Security Operations Manager

Posted:
11/20/2025, 12:53:54 AM

Location(s):
District of Columbia, United States ⋅ Washington, District of Columbia, United States

Experience Level(s):
Expert or higher ⋅ Senior

Field(s):
IT & Security

Workplace Type:
Hybrid

Position Overview:

The Security Operations Manager leads all operational security activities required to maintain the security posture of Consular Affairs (CA) production systems in accordance with Department of State (DoS) Information Assurance (IA) and Compliance policies. This role oversees the Security Operations team responsible for A&A support, continuous monitoring, incident response, patch and vulnerability management, POA&M remediation, cyber hygiene, SIEM operations, and maintenance of standard security configurations across all CA environments. The Security Operations Manager ensures compliance with DoS security controls, standards, and Diplomatic Technology IA accreditation requirements while coordinating with ISSO teams, engineering groups, and external stakeholders. This position requires strong leadership, deep IA and compliance experience, and the ability to manage complex security operations in a global enterprise production environment.

Primary Responsibilities:

  • Lead and manage the Security Operations team responsible for maintaining CA production security posture across domestic and overseas environments.

  • Ensure compliance with DoS IA and security policies, NIST SP 800-53, IRM/IA accreditation requirements, and CA/CST ISSO guidance.

  • Oversee and support all phases of the Assessment & Authorization (A&A) process, including continuous monitoring, evidence collection, documentation, and remediation tracking.

  • Manage and maintain POA&M remediation, ensuring timely updates, closure of vulnerabilities, and compliance with required reporting frequency.

  • Oversee security monitoring, threat detection, digital forensics support, centralized logging, SIEM administration, and correlation analysis.

  • Lead incident response operations, including investigation, containment, remediation, reporting, and coordination with DoS and interagency stakeholders.

  • Maintain standard security configurations, Group Policy Object (GPO) compliance, enclave/network segregation support, and secure baseline management.

  • Direct patch and security update operations, including deployment, compliance tracking, failure remediation, and documentation.

  • Ensure compliance with DoS patching timelines, vulnerability mitigation rules, and Notification Bulletin requirements.

  • Support cyber hygiene assessments, vulnerability scans, risk mitigation activities, and validation of implemented security controls.

  • Develop and maintain security diagrams, operational documentation, SOPs, and policies.

  • Assist with security tests and audits, ensuring CA systems are properly configured and security controls operate as intended.

  • Coordinate with CA/CST ISSO, engineering teams, operations centers, and external organizations to support enterprise security strategy, incident coordination, and compliance initiatives.

Basic Qualifications:

  • Active Top Secret (TS) clearance.

  • Master’s degree and 15+ years of prior relevant experience in cybersecurity, information assurance, security operations, or related IT disciplines. In lieu of degree, 20+ years experience is required.

  • Certified Information Systems Security Professional (CISSP) certification.

  • Demonstrated experience managing and leading security operations staff in an enterprise production environment of similar size, scope, and complexity.

  • Proven experience managing information security risks and completing the full Assessment & Authorization (A&A) process, including achieving an Authority to Operate (ATO) for cloud or hybrid environments.

  • Strong experience with continuous monitoring, vulnerability management, incident response, centralized logging, and SIEM operations.

  • Experience with NIST SP 800-53 security controls, IA compliance frameworks, and accreditation processes aligned with DoS IRM/IA.

  • Demonstrated experience maintaining secure baselines, STIG/CSH compliance, Group Policy Object (GPO) enforcement, and secure configuration management.

  • Experience leading enterprise patch management operations, deploying security updates, conducting remediation, and maintaining compliance with DoS patching timelines.

  • Experience with POA&M lifecycle management, remediation tracking, and reporting activities.

Preferred Qualification:

  • Experience working with DoS security policies, DS guidance, and IRM/IA processes.

  • Demonstrated experience with encryption devices, cryptographic procedures, and secure data handling across enterprise networks.

  • Experience supporting or administering SIEM platforms (Splunk, ArcSight, QRadar, Elastic, etc.).

  • Experience conducting digital forensics, log analysis, threat correlation, and OSINT-aligned security investigations.

  • Experience with STIGs, secure configuration guides, and CA-specific baseline development.

  • Experience with patch management systems, automation tools, antivirus/EDR management, and vulnerability scanning platforms (e.g., Tenable, Qualys).

  • Experience supporting large-scale enterprise environments involving cloud, hybrid, and on-premises security architectures.

  • Prior experience supporting Department of State (DoS), FBI, DHS, or Intelligence Community (IC) security environments is highly preferred.

Relevant security certifications such as:

  • CISM (Certified Information Security Manager)

  • GIAC Certifications (GCIH, GCIA, GCFA, GCED, etc.)

  • Security+, CySA+, or CASP+

  • Certified Ethical Hacker (CEH)

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

November 20, 2025

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $148,850.00 - $269,075.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos

Website: https://www.leidos.com/

Headquarter Location: Reston, Virginia, United States

Employee Count: 10001+

Year Founded: 1969

IPO Status: Public

Industries: Computer ⋅ Government ⋅ Information Services ⋅ Information Technology ⋅ National Security ⋅ Software