Security Operations Manager

US101 Guidehouse Inc.

Washington (District of Columbia)

On-site

USD 149,000 - 248,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision
Holidays
Bonus potential
Parental Leave
401(k)
Life Insurance
HSA/FSA & Dependent Care
Learning & Certifications
Mobility Stipend

Job summary

Guidehouse is seeking a seasoned SOC Manager to lead security operations for a Federal Agency, ensuring continuous 24/7 monitoring of critical Oracle-based systems, and coordinating with ISSOs to meet RMF and A&A requirements. The role requires active top-tier certifications, seven-plus years in security, and US citizenship. You will develop detection use cases, run incident response, and report SOC metrics to improve performance; travel up to 10% is expected.

Qualifications

  • Minimum of seven years in security operations.
  • Active CISSP, GCIA, or equivalent certification.
  • U.S. citizenship and ability to obtain SECRET clearance.

Responsibilities

  • Oversee 24/7 security operations and monitoring.
  • Lead RMF and A&A activities with ISSOs.
  • Configure and operate SIEM processes for Oracle systems.
  • Develop detection use cases, playbooks, and investigative procedures.
  • Coordinate incident response actions with ISSOs and incident response teams.

Skills

SOC management
SIEM expertise
EDR tools
SOAR automation
Leadership
KPIs & metrics
Technical communication
Incident response coordination

Education

Bachelor's degree

Tools

CISSP/GCIA certification

Job description

Job Family: Cyber Consulting Travel Required: Up to 10% Clearance Required: Active Secret

Seeking highly skilled and versatile SOC Manager, to assist in providing comprehensive cybersecurity support services to protect critical consular systems and data for a large Federal Agency. The SOC Manager serves as the primary technical lead for all security operations and monitoring activities under this call order. Oversees 24/7 operational coverage. Coordinates directly with the ISSOs to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities. Ensures all security operations activities align with ISSO-approved security baselines and Department policies.

What You Will Do:
  • Implement and operate Security Information and Event Management (SIEM) processes for covered Oracle systems: Configure SIEM to collect security events from Oracle systems
  • Develop correlation rules for Oracle-specific security events - Monitor SIEM alerts and investigate security anomalies
  • Provide SIEM data and alerts to ISSO(s) for incident response coordination
  • Conduct Open-Source Intelligence Threat (OSINT) monitoring for Oracle-specific threats: Monitor Oracle security advisories and vulnerability disclosures Track threat intelligence related to Oracle database attacks Provide threat intelligence summaries to ISSOs weekly
  • Perform digital forensics and log analysis for covered systems: Analyze Oracle audit logs, AVDF reports, and PUM access logs Investigate security anomalies and suspicious activities Provide forensic findings to ISSO and incident response teams
  • Support ISSO-led incident response activities: Execute technical incident response actions as directed by ISSO Provide system logs, forensic data, and technical analysis – Implement incident containment and remediation measures per ISSO direction Document incident response actions and provide to ISSO for incident reports
  • Perform operational security posture assessments: Conduct technical security reviews of Oracle system configurations Identify security weaknesses and configuration vulnerabilities Provide assessment findings to ISSO for POA&M development Implement ISSO-directed security improvements
  • Maintain long-term storage of security logs and audit data: Retain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements Ensure log data availability for ISSO-led compliance audits and assessments Provide historical log data to ISSO upon request for correlation and analysis
What You Will Need:
  • Minimum of SEVEN (7)+ years of overall work experience.
  • Bachelors degree from an accredited university.
  • Must have active CISSP, GCIA or equivalent certification.
  • Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse.
  • Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred.
  • US Citizenship is contractually required.
  • Strong familiarity with SIEM platforms, endpoint detection and response (EDR) tools, and SOAR workflow automation.
  • Demonstrated ability to develop and maintain detection use cases, playbooks, and investigative procedures.
  • Experience defining and reporting SOC metrics and KPIs to measure effectiveness and drive operational improvements.
  • Excellent written and verbal communication skills with the ability to communicate technical details to non-technical stakeholders and executive leadership.
  • Proven leadership skills: coaching, performance management, scheduling for 24/7 operations, and handling escalations under pressure.
What Would Be Nice To Have:
  • Master’s in computer science, IT, cybersecurity or related field.
  • Experience working with the Department of State preferred.
Annual Salary Range:

The annual salary range for this position is $149,000.00-$248,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.

What We Offer:
  • Medical, Rx, Dental & Vision Insurance
  • Personal and Family Sick Time & Company Paid Holidays
  • Position may be eligible for a discretionary variable incentive bonus
  • Parental Leave and Adoption Assistance
  • 401(k) Retirement Plan
  • Basic Life & Supplemental Life
  • Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts
  • Short-Term & Long-Term Disability
  • Student Loan PayDown Tuition Reimbursement, Personal Development & Learning Opportunities
  • Skills Development & Certifications
  • Employee Referral Program
  • Corporate Sponsored Events & Community Outreach
  • Emergency Back-Up Childcare Program
  • Mobility Stipend
About Guidehouse

Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets. Built to help clients across industries outwit complexity, the firm brings together approximately 18,000 professionals to achieve lasting impact and shape a meaningful future. guidehouse.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Manager
Security Operations Manager

Guidehouse • United States

On-site
USD 149,000 - 248,000
Medical Insurance
401(k) Retirement Plan
Parental Leave and Adoption Assistance
+2
Security Operations Manager
Security Operations Manager

Guidehouse • Washington

On-site
USD 149,000 - 248,000
Security Analyst – Mid (SecCM – Mid)
Security Analyst – Mid (SecCM – Mid)

Dovel Technologies, Inc • Arlington (VA), Northern (KY)

Hybrid
USD 110,000 - 140,000
Medical, Rx, Dental & Vision Insurance
Parental Leave and Adoption Assistance
401(k) Retirement Plan
+1
Security Analyst – Mid (SecCM – Mid)
Security Analyst – Mid (SecCM – Mid)

Guidehouse • Arlington (VA)

On-site
USD 120,000 - 150,000
Medical, Rx, Dental & Vision Insurance
401(k) Retirement Plan
Parental Leave and Adoption Assistance
+1
Senior Cyber Consultant - ISSO/ISSM
Senior Cyber Consultant - ISSO/ISSM

Dovel Technologies, Inc • Washington

On-site
USD 113,000 - 188,000
Medical Insurance
Dental & Vision
401(k) Plan
+3
Operations Facilitation Specialist
Operations Facilitation Specialist

Dovel Technologies, Inc • McLean (VA)

Hybrid
USD 120,000 - 180,000
Medical
Rx
Dental & Vision Insurance
+4
Cybersecurity Consultant
Cybersecurity Consultant

Dovel Technologies, Inc • United States

On-site
USD 85,000 - 141,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Security Operations Manager (SOC Manager)
Security Operations Manager (SOC Manager)

Connected Logistics • Virginia (MN)

Hybrid
USD 160,000 - 170,000
Health insurance
Dental insurance
Vision insurance
+4
Security Analyst – Mid (SecCM – Mid)
Security Analyst – Mid (SecCM – Mid)

Guidehouse • Virginia (MN)

On-site
USD 110,000 - 140,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Senior Operations Facilitation Manager
Senior Operations Facilitation Manager

Dovel Technologies, Inc • McLean (VA)

Hybrid
USD 170,000 - 210,000
Medical Insurance
Sick Time & Holidays
Parental Leave & Adoption Assistance
+3