Security Operations Manager

Paragon Technology Group

Washington (District of Columbia)

Hybrid

USD 140,000 - 180,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Paragon Technology Group seeks an experienced Security Operations Manager to lead 24/7 security operations for Oracle AVDF, PUM, Database, Engineered Systems, and Oracle Golden Gate, ensuring availability and compliance for DOS systems.

The role coordinates with the ISSO to support RMF and A&A, oversees incident response, privileged-access management, SIEM, and threat monitoring, and develops SOPs and runbooks to strengthen the security posture.

Qualifications

  • Bachelor's degree and at least eight years of relevant professional experience.
  • CISSP, GCIA, or equivalent cybersecurity certification.
  • Experience leading or managing cybersecurity operations, security monitoring, incident response, or SOC activities.
  • Experience supporting enterprise security operations in highly available, mission-critical environments.
  • Strong knowledge of cybersecurity operations, including vulnerability management, incident response, SIEM, log analysis, digital forensics, and configuration management.
  • Working knowledge of NIST SP 800-53 security controls and Federal cybersecurity requirements.

Responsibilities

  • Serve as the primary technical lead for security operations and monitoring activities and provide day-to-day technical direction to the security operations team.
  • Manage and coordinate 24/7 operational coverage for Oracle AVDF and PUM and after-hours coverage for Oracle Database and Engineered Systems and Oracle Golden Gate.
  • Ensure security operations maintain the availability, reliability, and operational continuity of covered mission-critical systems.
  • Coordinate with the ISSO to provide technical security evidence, operational data, and remediation support for RMF, A&A, continuous monitoring, and POA&M.
  • Lead detection, analysis, escalation, containment, remediation, and resolution of security incidents and operational security issues.
  • Oversee privileged-access management operations including provisioning, MFA, recertification, and monitoring of privileged infrastructure.

Skills

CISSP
GCIA
Cybersecurity leadership
Incident response
Security operations
Threat analysis

Education

Bachelor's degree

Tools

Oracle AVDF
Oracle PUM
Oracle Golden Gate
SIEM

Job description

Paragon Technology Group is seeking an experienced Security Operations Manager (SOC Manager) to serve as the primary technical lead for security operations and monitoring supporting mission-critical Department of State (DOS) systems. The Security Operations Manager will lead and coordinate security operations across Oracle-based enterprise systems, including Oracle Audit Vault/Data Safe (AVDF), Oracle Privileged User Management (PUM), Oracle Database and Engineered Systems, and Oracle Golden Gate.


The Security Operations Manager will oversee 24/7 operational coverage for AVDF and PUM systems and after-hours coverage for Oracle Database, Engineered Systems, and Golden Gate. The position will coordinate directly with the DT/EA Information System Security Officer (ISSO) to ensure technical security evidence, operational data, and remediation activities support Risk Management Framework (RMF) and Assessment and Authorization (A&A) requirements.


The successful candidate will provide technical leadership to maintain system availability and reliability, ensure compliance with Federal and Department of State cybersecurity requirements, rapidly identify and resolve security incidents, support insider threat detection, and continuously improve security operations and monitoring capabilities.


Key Responsibilities


  • Serve as the primary technical lead for security operations and monitoring activities and provide day-to-day technical direction to the security operations team.

  • Manage and coordinate 24/7 operational coverage for Oracle AVDF and PUM and after-hours operational coverage for Oracle Database and Engineered Systems and Oracle Golden Gate.

  • Ensure security operations maintain the availability, reliability, and operational continuity of covered mission-critical systems.

  • Coordinate directly with the DT/EA ISSO to provide technical security evidence, operational data, and remediation support for RMF, A&A, continuous monitoring, and POA&M activities.

  • Ensure covered systems maintain an operational security posture consistent with Federal and DOS requirements, including NIST SP 800-53 Rev. 5, applicable Executive Orders, OIG directives, DOS security requirements, and ISSO-approved security baselines.

  • Lead the detection, analysis, escalation, containment, remediation, and resolution of security incidents and operational security issues.

  • Oversee privileged-access management operations, including account provisioning, elevated privilege requests, multifactor authentication, periodic user recertification, inactive account management, and monitoring of privileged-management infrastructure.

  • Oversee Oracle security monitoring, audit-data collection, anomaly detection, reporting, and protection of sensitive and personally identifiable information (PII).

  • Direct Security Information and Event Management (SIEM) activities for covered Oracle systems, including event collection, correlation rules, alert monitoring, and investigation of security anomalies.

  • Oversee Oracle-focused threat intelligence and OSINT monitoring, digital forensics, audit and log analysis, and investigation of suspicious activities.

  • Support ISSO-led incident response activities by coordinating technical analysis, containment, remediation, forensic evidence, system logs, and documentation.

  • Lead operational security posture assessments to identify configuration weaknesses, vulnerabilities, and other security deficiencies and coordinate corrective actions with the ISSO.

  • Oversee development and maintenance of technical security configuration and hardening guides based on DOS-approved standards, applicable DISA STIGs, Oracle security best practices, and ISSO-provided NIST SP 800-53 implementation guidance.

  • Ensure configuration changes and security baselines follow established Configuration Management processes and receive required ISSO review and approval.

  • Direct vulnerability remediation and patch/security-update management for covered Oracle systems, including testing, deployment, compliance tracking, remediation planning, and reporting.

