{"schemaVersion":"jobsearcher.job.v1","id":"a890408e9d8d75f5274ece4c","url":"https://jobsearcher.com/jobs/a890408e9d8d75f5274ece4c","canonicalUrl":"https://jobsearcher.com/jobs/a890408e9d8d75f5274ece4c","title":"Security Operations Manager","description":"Job Family:\n\nCyber Consulting\n\nTravel Required:\n\nUp to 10%\n\nClearance Required:\n\nActive Secret\n\nSeeking highly skilled and versatile SOC Manager, to assist in providing  comprehensive cybersecurity support services to protect critical consular systems and data for a large Federal Agency. The SOC Manager serves as the primary technical lead for all security operations and monitoring activities under this call order. Oversees 24/7 operational coverage. Coordinates directly with the ISSOs to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities. Ensures all security operations activities align with ISSO-approved security baselines and Department policies.\n\nWhat You Will Do:\n\nImplement and operate Security Information and Event Management (SIEM) processes for covered Oracle systems:\n\nConfigure SIEM to collect security events from Oracle systems\nDevelop correlation rules for Oracle-specific security events - Monitor SIEM alerts and investigate security anomalies\nProvide SIEM data and alerts to ISSO(s) for incident response coordination\nConduct Open-Source Intelligence Threat (OSINT) monitoring for Oracle-specific threats:\nMonitor Oracle security advisories and vulnerability disclosures\nTrack threat intelligence related to Oracle database attacks\nProvide threat intelligence summaries to ISSOs weekly\nPerform digital forensics and log analysis for covered systems:\nAnalyze Oracle audit logs, AVDF reports, and PUM access logs\nInvestigate security anomalies and suspicious activities\nProvide forensic findings to ISSO and incident response teams\nSupport ISSO-led incident response activities:\nExecute technical incident response actions as directed by ISSO\nProvide system logs, forensic data, and technical analysis –\nImplement incident containment and remediation measures per ISSO direction\nDocument incident response actions and provide to ISSO for incident reports\nPerform operational security posture assessments:\nConduct technical security reviews of Oracle system configurations\nIdentify security weaknesses and configuration vulnerabilities\nProvide assessment findings to ISSO for POA&M development\nImplement ISSO-directed security improvements\nMaintain long-term storage of security logs and audit data:\nRetain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements\nEnsure log data availability for ISSO-led compliance audits and assessments\nProvide historical log data to ISSO upon request for correlation and analysis\n\nWhat You Will Need:\n\nMinimum of SEVEN (7)+ years of overall work experience.\nBachelors degree from an accredited university.\nMust have active CISSP, GCIA or equivalent certification\nMust be able to OBTAIN and MAINTAIN a Federal or DoD \"SECRET\" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE \"SECRET\" or higher-level clearance are preferred.\nUS Citizenship is contractually required.\nStrong familiarity with SIEM platforms, endpoint detection and response (EDR) tools, and SOAR workflow automation.\nDemonstrated ability to develop and maintain detection use cases, playbooks, and investigative procedures.\nExperience defining and reporting SOC metrics and KPIs to measure effectiveness and drive operational improvements.\nExcellent written and verbal communication skills with the ability to communicate technical details to non-technical stakeholders and executive leadership.\nProven leadership skills: coaching, performance management, scheduling for 24/7 operations, and handling escalations under pressure.\n\nWhat Would Be Nice To Have:\n\nMaster’s in computer science, IT, cybersecurity or related field\nExperience working with the Department of State preferred\n\nThe annual salary range for this position is $149,000.00-$248,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.\n\nWhat We Offer:\n\nGuidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.\n\nBenefits include:\n\nMedical, Rx, Dental & Vision Insurance\n\nPersonal and Family Sick Time & Company Paid Holidays\n\nPosition may be eligible for a discretionary variable incentive bonus\n\nParental Leave and Adoption Assistance\n\n401(k) Retirement Plan\n\nBasic Life & Supplemental Life\n\nHealth Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts\n\nShort-Term & Long-Term Disability\n\nStudent Loan PayDown\n\nTuition Reimbursement, Personal Development & Learning Opportunities\n\nSkills Development & Certifications\n\nEmployee Referral Program\n\nCorporate Sponsored Events & Community Outreach\n\nEmergency Back-Up Childcare Program\n\nMobility Stipend\n\nAbout Guidehouse\n\nGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.\n\nGuidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.\n\nIf you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.\n\nAll communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.\n\nIf any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.