Security Operations Manager

Guidehouse

United States

On-site

USD 149,000 - 248,000

Full time

21 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical Insurance
401(k) Retirement Plan
Parental Leave and Adoption Assistance
Tuition Reimbursement
Mobility Stipend

Job summary

Guidehouse is seeking a skilled SOC Manager to lead 24/7 security operations for critical consular systems at a Federal Agency. You will coordinate with ISSOs, maintain baselines, and ensure RMF and A&A requirements are met.

Required CISSP/GCIA, active SECRET clearance, and 7+ years of experience. Salary ranges reflect extensive federal contracting experience and on-site duties in the United States.

Qualifications

  • Minimum of SEVEN (7) years of overall work experience.
  • Bachelor's degree from an accredited university.
  • Active CISSP, GCIA or equivalent certification required.
  • Must obtain and maintain a Federal or DoD SECRET clearance; onboard with Guidehouse after adjudication.
  • US Citizenship is required by contract.
  • Strong familiarity with SIEM platforms, EDR tools, and SOAR workflow automation.
  • Ability to develop and maintain detection use cases, playbooks, and investigative procedures.
  • Experience defining and reporting SOC metrics and KPIs to improve operations.
  • Excellent written and verbal communication for technical and executive audiences.
  • Proven leadership: coaching, performance management, and 24/7 operations management.

Responsibilities

  • Configure SIEM to collect security events from Oracle systems.
  • Develop correlation rules for Oracle security events and monitor alerts.
  • Provide SIEM data to ISSOs for incident response coordination.
  • Conduct OSINT monitoring for Oracle threats.
  • Monitor Oracle advisories and vulnerability disclosures.
  • Track threat intel on Oracle database attacks; share summaries weekly.
  • Perform forensics and log analysis for covered systems.
  • Support ISSO-led incident response actions and containment.
  • Document incident actions for reports.
  • Conduct technical security posture reviews and POA&M development.
  • Maintain long-term storage of logs per retention rules.
  • Provide historical log data for correlation and analysis.

Skills

SIEM monitoring
EDR familiarity
SOAR automation
Detection use cases
Playbooks
Investigative procedures
SOC KPIs
Leadership
Communication

Education

Bachelor's degree

Tools

SIEM platforms
EDR tools
SOAR

Job description

Job Family

Cyber Consulting

Travel Required

Up to 10%

Clearance Required

Active Secret

Seeking highly skilled and versatile SOC Manager, to assist in providing comprehensive cybersecurity support services to protect critical consular systems and data for a large Federal Agency. The SOC Manager serves as the primary technical lead for all security operations and monitoring activities under this call order. Oversees 24/7 operational coverage. Coordinates directly with the ISSOs to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities. Ensures all security operations activities align with ISSO-approved security baselines and Department policies.

What You Will Do
  • Configure SIEM to collect security events from Oracle systems
  • Develop correlation rules for Oracle-specific security events - Monitor SIEM alerts and investigate security anomalies
  • Provide SIEM data and alerts to ISSO(s) for incident response coordination
  • Conduct Open-Source Intelligence Threat (OSINT) monitoring for Oracle-specific threats:
  • Monitor Oracle security advisories and vulnerability disclosures
  • Track threat intelligence related to Oracle database attacks
  • Provide threat intelligence summaries to ISSOs weekly
  • Perform digital forensics and log analysis for covered systems:
  • Analyze Oracle audit logs, AVDF reports, and PUM access logs
  • Investigate security anomalies and suspicious activities
  • Provide forensic findings to ISSO and incident response teams
  • Support ISSO-led incident response activities:
  • Execute technical incident response actions as directed by ISSO
  • Provide system logs, forensic data, and technical analysis -
  • Implement incident containment and remediation measures per ISSO direction
  • Document incident response actions and provide to ISSO for incident reports
  • Perform operational security posture assessments:
  • Conduct technical security reviews of Oracle system configurations
  • Identify security weaknesses and configuration vulnerabilities
  • Provide assessment findings to ISSO for POA&M development
  • Implement ISSO-directed security improvements
  • Maintain long-term storage of security logs and audit data:
  • Retain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements
  • Ensure log data availability for ISSO-led compliance audits and assessments
  • Provide historical log data to ISSO upon request for correlation and analysis
What You Will Need
  • Minimum of SEVEN (7)+ years of overall work experience.
  • Bachelors degree from an accredited university.
  • Must have active CISSP, GCIA or equivalent certification
  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred.
  • US Citizenship is contractually required.
  • Strong familiarity with SIEM platforms, endpoint detection and response (EDR) tools, and SOAR workflow automation.
  • Demonstrated ability to develop and maintain detection use cases, playbooks, and investigative procedures.
  • Experience defining and reporting SOC metrics and KPIs to measure effectiveness and drive operational improvements.
  • Excellent written and verbal communication skills with the ability to communicate technical details to non-technical stakeholders and executive leadership.
  • Proven leadership skills: coaching, performance management, scheduling for 24/7 operations, and handling escalations under pressure.
What Would Be Nice To Have
  • Master’s in computer science, IT, cybersecurity or related field
  • Experience working with the Department of State preferred
Annual Salary Range

The annual salary range for this position is $149,000.00-$248,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.

What We Offer

Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace.

Benefits Include
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown
  • Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse

Guidehouse is an Equal Opportunity Employer-Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation.

Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco.

If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation.

All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process.

If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties.

Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Manager
Security Operations Manager

US101 Guidehouse Inc. • Washington

On-site
USD 149,000 - 248,000
Medical, Dental, Vision
Holidays
Bonus potential
+6
Security Operations Manager
Security Operations Manager

Guidehouse • Washington

On-site
USD 149,000 - 248,000
Operations Facilitation Specialist
Operations Facilitation Specialist

Guidehouse • Arlington (VA)

On-site
USD 120,000 - 160,000
Medical, Dental & Vision Insurance
Parental Leave and Adoption Assistance
401(k) Retirement Plan
+2
Security Analyst – Mid (SecCM – Mid)
Security Analyst – Mid (SecCM – Mid)

Guidehouse • Virginia (MN)

On-site
USD 110,000 - 140,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Senior Data Engineer
Senior Data Engineer

Guidehouse • Arlington (VA)

Hybrid
USD 113,000 - 188,000
Senior Data Engineer
Senior Data Engineer

Guidehouse • Washington

Hybrid
USD 113,000 - 188,000
Health insurance
401(k) Retirement Plan
Tuition Reimbursement
Data Engineer
Data Engineer

Guidehouse • Washington

Hybrid
USD 85,000 - 141,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Tuition Reimbursement
+1
Cybersecurity GRC Program Manager
Cybersecurity GRC Program Manager

Guidehouse • Arlington (VA)

On-site
USD 130,000 - 216,000
Medical Insurance
401(k) Retirement Plan
Parental Leave
+1
Data Engineer
Data Engineer

Guidehouse • Arlington (VA)

Hybrid
USD 85,000 - 141,000
Data Engineer
Data Engineer

Guidehouse • McLean (VA)

Hybrid
USD 85,000 - 141,000
Health Insurance
401(k) Plan
Parental Leave
+3