> Markdown version of [/jobs/ext/1840042-arcsight-enterprise-security-manager](https://www.wearedevelopers.com/jobs/ext/1840042-arcsight-enterprise-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ArcSight Enterprise Security Manager - **Company:** CareerCircle - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Excel, Microsoft Windows, Application Layers, Microsoft Outlook, Network Analysis, Signals Intelligence, CompTIA Security+, Cyber Security, Information Systems, Computer Networks, Domain Name System (DNS), Identity and Access Management, IP Addressing, Intrusion Detection and Prevention, Intrusion Detection Systems, Key Management, Knowledge Management, Pcap, Microsoft Office, Microsoft Servers, Windows Servers, NetFlow, Network Monitoring, Packet Analyzer, Open Source Technology, Open Source Intelligence, Open Systems Interconnection (OSI), Peering, Rapid Prototyping Process, ArcSight SIEM Tool, TCP/IP, Wireshark, Software Vulnerability Management, Windows Desktop, Data Logging, Computer Networking Systems, Computer Network Operations, Mitre Att&ck, Virtual Environment, Malware, Cyber Threat Analysis, Cyber Warfare, Splunk - **Published:** July 30, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/md/odenton/a3add06f-dfdf-427c-8497-02c1260d02a5 ## About the Role Triage TCP/IP NetFlow Equities Dashboard Wireshark Operations Leadership Automation Mitigation Market Data Risk Analysis Cyber Defense Cyber Security Trend Analysis Packet Analyzer Ancient History Threat Detection Malware Analysis Network Analysis Application Layers Network Monitoring Information Systems Exploitation Techniques Vulnerability Management Open Source Intelligence Cyber Threat Intelligence Cyber Kill Chain Framework Standard Operating Procedure Open Systems Interconnection, * Active DoD TS/SCI Clearance and eligible for polygraph * Bachelor's Degree in related discipline and 12 years of related experience. Additional experience may be accepted in lieu of degree * Security+ Certification (or other equivalent DoD 8570 Level II certification) * In-depth knowledge of network and application protocols, cyber vulnerabilities and exploitation techniques and cyber threat/adversary methodologies. * Proficiency with datasets, tools and protocols that support analysis ( e.g. passive DNS, Virus Total, Recorded Future, TCP/IP, OSI, WHOIS, enumeration, threat indicators, malware analysis results, Wireshark, Splunk, Arcsight etc .). * Experience with various open-source and commercial vendor portals, services and platforms that provide insight into how to identify and/or combat threats or vulnerabilities to the enterprise. * Proficiency working with various types of network data (e.g. netflow, PCAP, custom application logs), * Experience with the DISN and other DOD Networks. * Skilled in building extended cyber security analytics (Trends, Dashboards, etc.). * Demonstrated experience briefing Senior Executive Service (SES) and General Officer/Flag Officer (GO/FO) leadership. * Experience in intelligence driven defense and/or cyber Kill Chain methodology. * IAT Level III and IAM Level II+III Certifications, NetFlow Equities Dashboard Wireshark Operations Leadership Automation Mitigation Market Data Risk Analysis Cyber Defense Cyber Security Trend Analysis Packet Analyzer Ancient History Threat Detection Malware Analysis Network Analysis Application Layers Network Monitoring Information Systems Exploitation Techniques Vulnerability Management Open Source Intelligence Cyber Threat Intelligence Cyber Kill Chain Framework Standard Operating Procedure Open Systems Interconnection ArcSight Enterprise Security Manager, Time Off Management Security Engineering CompTIA Security+ CE Signals Intelligence Information Assurance Continuous Monitoring Prototype Development Risk Management Framework Verbal Communication Skills Computer Network Operations Information Systems Security GIAC Security Leadership Certification Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) ## Description The Leidos Defense Group has an opening for a Cyber Security Fusion Analyst on the DISA GSM-O II program supporting Joint Force Headquarters DODIN at Fort Meade., GSM-O II provides network operations and cyber defense support to the Defense Information Systems Agency (DISA) in support of the DOD and COCOMs. In this role, you will provide support with incident handling, triage of events, network analysis, threat detection, trend analysis, metric development, and vulnerability information dissemination., * Leverage an array of network monitoring and detection capabilities (including netflow, custom application protocol logging, signature-based IDS, and full packet capture (PCAP) data) to identify cyber adversary activity. * Support the development of Cyber Fusion standard operating procedures (SOPs), and Cyber Fusion Framework and Methodology based on industry best practice and department of defense instruction, guidance, and policy. * Identify threats to the enterprise and provide mitigation strategies to improve security, and reduce the attack surface. * Perform analysis by leveraging serialized threat reporting, intelligence product sharing, OSINT, and open source vulnerability information to ensure prioritized plans are developed. * Analyze and document malicious cyber actors TTPs, providing recommendations and alignment to vulnerabilities and applicability to the enterprise operational environment. * Discover adversary campaigns, anomalies and inconsistencies in sensor and system logs, SIEMs, and other data. * Identify, investigate and rule out system compromises, with the capacity to provide written analytic summaries and attack life cycle visualizations. * Provide risk assessments and recommendations based on analysis of technologies, threats, intelligence, and vulnerabilities. * Offer recommendations to adjust enterprise or tactical countermeasures to for threats impacting the DODIN. * Collect analysis metrics and trending data, identify key trends, and provide situational awareness on these trends., Operations Leadership Subnetwork Market Data Communication IP Addressing Microsoft 365 Cyber Defense Cyber Security Microsoft Excel Windows Servers Decision Making Microsoft Teams Windows Desktop Ancient History Microsoft Office Microsoft Access Cisco Networking Operating Systems Microsoft Outlook Microsoft Servers Policy Development Network Monitoring Information Systems Virtual Environment Knowledge Management Cyber Threat Intelligence IAT Level II Certification Interpersonal Communications Peering (Computer Networking) Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0, Equities Operations Purchasing Upskilling Market Data NIST 800-53 Cryptography Self-Starter Key Management Ancient History Defense In Depth Rapid Prototyping Analytical Method Security Clearance Information Systems Operations Security GIAC Certifications Enterprise Security ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Debunking the Top 10 Myths about Web 3](https://www.wearedevelopers.com/videos/634-debunking-the-top-10-myths-about-web-3) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)