ECS Tech Inc logo
ECS Tech Inc

All candidates must meet the following criteria: Must be a US Citizen, no dual Citizenships. Must be able to secure a Public trust clearance. Must be able to work across multiple programs across the Federal and DOD space. The core values that ECS looks for in an engagement manager include: Teamwork, Respect, Accountability, Integrity, and Leadership.

Security Operations Manager

Location

United States

Posted

25 days ago

Salary

$150K - $190K / year

Seniority

Lead

No structured requirement data.

Job Description

Security Operations Manager

ECS Tech Inc

Role Description Everforth ECS is seeking a Security Operations Manager to work remotely. This position is contingent upon contract award. The Security Operations Manager will be the single POC providing ongoing status and progress to the NIAID CO and COR. In this role, you will be responsible for: - Cybersecurity incident resolution, including investigation and response to minimize the impact or likelihood of incidents. - Monitoring of NIAID systems and components to detect potential threats. - Project management and engineering support for the improvement and automation of security operations tools and processes. - Project support for improving and automating security operations capabilities, including: - Developing solutions and options for project milestones. - Developing project plans in a task and completion tracking tool such as Jira. - Reporting on progress in real-time using an IT Service Management tool such as ServiceNow. - Responding to and resolving security and privacy incidents and coordinating with the NIH Threat Management and Incident Response (TMIR) team and privacy coordinators according to NIH or Federal format and timelines. - Advising and assisting with SOC architecture activities for all SOC information systems initiatives supporting all SOC tools and capabilities. Salary Range: $150,000 - $190,000 Qualifications - Bachelor's degree in Cybersecurity, Computer Science, or related field. - Active Public Trust or higher security clearance. - Minimum of 10 years of experience in cybersecurity; 15 years’ experience preferred. - 8+ years’ experience leading and delivering in security operations programs and incident management for comparably sized federal agencies and security programs. - Shall have at least one of the following industry-recognized certifications: - Certified Information System Security Professional (CISSP) - Global Information Assurance Certification (GIAC) - Certified Enterprise Defender (GCED) - GIAC Certified Incident Handler (GCIH) - Certified Network Defender (CND) - Systems Security Certified Practitioner (SSCP) - Proven ability to understand threats, evaluate the impact of potential incidents, and recommend risk reduction techniques. - Demonstrated expertise in analyzing and providing clear and concise risk reports, dashboards, and other visualizations to federal risk executives, system operators, and system stakeholders. - Knowledge of and experience overseeing the administration and configuration of security tools. - Experience with enterprise-wide penetration testing remediation to comply with agency remediation standards. - Documented experience in monitoring an enterprise-wide environment for potential security incidents. - Experience in establishing and enhancing security operations capabilities and proactively identifying potential risks. - Experience in setting up, administering, and enhancing cybersecurity tools and security operations processes. - Knowledge of different operational threat environments and incident categories. - Reside within the Washington DC Metro area. - Travel within the Washington DC Metro Area, and CONUS as needed. Requirements - Cybersecurity incident resolution. - Monitoring of systems for potential threats. - Project management and engineering support. - Coordination with NIH TMIR team and privacy coordinators. - Advising on SOC architecture activities. Benefits - General Description of Benefits

Related Categories

Related Job Pages

More Security Operations Jobs

ServiceNow logo

Senior Principal Technology Consultant-Security Operations

ServiceNow

As the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,100+ customers, we serve approximately 85% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.servicenow.com/careers. From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.

