Join a team committed to innovation, service, and excellence. At Blue Rose Consulting Group, every role is an opportunity to drive real-world results and make a difference.
Explore current openings today and find out how your skills can help shape the future.
Stay connected — subscribe to our RSS feed for new opportunities as they open.
| Department: | DOS GMOS |
| Location: | Washington, DC |
Blue Rose Consulting Group, Inc. (Blue Rose) is a certified HUBZone and Service-Disabled Veteran-Owned Small Business supporting Federal customers with mission-focused technology, professional services, and operational support. We are building a team for the anticipated Department of State Global Mission Operations Support (GMOS) effort supporting the Bureau of Diplomatic Technology, Enterprise Applications Directorate, Office of Consular Systems and Technology.
Monitor, analyze, correlate, and investigate security events using SIEM, log-management, threat intelligence, OSINT, and incident-response processes. This position supports the Department of State Consular Affairs global information technology environment, which includes domestic and overseas facilities, on-premises infrastructure, cloud platforms, applications, databases, and enterprise support services. This is a contingent position based on contract award and final customer requirements.
• Monitor SIEM alerts, logs, audit trails, network events, endpoint events, and other telemetry for suspicious or policy-violating activity.
• Triage, correlate, investigate, document, and escalate potential security incidents in accordance with established procedures.
• Develop and tune SIEM searches, dashboards, correlation rules, alerts, reports, and use cases to improve detection quality.
• Use open-source intelligence, threat intelligence, and digital-forensics techniques to enrich investigations and assess potential impact.
• Coordinate with security, infrastructure, network, application, and incident-response teams during investigation, containment, recovery, and lessons-learned activities.
• Maintain incident timelines, case notes, evidence, metrics, trends, and management reports.
• Identify recurring patterns, coverage gaps, false positives, and opportunities to improve monitoring and response processes.
• 3+ years of SIEM administration, security monitoring, threat analysis, or SOC experience.
• Hands-on experience with Splunk or another enterprise SIEM/log-management platform.
• Experience triaging and investigating alerts, correlating events, and escalating potential incidents.
• Familiarity with incident response, digital forensics, OSINT, threat intelligence, and recovery procedures.
• Ability to work shift-based operations when required and communicate clearly during high-priority incidents.
• Active Secret clearance; Top Secret may be preferred or required for certain assignments.
• Splunk, Security+, CySA+, GCIH, GCIA, or equivalent certification.
• Experience supporting Federal or Department of State security operations.
• Experience with cloud logs, endpoint detection and response, network security monitoring, or automation.
Compensation will be commensurate with experience, qualifications, assigned work location, and final contract requirements. Blue Rose offers a competitive benefits package for eligible full-time employees. Specific compensation and benefit details will be provided during the recruiting process.
Please submit a current resume that clearly demonstrates the required experience, technical qualifications, certifications, and active security clearance. Candidates selected for consideration may be asked to provide additional information to support contract staffing and clearance verification.
Blue Rose Consulting Group, Inc. is an Equal Opportunity Employer.
This position is in anticipation of contract award and is contingent upon successful contract award. Applicants will be contacted regarding employment opportunities upon award notification.