Cybersecurity Engineer | SIEM, SOAR, Security Operations & Cloud Security

Apex Systems

Richmond (VA)

Hybrid

USD 96,000 - 165,000

Part time

11 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

401K match
HSA
ESPP
EAP
Certification support

Job summary

Everforth Apex is strengthening its Security Engineering & Operations capabilities in a hybrid North Chesterfield environment. The Cybersecurity Engineer will design security controls, lead SIEM/SOAR integrations, and develop detection use cases to support a mature SOC model.

The role emphasizes collaboration with IT operations, application teams, and SOC analysts, with a hands-on technical mindset and experience across cloud, on‑prem, and identity security areas.

Qualifications

  • 10+ years of experience in security engineering, security operations, or systems engineering with cybersecurity responsibilities.
  • Hands-on experience with SIEM platforms such as Splunk, LogRhythm, Microsoft Sentinel, or similar technologies.
  • Experience with log onboarding, security monitoring, and detection engineering.
  • Strong understanding of identity security, including IAM, SSO, MFA, privileged access management, and role-based access design.
  • Experience securing Windows and Linux environments, network infrastructure, and cloud workloads.
  • Experience implementing secure configuration baselines using CIS, DISA STIG, or comparable frameworks.
  • Proficiency in scripting and automation using PowerShell, Python, or similar languages.
  • Understanding of incident response engineering requirements, including visibility, forensic readiness, and data access considerations.
  • Experience working within regulated environments and security compliance frameworks such as NIST CSF, RMF, CJIS, or similar standards.

Responsibilities

  • Design and implement security controls across identity, network, endpoint, and cloud environments.
  • Lead SIEM/SOAR integrations, including log onboarding, parsing, normalization, and automation readiness.
  • Implement secure configuration and baseline management for critical infrastructure, servers, workstations, and cloud assets.
  • Support enterprise security architecture development, including secure-by-design reviews with application and infrastructure teams.
  • Develop and tune detection use cases aligned with the security operations roadmap, prioritized by risk and threat exposure.
  • Engineer identity security controls, including IAM/PAM hardening, role‑based access validation, and integration with monitoring solutions.
  • Implement cryptographic management practices, key lifecycle controls, and validation processes for sensitive systems.
  • Build and maintain logging pipelines to ensure visibility across endpoints, servers, network devices, identity platforms, and cloud services.
  • Support vulnerability management engineering, including scanner integration, asset classification, and remediation workflow design.
  • Partner with security operations personnel to develop and tune detection rules, correlation logic, and enrichment processes.
  • Participate in incident investigations and root‑cause analysis with a focus on implementing engineering solutions that prevent recurring issues.
  • Implement threat intelligence ingestion pipelines and integrate intelligence feeds into detection and response processes.
  • Identify and implement high‑impact opportunities for security automation, including alert enrichment, ticket creation, and response workflow orchestration.
  • Evaluate tool health, tuning opportunities, and integration gaps; provide recommendations to support the cybersecurity modernization roadmap.
  • Support emerging AI‑assisted capabilities designed to improve security operations and analyst effectiveness.
  • Work closely with IT operations, infrastructure, endpoint management, and application teams to drive secure configurations and optimize security controls.
  • Participate in governance meetings and contribute to progress reporting and strategic planning efforts.
  • Develop technical documentation, operational runbooks, and knowledge transfer materials for internal teams.
  • Develop a SIEM/SOAR engineering plan with integration of core security tools.

Skills

SIEM
SOAR
Identity security
IAM/PAM
Cloud security
Incident response
Vulnerability management

Job description

Job#: 3052876

Job Description:

Cybersecurity Engineer (Contractor)

Location

North Chesterfield, VA (Hybrid)

Engagement

12-month contract with option to extend

Reports To

Director of Security Engineering & Operations

Screening

Must be able to pass a background investigation

Position Overview

Our client is strengthening and modernizing its Security Engineering & Operations capabilities as part of a broader effort to mature its cybersecurity posture. The organization is expanding its engineering depth, enhancing existing SIEM, EDR, and SOC practices, and evaluating the optimal team model for future growth. This initiative focuses on elevating current capabilities, closing visibility gaps, and evolving the tools, processes, and operational practices that will support a mature cybersecurity program. The Cybersecurity Engineer will help broaden and strengthen core engineering functions that enable an effective SOC model, including SIEM/SOAR integration, identity and endpoint security engineering, secure configuration baselines, and cloud and enterprise architecture support. This role partners with IT operations, application teams, and SOC analysts while operating within an evolving security organization. Success in this role requires adaptability, process improvement experience, strong documentation habits, and a hands‑on technical mindset.

