Leidos Holdings Inc.-posted about 1 month ago
Full-time • Mid Level
Washington, DC
11-50 employees
Professional, Scientific, and Technical Services

The Security Operations Manager leads all operational security activities required to maintain the security posture of Consular Affairs (CA) production systems in accordance with Department of State (DoS) Information Assurance (IA) and Compliance policies. This role oversees the Security Operations team responsible for A&A support, continuous monitoring, incident response, patch and vulnerability management, POA&M remediation, cyber hygiene, SIEM operations, and maintenance of standard security configurations across all CA environments. The Security Operations Manager ensures compliance with DoS security controls, standards, and Diplomatic Technology IA accreditation requirements while coordinating with ISSO teams, engineering groups, and external stakeholders. This position requires strong leadership, deep IA and compliance experience, and the ability to manage complex security operations in a global enterprise production environment.

  • Lead and manage the Security Operations team responsible for maintaining CA production security posture across domestic and overseas environments.
  • Ensure compliance with DoS IA and security policies, NIST SP 800-53, IRM/IA accreditation requirements, and CA/CST ISSO guidance.
  • Oversee and support all phases of the Assessment & Authorization (A&A) process, including continuous monitoring, evidence collection, documentation, and remediation tracking.
  • Manage and maintain POA&M remediation, ensuring timely updates, closure of vulnerabilities, and compliance with required reporting frequency.
  • Oversee security monitoring, threat detection, digital forensics support, centralized logging, SIEM administration, and correlation analysis.
  • Lead incident response operations, including investigation, containment, remediation, reporting, and coordination with DoS and interagency stakeholders.
  • Maintain standard security configurations, Group Policy Object (GPO) compliance, enclave/network segregation support, and secure baseline management.
  • Direct patch and security update operations, including deployment, compliance tracking, failure remediation, and documentation.
  • Ensure compliance with DoS patching timelines, vulnerability mitigation rules, and Notification Bulletin requirements.
  • Support cyber hygiene assessments, vulnerability scans, risk mitigation activities, and validation of implemented security controls.
  • Develop and maintain security diagrams, operational documentation, SOPs, and policies.
  • Assist with security tests and audits, ensuring CA systems are properly configured and security controls operate as intended.
  • Coordinate with CA/CST ISSO, engineering teams, operations centers, and external organizations to support enterprise security strategy, incident coordination, and compliance initiatives.
  • Active Top Secret (TS) clearance.
  • Master's degree and 15+ years of prior relevant experience in cybersecurity, information assurance, security operations, or related IT disciplines. In lieu of degree, 20+ years experience is required.
  • Certified Information Systems Security Professional (CISSP) certification.
  • Demonstrated experience managing and leading security operations staff in an enterprise production environment of similar size, scope, and complexity.
  • Proven experience managing information security risks and completing the full Assessment & Authorization (A&A) process, including achieving an Authority to Operate (ATO) for cloud or hybrid environments.
  • Strong experience with continuous monitoring, vulnerability management, incident response, centralized logging, and SIEM operations.
  • Experience with NIST SP 800-53 security controls, IA compliance frameworks, and accreditation processes aligned with DoS IRM/IA.
  • Demonstrated experience maintaining secure baselines, STIG/CSH compliance, Group Policy Object (GPO) enforcement, and secure configuration management.
  • Experience leading enterprise patch management operations, deploying security updates, conducting remediation, and maintaining compliance with DoS patching timelines.
  • Experience with POA&M lifecycle management, remediation tracking, and reporting activities.
  • Experience working with DoS security policies, DS guidance, and IRM/IA processes.
  • Demonstrated experience with encryption devices, cryptographic procedures, and secure data handling across enterprise networks.
  • Experience supporting or administering SIEM platforms (Splunk, ArcSight, QRadar, Elastic, etc.).
  • Experience conducting digital forensics, log analysis, threat correlation, and OSINT-aligned security investigations.
  • Experience with STIGs, secure configuration guides, and CA-specific baseline development.
  • Experience with patch management systems, automation tools, antivirus/EDR management, and vulnerability scanning platforms (e.g., Tenable, Qualys).
  • Experience supporting large-scale enterprise environments involving cloud, hybrid, and on-premises security architectures.
  • Prior experience supporting Department of State (DoS), FBI, DHS, or Intelligence Community (IC) security environments is highly preferred.
  • CISM (Certified Information Security Manager)
  • GIAC Certifications (GCIH, GCIA, GCFA, GCED, etc.)
  • Security+, CySA+, or CASP+
  • Certified Ethical Hacker (CEH)
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service