  • Ensure critical vulnerabilities and Known Exploited Vulnerabilities (KEVs) are remediated within DOS-established timeframes.

  • Maintain appropriate security-log and audit-data retention and ensure historical information is available to support security investigations, audits, assessments, and compliance activities.

  • Support DT/EA's Insider Threat Program through effective use of AVDF, PUM, audit information, privileged-user monitoring, and security use cases.

  • Coordinate security-related activities with Government stakeholders, application teams, production support teams, and other DT/EA contractors and vendors.

  • Identify opportunities to improve security operations, monitoring capabilities, system performance, automation, procedures, and operational effectiveness.

  • Develop and maintain security operations SOPs, runbooks, configuration guides, patch-management procedures, and other technical documentation.

  • Support required weekly, monthly, quarterly, incident, root-cause-analysis, and ad hoc reporting by providing accurate security operations metrics, status, trends, risks, and remediation information.


Required Qualifications


  • Bachelor's degree and at least eight (8) years of relevant professional experience.

  • CISSP, GCIA, or equivalent cybersecurity certification.

  • Demonstrated experience leading or managing cybersecurity operations, security monitoring, incident response, or Security Operations Center (SOC) activities.

  • Experience supporting enterprise security operations in highly available, mission-critical environments.

  • Strong knowledge of cybersecurity operations, including vulnerability management, incident response, SIEM, security monitoring, threat analysis, log analysis, digital forensics, configuration management, and security hardening.

  • Working knowledge of NIST SP 800-53 security controls and Federal cybersecurity requirements.

  • Experience coordinating cybersecurity activities with ISSOs, security managers, system administrators, engineers, application teams, and other technical stakeholders.

  • Demonstrated ability to manage security incidents, establish priorities, coordinate technical resources, and drive issues through resolution in time-sensitive operational environments.

  • Experience developing and maintaining security operations procedures, technical documentation, SOPs, runbooks, configuration guides, and operational metrics.

  • Strong written and verbal communication skills with the ability to communicate technical security issues, risks, operational status, and recommended actions to technical and management audiences.

  • Ability to provide leadership across teams supporting continuous, 24/7, and after-hours operations.


Preferred Qualifications


  • Experience supporting Department of State or other Federal Government cybersecurity environments.

  • Experience with Oracle Database, Oracle Engineered Systems, Oracle Audit Vault/Data Safe (AVDF), Oracle Privileged User Management (PUM), and/or Oracle Golden Gate.

  • Experience with Oracle Identity Manager (OIM), Oracle Access Manager (OAM), Oracle HTTP Server (OHS), or Oracle Unified Directory (OUD).

  • Experience implementing and operating SIEM capabilities for Oracle or other enterprise database environments.

  • Experience applying DISA Security Technical Implementation Guides (STIGs), Federal security baselines, and enterprise configuration-management requirements.

  • Experience supporting RMF, A&A, POA&M remediation, continuous monitoring, and Security Impact Analysis activities from a technical security operations perspective.

  • Experience supporting privileged-access management, multifactor authentication, insider-threat monitoring, threat intelligence, and forensic analysis.

  • Experience leading cybersecurity operations supporting geographically distributed, mission-critical Federal systems.


Security Requirements


  • Must be able to obtain and maintain the security clearance and/or Department of State personnel security eligibility required for the position.


Work Location and Schedule

The position may primarily be performed remotely; however, because the Security Operations Manager is designated as Key Personnel, the individual must reside within reasonable commuting distance of the Government facility at State Annex 17 (SA-17), 600 19th Street NW, Washington, D.C., and be available for onsite meetings or mission-critical support as required. Contractor personnel are expected to be available during established core business hours; however, this position is responsible for managing operations that include 24/7 and after-hours coverage and must be available as necessary to respond to critical operational and cybersecurity events.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Manager
Security Operations Manager

Paragon Technology Group, Inc. • Washington

Hybrid
USD 140,000 - 190,000
Security Operations Manager (SOC Manager)
Security Operations Manager (SOC Manager)

Connected Logistics • Washington

Hybrid
USD 160,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+4
Security Operations Manager (SOC Manager)
Security Operations Manager (SOC Manager)

Connected Logistics • Springfield (VA)

Hybrid
USD 160,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+4
Program Manager
Program Manager

Paragon Technology Group, Inc. • Washington

On-site
USD 120,000 - 180,000
Cyber Security Lead
Cyber Security Lead

Concept Plus, LLC • Fairfax (VA)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+6
Communication Security Operations Lead
Communication Security Operations Lead

SAIC • Springfield (VA)

Hybrid
USD 160,000 - 200,000
Cyber Security Lead
Cyber Security Lead

Concept-Plus • United States

Remote
USD 140,000 - 190,000
Competitive pay
Health insurance
Dental insurance
+6
Cyber Security Lead
Cyber Security Lead

Concept Plus, LLC • United States

Hybrid
USD 140,000 - 190,000
Competitive pay
Health, dental, and vision insurance
Life insurance
+6
Deputy Program Manager
Deputy Program Manager

Paragon Technology • Washington

On-site
USD 120,000 - 160,000
Senior Security Operations Lead — 24/7 Oracle Security
Senior Security Operations Lead — 24/7 Oracle Security

Paragon Technology Group • Washington

Hybrid
USD 140,000 - 180,000