Security Operations Manager (SOC Manager)
Contingent Contract Award
National Capital Region - Remote but must be within 50 miles of D.C. for on-stie performance as requested
Connected Logistics is seeking highly skilled and versatile SOC Manager, to assist in providing the Department of State Directorate of Technology (DT), Enterprise Architecture (EA), Cyber Security Team (CST) comprehensive cybersecurity support services to protect critical consular systems and data. The CST Cyber portfolio ensures compliance with federal mandates including the Federal Information Security Modernization Act (FISMA) and the Risk Management Framework (RMF), encompassing security monitoring, incident response, threat detection, vulnerability management, and continuous authorization activities.
The SOC Manager serves as the primary technical lead for all security operations and monitoring activities under this call order. Oversees 24/7 operational coverage for AVDF and PUM systems and after-hours coverage for Oracle Database, Engineered Systems, and Golden Gate. Coordinates directly with the DT/EA ISSO to ensure technical security evidence, remediation actions, and operational data are delivered in support of RMF and A&A activities. Ensures all security operations activities align with ISSO-approved security baselines and Department policies.
Key Responsibilities
Implement and operate Security Information and Event Management (SIEM) processes for covered Oracle systems:
- Configure SIEM to collect security events from Oracle databases, AVDF, PUM, and Golden Gate
- Develop correlation rules for Oracle-specific security events - Monitor SIEM alerts and investigate security anomalies
- Provide SIEM data and alerts to DT/EA ISSO for incident response coordination
Conduct Open-Source Intelligence Threat (OSINT) monitoring for Oracle-specific threats:
- Monitor Oracle security advisories and vulnerability disclosures
- Track threat intelligence related to Oracle database attacks
- Provide threat intelligence summaries to DT/EA ISSO weekly
Perform digital forensics and log analysis for covered systems:
- Analyze Oracle audit logs, AVDF reports, and PUM access logs
- Investigate security anomalies and suspicious activities
- Provide forensic findings to DT/EA ISSO and incident response teams
Support DT/EA ISSO-led incident response activities:
- Execute technical incident response actions as directed by ISSO
- Provide system logs, forensic data, and technical analysis –
- Implement incident containment and remediation measures per ISSO direction
- Document incident response actions and provide to ISSO for incident reports
Perform operational security posture assessments:
- Conduct technical security reviews of Oracle system configurations
- Identify security weaknesses and configuration vulnerabilities
- Provide assessment findings to DT/EA ISSO for POA&M development
- Implement ISSO-directed security improvements
Maintain long-term storage of security logs and audit data:
- Retain Oracle audit logs, AVDF data, and PUM access logs per DOS retention requirements
- Ensure log data availability for ISSO-led compliance audits and assessments
- Provide historical log data to ISSO upon request for correlation and analysis