Monitoring & Event Management Team Lead; SIEM‐capable
Listed on 2026-01-20
-
IT/Tech
IT Support, Cybersecurity, IT Project Manager
Job Description
Advance how our customer operates while you advance your career. Join GDIT as Monitoring & Event Management Team Lead (SIEM‑capable) and build an impactful career in enterprise IT, collaborating with people who are driven and resourceful like you.
As the Monitoring & Event Management Team Lead, you will lead the team that staffs the Enterprise‑Wide Command Center (EWCC) and own day‑to‑day delivery of 24x7x365 monitoring, event correlation, incident validation, escalation, and restoration activities across FDIC’s hybrid IT environment. You will ensure MEM tooling, dashboards, CMDB/ITSM integration, and processes meet FDIC requirements and contractual service levels while managing contractor personnel performance, documentation, and continuous improvement.
MEANINGFULWORK AND PERSONAL IMPACT
As the Monitoring & Event Management Team Lead, the work you’ll do at GDIT will be impactful to the mission of FDIC. You will play a crucial role in ensuring continuous availability and rapid restoration of critical FDIC services and infrastructure.
- Lead MEM staffing, shift schedules, handoffs, and Duty Officer readiness to ensure uninterrupted 24x7x365 EWCC operations.
- Manage event detection, validation, correlation, automated ticket generation into ITSM, and lead incident bridge calls for P1/P2 incidents.
- Drive improvements in monitoring efficacy, reduce false positives, and ensure timely P1 outage notifications and status updates per SLAs.
- Utilize enterprise monitoring tools, CMDB/ITSM integrations, synthetic transaction scripts, automation, Service Now Operations Modules, and SIEM‑style event/log correlation to deliver reliable MEM services.
Bring your technology expertise and drive for innovation to GDIT. The Monitoring & Event Management Team Lead must have:
- Minimum 5 years of Monitoring & Event Management experience. At least 3 years in an IT outsourcing environment managing contractor personnel and operational delivery for 24x7 services.
- ITIL 4 Foundation (required).
- High School Diploma;
College preferred.
- Strong knowledge of ICMP, SNMPv3, SSH, WMI, Net Flow and encrypted management protocols.
- Hands‑on experience with availability, utilization, performance, synthetic transaction, composite transaction, and log file monitoring.
- Experience integrating monitoring with CMDB/CMS and ITSM platforms and automating incident population and severity assignment.
- Proficiency in Service Now Operations Modules, including Event Management, ITOM/Discovery, Service Mapping, Incident Management, CMDB operations, and Orchestration.
- SIEM keyword:
Experience with log aggregation, event normalization, correlation rule development, and SIEM‑style analytics (e.g., Splunk, QRadar, Microsoft Sentinel, or equivalent) or demonstrated ability to implement equivalent capabilities within MEM tooling. - Proficiency in scripting and automation for synthetic transactions and automated remediation (Power Shell, Python, or similar).
- Familiarity with database monitoring, middleware metrics (JVM, connection pools), and cloud monitoring for IaaS/PaaS/SaaS.
- Intune
- Crowd Strike
- Defender
- Endpoint Privilege Management
- Fleet RMM
- Netaphor Site Audit
- HP Web Jet Admin
- Kofax Autostore
- Token Vault
- Wise Admin Studio
- PSTools
- Graph
- Yubi Key Manager
- vSec:
CMS Admin
Location:
Onsite in Arlington, VA. Candidate must reside within the DC/MD/Northern VA area.
Skills and Abilities
- Proven leadership and team management in high‑pressure, 24x7 environments.
- Clear, concise communicator for technical and non‑technical stakeholders; experienced running incident bridge calls and delivering outage updates.
- Strong analytical skills for root cause analysis, trend interpretation, and parametric application analysis.
- Deep understanding of ITIL processes (Incident, Problem, Change, Event, Capacity) and experience enforcing SLAs and operational metrics.
- Customer focus and ability to coordinate with vendors and third‑party providers.
- Experience with Digital Experience Monitoring (DEX) and application performance monitoring (APM).
- Experience with low‑code automation platforms and vendor support relationships for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).