Security Operations Manager

Apply Now

Company: Appcast

Location: Huntsville, AL 35810

Description:

Leidos is seeking a detail-oriented and proactive Security Operations Manager to join our team. The Cybersecurity Analyst SME will serve as the Security Operations Manager of a 24/7/365 Enterprise Security Operations Center (ESOC) Watch Floor. This is an exciting opportunity to be at the forefront of cybersecurity operations and protect against cyberthreats. The analyst will join our team in Huntsville, AL providing holistic enterprise defensive strategies for enterprise cyber security capabilities implemented within the cyber infrastructure. Actively detecting, monitoring, preventing, and analyzing real-time cybersecurity information, events, and threats.

At Leidos, you'll join a team of innovators tackling some of the world's most critical challenges through cutting-edge technology and bold ideas. We foster a dynamic and collaborative environment where your expertise will directly contribute to mission success and the significance of your contributions will only be surpassed by the exceptional opportunities for your professional growth and advancement.

Primary Responsibilities:
  • The Security Operations Manager will plan, direct and manage day to day activities of contractor security operations staff
  • Suggest and implement controls for key information security gaps within the customer security infrastructure
  • Ensure timeliness and quality of reporting produced by the security operations staff to stakeholders
  • Instill and reinforce industry best practices in the domains of incident response, cybersecurity analysis, case and knowledge management, and ESOC operations
  • Act as subject matter expert in several security technologies (depth) with ability to lead across enterprise security domains (breadth)
  • Expertly collaborate across multiple disciplines and levels of the organization
  • Multitask with expert organizational skills in a fast-paced environment
  • Demonstrate an open mind, creative thinking, willingness to take calculated risks, and a strong ability to make informed decisions
  • Create job descriptions for new positions and manage annual performance plans
  • Continually mature ESOC operations and capabilities, developing intra-team relationships, and building trust and rapport with external stakeholders
  • Ensure that the ESOC's standard operation procedures are followed to maintain a high level of security across the organization
  • Keep up-to-date with the latest cybersecurity trends, vulnerabilities, and mitigation techniques to strengthen the organization's overall security posture.
  • Guide and mentor junior staff


Basic Qualifications:
  • Active Top-Secret Clearance with eligibility for SCI
  • US Citizenship
  • 10+ years of experience as a Cybersecurity professional and in a Security Operations Center environment
  • Experience with Splunk Enterprise Cybersecurity
  • Familiarity with all related aspects of cybersecurity operations and security architecture
  • In-depth knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies.


Preferred Qualifications:
  • One of the following certifications:
    • GIAC Continuous Monitoring Certification (GMON)
    • GIAC Certified Incident Handler (GCIH)
    • GIAC Certified Forensic Analyst (GCFA)
    • GIAC Certified Intrusion Analyst (GCIA)
    • GIAC Network Forensic Analyst (GNFA)
    • GIAC Cloud Threat Detection (GCTD)
    • GIAC Cloud Forensics Responder (GCFR)
  • CISSP Certification
  • Experience with Microsoft Sentinel
  • 6+ years of supervising and/or managing teams
  • 8+ years of intrusion detection and/or incident handling experience
  • Ability to analyze new attacks and provide guidance to watch floor analysts on detection and response
  • Knowledgeable of the various Intel Frameworks (e.g. Cyber Kill Chain, Diamond Model, MITRE ATT&CK, etc) and able to utilize it in their analysis workflow
  • Experience with Cloud (e.g. o365, Azure, AWS, etc) security monitoring and familiar with cloud threat landscape
  • Experience with FBI, DHS, IC, and DoD Networks.
  • Experience with configuring and operating cybersecurity and networking devices (i.e. routers, firewalls, IDPS)
  • Experience with mitigation development against malicious cyber activity


Original Posting:
April 17, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:
Pay Range $126,100.00 - $227,950.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Similar Jobs