Security Operations Manager; SOC Manager
Listed on 2026-09-13
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, Network Security
Contingent Contract Award
National Capital Region
- Remote but must be within 50 miles of D.C. for on-stie performance as requested
Connected Logistics is seeking highly skilled and versatile SOC Manager, to assist in providing the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities.
TheSOC Manager
serves as the primary technical lead for all security operations and monitoring activities under this call order. Oversees 24/7 operational coverage for AVDF and PUM systems and after-hours coverage for Oracle Database, Engineered Systems, and Golden Gate. Coordinates directly with the DT/EA ISSO to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities.
Ensures all security operations activities align with ISSO-approved security baselines and Department policies.
- Configure SIEM to collect security events from Oracle databases, AVDF, PUM, and Golden Gate
- Develop correlation rules for Oracle-specific security events
- Monitor SIEM alerts and investigate security anomalies - Provide SIEM data and alerts to DT/EA ISSO for incident response coordination
- Monitor Oracle security advisories and vulnerability disclosures
- Track threat intelligence related to Oracle database attacks
- Provide threat intelligence summaries to DT/EA ISSO weekly
- Analyze Oracle audit logs, AVDF reports, and PUM access logs
- Investigate security anomalies and suspicious activities
- Provide forensic findings to DT/EA ISSO and incident response teams
- Execute technical incident response actions as directed by ISSO
- Provide system logs, forensic data, and technical analysis –
- Implement incident containment and remediation measures per ISSO direction
- Document incident response actions and provide to ISSO for incident reports
- Conduct technical security reviews of Oracle system configurations
- Identify security weaknesses and configuration vulnerabilities
- Provide assessment findings to DT/EA ISSO for POA&M development
- Implement ISSO-directed security improvements
- Retain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements
- Ensure log data availability for ISSO-led compliance audits and assessments
- Provide historical log data to ISSO upon request for correlation and analysis
- Bachelor’s in computer science, IT, cybersecurity or related field
- 8 years’ experience security operations
- Must have active CISSP, GCIA or equivalent
- Current Secret clearance
- Experience working with the DoS preferred
- Have demonstrated experience managing 24/7/365 SOC operations
- Have demonstrated experience with SIEM platforms and threat intelligence
The anticipated salary range for this position is $-$ USD
. This is a good-faith range based on factors such as your experience, geographic location, and any applicable contractual requirements, and may vary slightly.
Beyond…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).