\n\nGuidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.","company":"Guidehouse","rawCompany":"guidehouse","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-09-12T10:20:10.480Z","occupations":[{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"928110","title":"National Security","slug":"national-security"},{"code":"922190","title":"Other Justice, Public Order, and Safety Activities","slug":"other-justice-public-order-and-safety-activities"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Security Operations Manager","description":"Job Family:\n\nCyber Consulting\n\nTravel Required:\n\nUp to 10%\n\nClearance Required:\n\nActive Secret\n\nSeeking highly skilled and versatile SOC Manager, to assist in providing  comprehensive cybersecurity support services to protect critical consular systems and data for a large Federal Agency. The SOC Manager serves as the primary technical lead for all security operations and monitoring activities under this call order. Oversees 24/7 operational coverage. Coordinates directly with the ISSOs to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities. Ensures all security operations activities align with ISSO-approved security baselines and Department policies.\n\nWhat You Will Do:\n\nImplement and operate Security Information and Event Management (SIEM) processes for covered Oracle systems:\n\nConfigure SIEM to collect security events from Oracle systems\nDevelop correlation rules for Oracle-specific security events - Monitor SIEM alerts and investigate security anomalies\nProvide SIEM data and alerts to ISSO(s) for incident response coordination\nConduct Open-Source Intelligence Threat (OSINT) monitoring for Oracle-specific threats:\nMonitor Oracle security advisories and vulnerability disclosures\nTrack threat intelligence related to Oracle database attacks\nProvide threat intelligence summaries to ISSOs weekly\nPerform digital forensics and log analysis for covered systems:\nAnalyze Oracle audit logs, AVDF reports, and PUM access logs\nInvestigate security anomalies and suspicious activities\nProvide forensic findings to ISSO and incident response teams\nSupport ISSO-led incident response activities:\nExecute technical incident response actions as directed by ISSO\nProvide system logs, forensic data, and technical analysis –\nImplement incident containment and remediation measures per ISSO direction\nDocument incident response actions and provide to ISSO for incident reports\nPerform operational security posture assessments:\nConduct technical security reviews of Oracle system configurations\nIdentify security weaknesses and configuration vulnerabilities\nProvide assessment findings to ISSO for POA&M development\nImplement ISSO-directed security improvements\nMaintain long-term storage of security logs and audit data:\nRetain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements\nEnsure log data availability for ISSO-led compliance audits and assessments\nProvide historical log data to ISSO upon request for correlation and analysis\n\nWhat You Will Need:\n\nMinimum of SEVEN (7)+ years of overall work experience.\nBachelors degree from an accredited university.\nMust have active CISSP, GCIA or equivalent certification\nMust be able to OBTAIN and MAINTAIN a Federal or DoD \"SECRET\" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE \"SECRET\" or higher-level clearance are preferred.\nUS Citizenship is contractually required.\nStrong familiarity with SIEM platforms, endpoint detection and response (EDR) tools, and SOAR workflow automation.\nDemonstrated ability to develop and maintain detection use cases, playbooks, and investigative procedures.\nExperience defining and reporting SOC metrics and KPIs to measure effectiveness and drive operational improvements.\nExcellent written and verbal communication skills with the ability to communicate technical details to non-technical stakeholders and executive leadership.\nProven leadership skills: coaching, performance management, scheduling for 24/7 operations, and handling escalations under pressure.\n\nWhat Would Be Nice To Have:\n\nMaster’s in computer science, IT, cybersecurity or related field\nExperience working with the Department of State preferred\n\nThe annual salary range for this position is $149,000.00-$248,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.\n\nWhat We Offer:\n\nGuidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.\n\nBenefits include:\n\nMedical, Rx, Dental & Vision Insurance\n\nPersonal and Family Sick Time & Company Paid Holidays\n\nPosition may be eligible for a discretionary variable incentive bonus\n\nParental Leave and Adoption Assistance\n\n401(k) Retirement Plan\n\nBasic Life & Supplemental Life\n\nHealth Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts\n\nShort-Term & Long-Term Disability\n\nStudent Loan PayDown\n\nTuition Reimbursement, Personal Development & Learning Opportunities\n\nSkills Development & Certifications\n\nEmployee Referral Program\n\nCorporate Sponsored Events & Community Outreach\n\nEmergency Back-Up Childcare Program\n\nMobility Stipend\n\nAbout Guidehouse\n\nGuidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.\n\nGuidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.\n\nIf you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.\n\nAll communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.\n\nIf any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.\n\nGuidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.","datePosted":"2026-09-12T10:20:10.480Z","dateModified":"2026-09-12T10:20:10.480Z","hiringOrganization":{"@type":"Organization","name":"Guidehouse","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a890408e9d8d75f5274ece4c"},"url":"https://jobsearcher.com/jobs/a890408e9d8d75f5274ece4c"}}