> Markdown version of [/jobs/ext/3568926-arcsight-enterprise-security-manager](https://www.wearedevelopers.com/jobs/ext/3568926-arcsight-enterprise-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ArcSight Enterprise Security Manager - **Company:** CareerCircle - **Location:** Washington, DC, United States (Remote available) - **Experience:** Expert - **Salary:** $131,300.0 - $237,350.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Code Coverage, CompTIA Security+, Cyber Security, Computer Networks, Digital Forensics, Internet Protocol, Intrusion Detection Systems, OSI Models, Pcap, Microsoft Security Essentials, NetFlow, Networking Basics, Network Monitoring, Packet Analyzer, NIPRNet, Performance Tuning, ArcSight SIEM Tool, Zero Trust Network Access, Requirements Management, Security Information and Event Management, Software Engineering, Subsystems, System Testing, Software Vulnerability Management, Network Routers, In-Plane Switching (IPS), Mitre Att&ck, QRadar, Cyber Threat Analysis, Firewalls (Computer Science), Web Filtering, SC Clearance, Hardware Infrastructure, Cyber Warfare, Splunk, Cisco - **Published:** October 3, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/va/alexandria/229a1e92-e778-42b5-b5d1-60d8e4facd83 ## About the Role Backbone Network CompTIA Security+ Digital Forensics Endpoint Security Content Filtering Process Improvement GIAC Certifications Top Secret Clearance Cyber Threat Hunting Continuous Monitoring MITRE ATT&CK Framework Technology Integration Complex Problem Solving Infrastructure Security Vulnerability Management Certified Ethical Hacker IAT Level II Certification IBM QRadar (SIEM Software) GIAC Certified Incident Handler GIAC Certified Intrusion Analyst Host Based Security System (HBSS) ArcSight Enterprise Security Manager CompTIA Cybersecurity Analyst (CySA+) GIAC Security Essentials Certification (GSEC) Security Information And Event Management (SIEM) Secret Internet Protocol Router Network (SIPRNet) Cisco Certified Network Associate Security (CCNA Security), * Security Clearance: Must possess an active Top-Secret clearance with SCI eligibility. Access to SCI, NIPRNet, SIPRNet, and JWICS networks is required. * Education & Experience: Requires a bachelor's degree in a relevant IT or Cybersecurity field and 12 to 15 years of prior relevant experience; OR a Master's degree with 10 to 13 years of prior relevant experience. This must include 5+ years in incident handling or SOC operations, extensive experience operating, planning, and managing a SOC/CIRT, and 3+ years of demonstrated experience administering and deploying enterprise network defense tools (e.g., IDS/IPS, Packet Capture, SIEM, Proxy, Web Content Filtering). * Certifications: Prior to Start: Must meet DoD 8140/8570.01-M requirements for IAT Level II (e.g., Security+ CE, CySA+, CCNA Security, GSEC). Within 180 Days: Must obtain a CSSP Analyst certification (e.g., CEH, CySA+, GCIA, GCIH). * Enterprise Tool & Infrastructure Expertise (Tool-Agnostic): Subject Matter Expertise in the architecture, engineering, and operations of enterprise SIEM platforms (e.g., Splunk, QRadar, ArcSight), endpoint security solutions (e.g., Trellix, MDE, ACAS), and modern security infrastructure (e.g., Taps, IPS, Zero Trust appliances). * Defensive Cyber Operations (DCO), Threat Hunting & Forensics: Experience executing and supporting DCO training and operations, to include conducting active threat hunts aligned to the MITRE ATT&CK framework, performing forensic analysis (using log data, IDS events, and network PCAP) to reconstruct attack timelines, and delivering actionable threat insights to operational teams. * Advanced Network Fundamentals & Complex Problem Solving: Deep understanding of network traffic, the OSI model, defense-in-depth principles, and the network threat lifecycle, with a proven ability to resolve highly complex, multi-dimensional technical problems affecting multiple aspects of a program. * Technical Leadership & Mentorship: Proven experience serving as a technical lead on large, complex projects; with the agility to pivot between multiple initiatives and track them to completion; while supervising, mentoring, and coaching technical staff across various skill levels. * Executive Communication & Reporting: Exceptional communication skills with the demonstrated ability to draft comprehensive technical reports and brief senior executive leadership (both internal and client-facing) on operational findings and matters of strategic importance. * Innovation & Technology Integration: Ability to drive the research, fielding, and integration of new security technologies, leading the collaborative development of innovative products and solutions alongside other industry experts. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares., Teamwork Plumbing Aviation Machinery Carpentry Hand Tools Positivity Pipefitting Construction Detail Oriented Professionalism Time Management Health Advocacy Strong Work Ethic Safety Procedures Business Solutions Good Driving Record Power Tool Operation Willingness To Learn Organizational Skills Valid Driver's License Commercial Construction Discounts And Allowances Verbal Communication Skills Employee Assistance Programs Certified Safety Professional 10-Hour OSHA General Industry Card, Teamwork Visionary Concision Leadership Innovation Subsystems Communication Code Coverage System Testing Control Systems Microsoft Office Software Testing Test Engineering Secret Clearance Systems Modeling Agile Methodology Submarine Warfare Hardware Components Software Development Fire-Control Systems Information Assurance Requirements Management Engineering Design Process Milestones (Project Management) Troubleshooting (Problem Solving) ## Description Triage NetFlow Planning Coaching Research Firewall Equities Timelines Operations Leadership Management Mentorship Innovation OSI Models Market Data CSSP Analyst Communication Cyber Defense Cyber Security Security Tools Packet Analyzer Security Systems Defense In Depth, The Detection, Monitoring, and Countermeasures Lead serves as a senior Subject Matter Expert (SME) responsible for the operational management and technical optimization of the Security Operations Center's (SOC) detection, triage, and prevention capabilities. This role leads the continuous monitoring of Pentagon networks, directs the tuning of all security tools to ensure optimal detection, and develops and implements countermeasures to mitigate security risks and prevent adversary actions. The Lead will manage a team of 10-15 staff in a high-pressure, 24/7/365 environment, ensuring the effectiveness and compliance of all detection and prevention systems in accordance with CJCSM 6510.01, DoD/IC directives, and the Performance Work Statement (PWS). This role involves evaluating current cyber defense technologies, identifying capability gaps, and shaping requirements for future cybersecurity operations (such as Thunderdome and Zeek/Netflow). The Lead will deliver strategic reports that drive tool impact and mission success. Primary Responsibilities * Security Monitoring & Detection: Lead the 24x7x365 real-time monitoring and analysis of network and endpoint security data from the J6 Pentagon sensor grid (including IDS/IPS, firewalls, netflow, packet capture, and SIEM). Direct the identification, trending, and correlation of event data to identify malicious cyber activity (including insider threats and APTs) and oversee backbone network monitoring to ensure proper configuration for both signature-based and anomalous activity detection. * Tool Tuning & Optimization: Lead the Countermeasures Team in the effective tuning and optimization of all security systems (e.g., SIEM, IDS/IPS, End Point Security) to ensure optimal detection and prevention capabilities. Ensure tools are configured with correct data feeds and direct the application of vendor and custom signatures to prevent, detect, and block malicious activity. * Countermeasure Development: Lead the development and implementation of countermeasures to mitigate potential security risks. Assess the effectiveness of current monitoring capabilities to drive process improvements and develop project plans for government approval to implement recommended detection enhancements. * Reporting & Metrics: Provide monthly reports to the Government on system uptime, availability, maintenance, and vulnerability mitigation. Provide input for monthly, quarterly, and annual reports detailing tool versions, upgrade plans, and license counts, while maintaining SOPs, after-hours recall rosters, and lifecycle status reports for all managed infrastructure., Equities Operations Purchasing Accounting Procurement Supply Chain Communication Vendor Management Price Negotiation Strategic Sourcing Request For Proposal Organizational Skills Supplier Performance Management +0 Test Technician Actalent Manassas, VA*Hybrid ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)