Jobs · Management · Virginia

Security Operations Manager (SOC Manager)

Connected Logistics · Virginia, United States · 2 wk ago
Management$160k–$170k/yrFull-time

About the role

Connected Logistics is seeking a highly skilled and versatile SOC Manager to provide the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) with comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities. The SOC Manager serves as the primary technical lead for all security operations and monitoring activities under this call order.

Responsibilities

  • Oversee 24/7 operational coverage for AVDF and PUM systems and after-hours coverage for Oracle Database, Engineered Systems, and Golden Gate.
  • Coordinate directly with the DT/EA ISSO to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities.
  • Ensure all security operations activities align with ISSO-approved security baselines and Department policies.

SIEM and Security Monitoring

  • Implement and operate Security Information and Event Management (SIEM) processes for covered Oracle systems:
    • Configure SIEM to collect security events from Oracle databases, AVDF, PUM, and Golden Gate.
    • Develop correlation rules for Oracle-specific security events.
    • Monitor SIEM alerts and investigate security anomalies.
    • Provide SIEM data and alerts to DT/EA ISSO for incident response coordination.

Threat Intelligence

  • Conduct Open-Source Intelligence Threat (OSINT) Monitoring for Oracle-specific Threats:
    • Monitor Oracle security advisories and vulnerability disclosures.
    • Track threat intelligence related to Oracle database attacks.
    • Provide threat intelligence summaries to DT/EA ISSO weekly.

Digital Forensics and Log Analysis

  • Analyze Oracle audit logs, AVDF reports, and PUM access logs.
  • Investigate security anomalies and suspicious activities.
  • Provide forensic findings to DT/EA ISSO and incident response teams.

Incident Response Support

  • Execute technical incident response actions as directed by ISSO.
  • Provide system logs, forensic data, and technical analysis.
  • Implement incident containment and remediation measures per ISSO direction.
  • Document incident response actions and provide to ISSO for incident reports.

Operational Security Posture Assessments

  • Conduct technical security reviews of Oracle system configurations.
  • Identify security weaknesses and configuration vulnerabilities.
  • Provide assessment findings to DT/EA ISSO for POA&M development.
  • Implement ISSO-directed security improvements.

Log Retention and Compliance

  • Maintain long-term storage of security logs and audit data:
    • Retain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements.
    • Ensure log data availability for ISSO-led compliance audits and assessments.
    • Provide historical log data to ISSO upon request for correlation and analysis.

Requirements

  • Bachelor’s in computer science, IT, cybersecurity or related field.
  • 8 years’ experience.
  • Must have active CISSP, GCIA or equivalent.
  • Current Secret clearance.
  • Experience working with the DoS preferred.

Pay

The anticipated salary range for this position is $160,000.00–$170,000.00 USD.

Benefits

  • Health, dental, vision, life, and disability insurance.
  • 401(k) package.
  • Generous Paid Time Off.

Similar jobs