Security Operations Manager Paragon Technology Group is seeking an experienced Security Operations Manager (SOC Manager) to serve as the primary technical lead for security operations and monitoring supporting mission-critical Department of State (DOS) systems. The Security Operations Manager will lead and coordinate security operations across Oracle-based enterprise systems, including Oracle Audit Vault/Data Safe (AVDF), Oracle Privileged User Management (PUM), Oracle Database and Engineered Systems, and Oracle Golden Gate. The Security Operations Manager will oversee 24/7 operational coverage for AVDF and PUM systems and after-hours coverage for Oracle Database, Engineered Systems, and Golden Gate. The position will coordinate directly with the DT/EA Information System Security Officer (ISSO) to ensure technical security evidence, operational data, and remediation activities support Risk Management Framework (RMF) and Assessment and Authorization (A&A) requirements. The successful candidate will provide technical leadership to maintain system availability and reliability, ensure compliance with Federal and Department of State cybersecurity requirements, rapidly identify and resolve security incidents, support insider threat detection, and continuously improve security operations and monitoring capabilities. Key Responsibilities
- Serve as the primary technical lead for security operations and monitoring activities and provide day-to-day technical direction to the security operations team.
- Manage and coordinate 24/7 operational coverage for Oracle AVDF and PUM and after-hours operational coverage for Oracle Database and Engineered Systems and Oracle Golden Gate.
- Ensure security operations maintain the availability, reliability, and operational continuity of covered mission-critical systems.
- Coordinate directly with the DT/EA ISSO to provide technical security evidence, operational data, and remediation support for RMF, A&A, continuous monitoring, and POA&M activities.
- Ensure covered systems maintain an operational security posture consistent with Federal and DOS requirements, including NIST SP 800-53 Rev. 5, applicable Executive Orders, OIG directives, DOS security requirements, and ISSO-approved security baselines.
- Lead the detection, analysis, escalation, containment, remediation, and resolution of security incidents and operational security issues.
- Oversee privileged-access management operations, including account provisioning, elevated privilege requests, multifactor authentication, periodic user recertification, inactive account management, and monitoring of privileged-management infrastructure.
- Oversee Oracle security monitoring, audit-data collection, anomaly detection, reporting, and protection of sensitive and personally identifiable information (PII).
- Direct Security Information and Event Management (SIEM) activities for covered Oracle systems, including event collection, correlation rules, alert monitoring, and investigation of security anomalies.
- Oversee Oracle-focused threat intelligence and OSINT monitoring, digital forensics, audit and log analysis, and investigation of suspicious activities.
- Support ISSO-led incident response activities by coordinating technical analysis, containment, remediation, forensic evidence, system logs, and documentation.
- Lead operational security posture assessments to identify configuration weaknesses, vulnerabilities, and other security deficiencies and coordinate corrective actions with the ISSO.
- Oversee development and maintenance of technical security configuration and hardening guides based on DOS-approved standards, applicable DISA STIGs, Oracle security best practices, and ISSO-provided NIST SP 800-53 implementation guidance.
- Ensure configuration changes and security baselines follow established Configuration Management processes and receive required ISSO review and approval.
- Direct vulnerability remediation and patch/security-update management for covered Oracle systems, including testing, deployment, compliance tracking, remediation planning, and reporting.
- Ensure critical vulnerabilities and Known Exploited Vulnerabilities (KEVs) are remediated within DOS-established timeframes.
- Maintain appropriate security-log and audit-data retention and ensure historical information is available to support security investigations, audits, assessments, and compliance activities.
- Support DT/EA's Insider Threat Program through effective use of AVDF, PUM, audit information, privileged-user monitoring, and security use cases.
- Coordinate security-related activities with Government stakeholders, application teams, production support teams, and other DT/EA contractors and vendors.
- Identify opportunities to improve security operations, monitoring capabilities, system performance, automation, procedures, and operational effectiveness.
- Develop and maintain security operations SOPs, runbooks, configuration guides, patch-management procedures, and other technical documentation.
- Support required weekly, monthly, quarterly, incident, root-cause-analysis, and ad hoc reporting by providing accurate security operations metrics, status, trends, risks, and remediation information.
Required Qualifications
- Bachelor's degree and at least eight (8) years of relevant professional experience.
- CISSP, GCIA, or equivalent cybersecurity certification.
- Demonstrated experience leading or managing cybersecurity operations, security monitoring, incident response, or Security Operations Center (SOC) activities.
- Experience supporting enterprise security operations in highly available, mission-critical environments.
- Strong knowledge of cybersecurity operations, including vulnerability management, incident response, SIEM, security monitoring, threat analysis, log analysis, digital forensics, configuration management, and security hardening.
- Working knowledge of NIST SP 800-53 security controls and Federal cybersecurity requirements.
- Experience coordinating cybersecurity activities with ISSOs, security managers, system administrators, engineers, application teams, and other technical stakeholders.
- Demonstrated ability to manage security incidents, establish priorities, coordinate technical resources, and drive issues through resolution in time-sensitive operational environments.
- Experience developing and maintaining security operations procedures, technical documentation, SOPs, runbooks, configuration guides, and operational metrics.
- Strong written and verbal communication skills with the ability to communicate technical security issues, risks, operational status, and recommended actions to technical and management audiences.
- Ability to provide leadership across teams supporting continuous, 24/7, and after-hours operations.
Preferred Qualifications
- Experience supporting Department of State or other Federal Government cybersecurity environments.
- Experience with Oracle Database, Oracle Engineered Systems, Oracle Audit Vault/Data Safe (AVDF), Oracle Privileged User Management (PUM), and/or Oracle Golden Gate.
- Experience with Oracle Identity Manager (OIM), Oracle Access Manager (OAM), Oracle HTTP Server (OHS), or Oracle Unified Directory (OUD).
- Experience implementing and operating SIEM capabilities for Oracle or other enterprise database environments.
- Experience applying DISA Security Technical Implementation Guides (STIGs), Federal security baselines, and enterprise configuration-management requirements.
- Experience supporting RMF, A&A, POA&M remediation, continuous monitoring, and Security Impact Analysis activities from a technical security operations perspective.
- Experience supporting privileged-access management, multifactor authentication, insider-threat monitoring, threat intelligence, and forensic analysis.
- Experience leading cybersecurity operations supporting geographically distributed, mission-critical Federal systems.
Security Requirements
- Must be able to obtain and maintain the security clearance and/or Department of State personnel security eligibility required for the position.
Work Location and Schedule The position may primarily be performed remotely; however, because the Security Operations Manager is designated as Key Personnel, the individual must reside within reasonable commuting distance of the Government facility at State Annex 17 (SA-17), 600 19th Street NW, Washington, D.C., and be available for onsite meetings or mission-critical support as required. Contractor personnel are expected to be available during established core business hours; however, this position is responsible for managing operations that include 24/7 and after-hours coverage and must be available as necessary to respond to critical operational and cybersecurity events.
|