ArcSight Enterprise Security Manager
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+25 more
Job description
Triage NetFlow Planning Coaching Research Firewall Equities Timelines Operations Leadership Management Mentorship Innovation OSI Models Market Data CSSP Analyst Communication Cyber Defense Cyber Security Security Tools Packet Analyzer Security Systems Defense In Depth, The Detection, Monitoring, and Countermeasures Lead serves as a senior Subject Matter Expert (SME) responsible for the operational management and technical optimization of the Security Operations Center’s (SOC) detection, triage, and prevention capabilities. This role leads the continuous monitoring of Pentagon networks, directs the tuning of all security tools to ensure optimal detection, and develops and implements countermeasures to mitigate security risks and prevent adversary actions. The Lead will manage a team of 10-15 staff in a high-pressure, 24/7/365 environment, ensuring the effectiveness and compliance of all detection and prevention systems in accordance with CJCSM 6510.01, DoD/IC directives, and the Performance Work Statement (PWS).
This role involves evaluating current cyber defense technologies, identifying capability gaps, and shaping requirements for future cybersecurity operations (such as Thunderdome and Zeek/Netflow). The Lead will deliver strategic reports that drive tool impact and mission success.
Primary Responsibilities
- Security Monitoring & Detection: Lead the 24x7x365 real-time monitoring and analysis of network and endpoint security data from the J6 Pentagon sensor grid (including IDS/IPS, firewalls, netflow, packet capture, and SIEM). Direct the identification, trending, and correlation of event data to identify malicious cyber activity (including insider threats and APTs) and oversee backbone network monitoring to ensure proper configuration for both signature-based and anomalous activity detection.
- Tool Tuning & Optimization: Lead the Countermeasures Team in the effective tuning and optimization of all security systems (e.g., SIEM, IDS/IPS, End Point Security) to ensure optimal detection and prevention capabilities. Ensure tools are configured with correct data feeds and direct the application of vendor and custom signatures to prevent, detect, and block malicious activity.
- Countermeasure Development: Lead the development and implementation of countermeasures to mitigate potential security risks. Assess the effectiveness of current monitoring capabilities to drive process improvements and develop project plans for government approval to implement recommended detection enhancements.
- Reporting & Metrics: Provide monthly reports to the Government on system uptime, availability, maintenance, and vulnerability mitigation. Provide input for monthly, quarterly, and annual reports detailing tool versions, upgrade plans, and license counts, while maintaining SOPs, after-hours recall rosters, and lifecycle status reports for all managed infrastructure., Equities Operations Purchasing Accounting Procurement Supply Chain Communication Vendor Management Price Negotiation Strategic Sourcing Request For Proposal Organizational Skills Supplier Performance Management +0 Test Technician Actalent
Manassas, VA*Hybrid
Requirements
Backbone Network CompTIA Security+ Digital Forensics Endpoint Security Content Filtering Process Improvement GIAC Certifications Top Secret Clearance Cyber Threat Hunting Continuous Monitoring MITRE ATT&CK Framework Technology Integration Complex Problem Solving Infrastructure Security Vulnerability Management Certified Ethical Hacker IAT Level II Certification IBM QRadar (SIEM Software) GIAC Certified Incident Handler GIAC Certified Intrusion Analyst Host Based Security System (HBSS) ArcSight Enterprise Security Manager CompTIA Cybersecurity Analyst (CySA+) GIAC Security Essentials Certification (GSEC) Security Information And Event Management (SIEM) Secret Internet Protocol Router Network (SIPRNet) Cisco Certified Network Associate Security (CCNA Security), * Security Clearance: Must possess an active Top-Secret clearance with SCI eligibility. Access to SCI, NIPRNet, SIPRNet, and JWICS networks is required.
- Education & Experience: Requires a bachelor’s degree in a relevant IT or Cybersecurity field and 12 to 15 years of prior relevant experience; OR a Master’s degree with 10 to 13 years of prior relevant experience. This must include 5+ years in incident handling or SOC operations, extensive experience operating, planning, and managing a SOC/CIRT, and 3+ years of demonstrated experience administering and deploying enterprise network defense tools (e.g., IDS/IPS, Packet Capture, SIEM, Proxy, Web Content Filtering).
- Certifications: Prior to Start: Must meet DoD 8140/8570.01-M requirements for IAT Level II (e.g., Security+ CE, CySA+, CCNA Security, GSEC). Within 180 Days: Must obtain a CSSP Analyst certification (e.g., CEH, CySA+, GCIA, GCIH).
- Enterprise Tool & Infrastructure Expertise (Tool-Agnostic): Subject Matter Expertise in the architecture, engineering, and operations of enterprise SIEM platforms (e.g., Splunk, QRadar, ArcSight), endpoint security solutions (e.g., Trellix, MDE, ACAS), and modern security infrastructure (e.g., Taps, IPS, Zero Trust appliances).
- Defensive Cyber Operations (DCO), Threat Hunting & Forensics: Experience executing and supporting DCO training and operations, to include conducting active threat hunts aligned to the MITRE ATT&CK framework, performing forensic analysis (using log data, IDS events, and network PCAP) to reconstruct attack timelines, and delivering actionable threat insights to operational teams.
- Advanced Network Fundamentals & Complex Problem Solving: Deep understanding of network traffic, the OSI model, defense-in-depth principles, and the network threat lifecycle, with a proven ability to resolve highly complex, multi-dimensional technical problems affecting multiple aspects of a program.
- Technical Leadership & Mentorship: Proven experience serving as a technical lead on large, complex projects; with the agility to pivot between multiple initiatives and track them to completion; while supervising, mentoring, and coaching technical staff across various skill levels.
- Executive Communication & Reporting: Exceptional communication skills with the demonstrated ability to draft comprehensive technical reports and brief senior executive leadership (both internal and client-facing) on operational findings and matters of strategic importance.
- Innovation & Technology Integration: Ability to drive the research, fielding, and integration of new security technologies, leading the collaborative development of innovative products and solutions alongside other industry experts.
If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., Teamwork Plumbing Aviation Machinery Carpentry Hand Tools Positivity Pipefitting Construction Detail Oriented Professionalism Time Management Health Advocacy Strong Work Ethic Safety Procedures Business Solutions Good Driving Record Power Tool Operation Willingness To Learn Organizational Skills Valid Driver’s License Commercial Construction Discounts And Allowances Verbal Communication Skills Employee Assistance Programs Certified Safety Professional 10-Hour OSHA General Industry Card, Teamwork Visionary Concision Leadership Innovation Subsystems Communication Code Coverage System Testing Control Systems Microsoft Office Software Testing Test Engineering Secret Clearance Systems Modeling Agile Methodology Submarine Warfare Hardware Components Software Development Fire-Control Systems Information Assurance Requirements Management Engineering Design Process Milestones (Project Management) Troubleshooting (Problem Solving)
Benefits & conditions
Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits ., 30-Hour OSHA General Industry Card +0 Purchasing Analyst V Aston Carter
About the company
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
7 Important Tips That Every Software Developer Should Know