Network Operations.
- Threat Modeling & Validation: Conduct threat scenario walkthroughs, coordinate red/blue team exercises, and oversee penetration testing efforts to validate the real-world effectiveness of existing security controls.
- Strategic Communication & Governance:
- Executive & Stakeholder Engagement: Maintain clear, concise, and timely operational communications with the CISO, executive leadership, and external federal/DOE stakeholders during routine operations and elevated threat conditions.
- RMF & Continuous Monitoring Integration: Bridge operational defense with governance by translating National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) guidance into continuous monitoring metrics and leveraging automated electronic Governance, Risk, and Compliance (eGRC) tools.
Minimum Job Requirements
- Bachelor's Degree and minimum 10 years of relevant experience.
- OR applicants without a bachelor's degree may be considered based on a combination of at least 18 years of completed education and/or relevant experience.
Preferred Job Requirements
- Three years of supervisory/management experience. Candidates with less years of supervisory/management experience will be required to complete a developmental plan approved by the Division Director or their delegate.
- Leadership & Mentorship Excellence:
- Proven track record of successfully growing, mentoring, and retaining technical cyber security staff, with a focus on knowledge transfer and elevating team capability.
- Strong interpersonal and service-oriented leadership skills, with demonstrated success managing cross-functional technical teams and complex projects.
- Core Technical & Operational Capabilities:
- Practical Cyber Operations: Extensive, hands-on experience in security operations (SOC), advanced threat hunting, log management/analysis, and coordinating responses to sophisticated attacks (including Advanced Persistent Threat (APT) vectors).
- SIEM & Analytics: In-depth experience with Splunk (or equivalent enterprise SIEM platforms), custom SPL detection development, and behavioral analytics.
- Defensive Engineering & Architecture: Deep understanding of security engineering principles, Next-Generation Firewalls (NGFW), Intrusion Detection/Prevention Systems (IDS/IPS), Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR), authentication mechanisms, and network security baselines.
- Zero Trust & Security Frameworks: Familiarity with implementing practical Zero Trust concepts (NIST Special Publication (SP) 800-207) and Defense-in-Depth strategies in complex environments.
- Vulnerability Assessment: Experience utilizing Tenable/Nessus or automated compliance scanning platforms to identify and remediate enterprise risks.
- Federal Frameworks & Mission Context:
- Knowledge of Federal cybersecurity standards and risk baselines (e.g., NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-37/39 RMF, Department of Defense (DoD) Security Technical Implementation Guides (STIGs), Committee on National Security Systems Introduction (CNSSI) 1253).
- Familiarity with Department of Energy (DOE) / National Nuclear Security Administration (NNSA) cybersecurity requirements, eGRC tools, or national laboratory environments.
- Professional certifications that demonstrate practical technical or leadership growth (e.g., Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Certified Ethical Hacker (CEH), or equivalent hands-on credentials).