Key Responsibilities
Security Engineering & Architecture
  • Design and implement security controls across identity, network, endpoint, and cloud environments.
  • Lead SIEM/SOAR integrations, including log onboarding, parsing, normalization, and automation readiness.
  • Implement secure configuration and baseline management for critical infrastructure, servers, workstations, and cloud assets.
  • Support enterprise security architecture development, including secure‑by‑design reviews with application and infrastructure teams.
  • Develop and tune detection use cases aligned with the security operations roadmap, prioritized by risk and threat exposure.
  • Engineer identity security controls, including IAM/PAM hardening, role‑based access validation, and integration with monitoring solutions.
  • Implement cryptographic management practices, key lifecycle controls, and validation processes for sensitive systems.
Security Operations Enablement
  • Build and maintain logging pipelines to ensure visibility across endpoints, servers, network devices, identity platforms, and cloud services.
  • Support vulnerability management engineering, including scanner integration, asset classification, and remediation workflow design.
  • Partner with security operations personnel to develop and tune detection rules, correlation logic, and enrichment processes.
  • Participate in incident investigations and root‑cause analysis with a focus on implementing engineering solutions that prevent recurring issues.
  • Implement threat intelligence ingestion pipelines and integrate intelligence feeds into detection and response processes.
Automation & Modernization
  • Identify and implement high‑impact opportunities for security automation, including alert enrichment, ticket creation, and response workflow orchestration.
  • Evaluate tool health, tuning opportunities, and integration gaps; provide recommendations to support the cybersecurity modernization roadmap.
  • Support emerging AI‑assisted capabilities designed to improve security operations and analyst effectiveness.
Collaboration & Cross‑Functional Coordination
  • Work closely with IT operations, infrastructure, endpoint management, and application teams to drive secure configurations and optimize security controls.
  • Participate in governance meetings and contribute to progress reporting and strategic planning efforts.
  • Develop technical documentation, operational runbooks, and knowledge transfer materials for internal teams.
Required Qualifications
  • 10+ years of experience in security engineering, security operations, or systems engineering with cybersecurity responsibilities.
  • Hands‑on experience with SIEM platforms such as Splunk, LogRhythm, Microsoft Sentinel, or similar technologies.
  • Experience with log onboarding, security monitoring, and detection engineering.
  • Strong understanding of identity security, including IAM, SSO, MFA, privileged access management, and role‑based access design.
  • Experience securing Windows and Linux environments, network infrastructure, and cloud workloads.
  • Experience implementing secure configuration baselines using CIS, DISA STIG, or comparable frameworks.
  • Proficiency in scripting and automation using PowerShell, Python, or similar languages.
  • Understanding of incident response engineering requirements, including visibility, forensic readiness, and data access considerations.
  • Experience working within regulated environments and security compliance frameworks such as NIST CSF, RMF, CJIS, or similar standards.
Preferred Qualifications
  • Experience supporting large enterprise or public‑sector environments.
  • Familiarity with SOAR platforms and security automation architecture.
  • Experience with vulnerability management tools and remediation workflow engineering.
  • Experience supporting hybrid security operations models involving internal teams and external service providers.
  • Relevant certifications such as CISSP, GSEC, GCIA, GCED, GCSA, AWS Security Specialty, or Azure Security certifications.
Expected Deliverables – Year One
  • Develop a SIEM/SOAR engineering plan with integration of at least 80% of core security tools.
  • Deploy 20‑50 tuned, risk‑based detection use cases.
  • Document logging and visibility improvements across identity, network, endpoint, and cloud environments.
  • Support development of incident response runbooks and cross‑functional operational documentation.
  • Conduct a baseline assessment of security tools and provide recommendations for future enhancements.
  • Deliver complete documentation for implemented controls, configurations, and integrations.
Engagement Structure
  • Hybrid work model requiring four days onsite in North Chesterfield, VA.
  • May support technical evaluations, product assessments, procurement activities, and contributions to solution documentation.

Everforth Apex is a world‑class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico.

Everforth Apex Benefits Overview: Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on‑demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our ‘Welcome Packet’ as well, which an Everforth Apex team member can provide.

Everforth Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Everforth Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law.

UnitedHealthcare creates and publishes the Transparency in Coverage Machine‑Readable Files on behalf of Everforth Apex Systems.

© 2026 Everforth, Inc. All rights reserved.

Everforth Apex Systems is part of the Commercial Segment of Everforth, Inc.

NYSE: EFOR

4400 Cox Road

Suite 200

Glen Allen, Virginia 23060

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT - SCDHHS - Security Analyst - Consultant
IT - SCDHHS - Security Analyst - Consultant

Apex Systems • Columbia (SC)

On-site
USD 65,000 - 90,000
Cyber Security Specialist MID - App Services EPS
Cyber Security Specialist MID - App Services EPS

Apex Systems • Norfolk (VA)

On-site
USD 70,000 - 110,000
Medical insurance
Dental insurance
Vision insurance
+1
Network / System Engineer III
Network / System Engineer III

Apex Systems • Chandler (AZ)

Hybrid
USD 130,000 - 180,000
Medical, dental, vision
401K with match
HSA plan
+4
Tier 1 SOC Analyst
Tier 1 SOC Analyst

Apex Systems • Rockville (MD)

On-site
USD 65,000 - 85,000
Elastic Security Analyst
Elastic Security Analyst

Apex Systems • Orlando (FL)

Hybrid
USD 48,000 - 69,000
Technical Advisor
Technical Advisor

Apex Systems • Fort Meade (MD)

On-site
USD 140,000 - 190,000
ESPP
401K program
HSA (Health Savings Account)
+2
Okta Engineering Lead
Okta Engineering Lead

Apex Systems • Indianapolis (IN)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+5
IT - ADMIN - Security Architect - Consultant
IT - ADMIN - Security Architect - Consultant

Apex Systems, LLC • Columbia (SC), Northern (KY)

Hybrid
USD 96,000 - 117,000
Medical benefits
401K with company match
Employee stock purchase program (ESPP)
+2
Tenable Security Engineer II
Tenable Security Engineer II

Apex Systems • Skokie (IL)

On-site
USD 100,000 - 130,000
Medical insurance
401K with company match
ESPP
+2
Network Security Analyst 1
Network Security Analyst 1

Apex Systems • Austin (TX)

On-site
USD 70,000 - 90,000
Medical, dental, vision insurance
401(k) with company match
Employee stock purchase program (ESPP)
+3