Full TimeRemoteTeam 10,001+Since 2004H1B Sponsor

Company Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today - ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone. Job Description What you get to do in this role: The Customer Outcomes Technical Consultant (TC) designs processes, built on ServiceNow, to achieve customers' desired outcomes. The TC provides expertise related to the processes enabled by the ServiceNow platform.• Apply ServiceNow knowledge and Security Operations domain expertise in customer engagements to provide optimum workflows.• Design efficient workflows based on ServiceNow SecOps product capabilities and leading practices, ensuring that the proposed solutions meet the customer's expectations.• Draft user stories and train customers to create their own acceptance criteria, testing strategy, and knowledge transfer while supporting customers in reviewing and approving them.• Be a contributor to leading practices and provide expertise related to the ServiceNow platform or solutions and workflows built on the platform.• Provide feedback to product development to improve the product based on experiences gained with customers.• Work with partners, in a co-delivery engagement, bringing leading practices guidance to the customer and partner team.• Play an important part of the Now Assure offering working with ServiceNow Partners.• Support the professional development of others through means of mentoring• Seen as an expert across the industry and an active contributor of leading practices.• Involved in more complex engagements, providing deeper expertise in a single workflow or scope across multiple workflows Qualifications To be successful in this role you have:• Minimum of 10 years of experience within a professional services organization or a similar client-facing, billable role.• Current experience security operations consulting engagements is preferred.• Industry domain expertise in Security Operations is preferred.• CISSP or equivalent certifications are highly preferred.• JavaScript proficiency is preferred.• Ability to fulfill technical consultant tasks as needed.• Experience driving complex issues through analysis and resolution.• Experience working collaboratively.• Ability to travel up to 50%• Ability to acquire all certifications in the "certification preferred" list within 90 days of hire. • ServiceNow certifications preferred: o ServiceNow Certified System Administrator o ServiceNow Certified Developer o ServiceNow Certified Data Foundations o ServiceNow Vulnerability Response Implementations Certification o ServiceNow Security Incident Response Certification For positions in this location, we offer a base pay of $192,400 - $336,700, plus equity (when applicable), variable/incentive compensation and benefits. Sales positions generally offer a competitive On Target Earnings (OTE) incentive compensation structure. Please note that the base pay shown is a guideline, and individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. We also offer health plans, including flexible spending accounts, a 401(k) Plan with company match, ESPP, matching donations, a flexible time away plan and family leave programs. Compensation is based on the geographic location in which the role is located and is subject to change based on work location. Additional Information Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here . To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact globaltalentss@servicenow.com for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license.

Illinois
$192.4K - $336.7K / year
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Triage alerts, investigate suspicious activity, lead incident response steps, and coordinate containment and recovery efforts. • Make sure logs and security data are gathered correctly, cleaned up, and organized so the team can analyze them effectively. • Examine systems, files, logs, and network data to understand what happened during security events. • Help newer analysts grow by sharing your experience, offering guidance, and running training sessions when needed. • Assist team members with technical questions, tool usage, investigation methods, and established response workflows. • Act as the point person during your shift: manage workload, oversee investigations, ensure smooth handoffs, and support teammates. • Look for opportunities to improve processes, recommend new tools or automations, and help refine how the team operates.

Florida + 4 moreAll locations: Florida | New Jersey | Massachusetts | Missouri | Texas
$105K - $133K / year
UpGuard logo

IT & Security Operations Analyst

UpGuard

We're on a mission to protect the world's data.

Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

• Run daily, weekly, and periodic IT and security checklists, with a focus on Google SecOps/Chronicle monitoring • Perform health checks across GCP infrastructure, SaaS applications, and security tooling (alerts, compliance, CI/CD pipelines) • Troubleshoot security or infrastructure issues, document fixes, and raise follow-up actions • Collaborate with DevOps and InfraOps on platform-level and security-related issues • Identify and propose security and platform improvements as you gain business context • Implement automation, security tooling, and platform enhancements to strengthen cloud and SaaS environments • Contribute to scripts, dashboards, and operational improvements with a focus on security and compliance • Feed insights from day-to-day work into long-term IT security and operational strategy • Occasionally assist with IT support tasks across systems, hardware, and software • Prioritize tasks effectively and align timelines with stakeholders

Australia
$1.5K / year
Ardent logo

Security Operations Center Analyst

Ardent

Your "ALL IN" Location Intelligence | Digital Transformation | Data Science & Analytics experts

Full TimeRemoteTeam 51-200Since 2008H1B Sponsor

• Monitor security alerts and events in a 24x7 SOC environment. • Perform initial triage and validation of alerts to determine severity and impact. • Conduct advanced alert investigation and analyze security events across identity, endpoint, and network telemetry. • Handle Tier I escalation workflows and support Tier II incident response activities. • Coordinate incident containment efforts and escalate complex incidents to Tier III as needed. • Monitor log ingestion pipelines and ensure data sources are functioning properly. • Document incidents, findings, and response actions in accordance with SOC procedures. • Contribute to daily reporting and provide accurate shift handoff documentation. • Identify trends, anomalies, and potential threats through continuous monitoring and analysis. • Collaborate with cross-functional teams to support incident resolution and improve detection capabilities.

United States