Cybersecurity Engineer | SIEM, SOAR, Security Operations & Cloud Security

Apex Systems

Virginia (MN)

Hybrid

USD 83,000 - 152,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Apex Systems is seeking a seasoned Cybersecurity Engineer to strengthen Security Engineering & Operations, focusing on SIEM/SOAR integrations, secure baselines, and cloud security across identity, endpoints, and network environments.

The role collaborates with IT operations, application teams, and SOC analysts in a hybrid North Chesterfield, VA setting. 10+ years in security engineering and hands-on SIEM skills are essential.

Qualifications

  • 10+ years in security engineering, security operations, or systems engineering with cybersecurity responsibilities.
  • Hands-on experience with SIEM platforms such as Splunk, LogRhythm, Microsoft Sentinel, or similar.
  • Experience with log onboarding, security monitoring, and detection engineering.
  • Strong understanding of identity security, including IAM, SSO, MFA, privileged access management, and RBAC.
  • Experience securing Windows and Linux environments, network infrastructure, and cloud workloads.
  • Experience implementing secure configuration baselines using CIS, DISA STIG, or similar frameworks.
  • Proficiency in scripting/automation using PowerShell, Python, or similar languages.
  • Understanding of incident response engineering requirements, including visibility, forensic readiness, and data access considerations.
  • Experience with security compliance frameworks such as NIST CSF, RMF, CJIS.

Responsibilities

  • Design and implement security controls across identity, network, endpoint, and cloud environments.
  • Lead SIEM/SOAR integrations, including log onboarding, parsing, normalization, and automation readiness.
  • Implement secure configuration and baseline management for critical infrastructure, servers, workstations, and cloud assets.
  • Support enterprise security architecture development, including secure-by-design reviews with application and infrastructure teams.
  • Develop and tune detection use cases aligned with the security operations roadmap, prioritized by risk and threat exposure.
  • Engineer identity security controls, including IAM/PAM hardening, RBAC, and integration with monitoring solutions.
  • Implement cryptographic management practices, key lifecycle controls, and validation processes for sensitive systems.
  • Build logging pipelines to ensure visibility across endpoints, servers, network devices, identity platforms, and cloud services.
  • Support vulnerability management engineering, including scanner integration, asset classification, and remediation workflow design.
  • Partner with security operations personnel to develop and tune detection rules, correlation logic, and enrichment processes.
  • Participate in incident investigations and root-cause analysis with a focus on engineering solutions to prevent recurrences.
  • Implement threat intelligence ingestion pipelines and integrate intelligence feeds into detection and response processes.
  • Identify high-impact opportunities for security automation, including alert enrichment, ticket creation, and response workflow orchestration.

Skills

Security engineering
Security operations
Automation scripting
Incident response
Documentation

Education

Bachelor's degree in CS or cybersecurity
CISSP or equivalent

Tools

Splunk
LogRhythm
Microsoft Sentinel
PowerShell
Python

Job description

# Cybersecurity Engineer | SIEM, SOAR, Security Operations & Cloud SecurityApply**Job#: 3052876****Job Description:**Cybersecurity Engineer (Contractor)LocationNorth Chesterfield, VA (Hybrid)Engagement12-month contract with option to extendReports ToDirector of Security Engineering & OperationsScreeningMust be able to pass a background investigationPosition OverviewOur client is strengthening and modernizing its Security Engineering & Operations capabilities as part of a broader effort to mature its cybersecurity posture. The organization is expanding its engineering depth, enhancing existing SIEM, EDR, and SOC practices, and evaluating the optimal team model for future growth. This initiative focuses on elevating current capabilities, closing visibility gaps, and evolving the tools, processes, and operational practices that will support a mature cybersecurity program.The Cybersecurity Engineer will help broaden and strengthen core engineering functions that enable an effective SOC model, including SIEM/SOAR integration, identity and endpoint security engineering, secure configuration baselines, and cloud and enterprise architecture support. This role partners with IT operations, application teams, and SOC analysts while operating within an evolving security organization. Success in this role requires adaptability, process improvement experience, strong documentation habits, and a hands-on technical mindset.Key ResponsibilitiesSecurity Engineering & Architecture* Design and implement security controls across identity, network, endpoint, and cloud environments.* Lead SIEM/SOAR integrations, including log onboarding, parsing, normalization, and automation readiness.* Implement secure configuration and baseline management for critical infrastructure, servers, workstations, and cloud assets.* Support enterprise security architecture development, including secure-by-design reviews with application and infrastructure teams.* Develop and tune detection use cases aligned with the security operations roadmap, prioritized by risk and threat exposure.* Engineer identity security controls, including IAM/PAM hardening, role-based access validation, and integration with monitoring solutions.* Implement cryptographic management practices, key lifecycle controls, and validation processes for sensitive systems.Security Operations Enablement* Build and maintain logging pipelines to ensure visibility across endpoints, servers, network devices, identity platforms, and cloud services.* Support vulnerability management engineering, including scanner integration, asset classification, and remediation workflow design.* Partner with security operations personnel to develop and tune detection rules, correlation logic, and enrichment processes.* Participate in incident investigations and root-cause analysis with a focus on implementing engineering solutions that prevent recurring issues.* Implement threat intelligence ingestion pipelines and integrate intelligence feeds into detection and response processes.Automation & Modernization* Identify and implement high-impact opportunities for security automation, including alert enrichment, ticket creation, and response workflow orchestration.* Evaluate tool health, tuning opportunities, and integration gaps; provide recommendations to support the cybersecurity modernization roadmap.* Support emerging AI-assisted capabilities designed to improve security operations and analyst effectiveness.Collaboration & Cross-Functional Coordination* Work closely with IT operations, infrastructure, endpoint management, and application teams to drive secure configurations and optimize security controls.* Participate in governance meetings and contribute to progress reporting and strategic planning efforts.* Develop technical documentation, operational runbooks, and knowledge transfer materials for internal teams.Required Qualifications* 10+ years of experience in security engineering, security operations, or systems engineering with cybersecurity responsibilities.* Hands-on experience with SIEM platforms such as Splunk, LogRhythm, Microsoft Sentinel, or similar technologies.* Experience with log onboarding, security monitoring, and detection engineering.* Strong understanding of identity security, including IAM, SSO, MFA, privileged access management, and role-based access design.* Experience securing Windows and Linux environments, network infrastructure, and cloud workloads.* Experience implementing secure configuration baselines using CIS, DISA STIG, or comparable frameworks.* Proficiency in scripting and automation using PowerShell, Python, or similar languages.* Understanding of incident response engineering requirements, including visibility, forensic readiness, and data access considerations.* Experience working within regulated environments and security compliance frameworks such as NIST CSF, RMF, CJIS, or similar standards.Preferred Qualifications* Experience supporting large enterprise or public-sector environments.* Familiarity with SOAR platforms and security automation architecture.* Experience with vulnerability management tools and remediation workflow engineering.* Experience supporting hybrid security operations models involving internal teams and external service providers.* Relevant certifications such as CISSP, GSEC, GCIA, GCED, GCSA, AWS Security Specialty, or Azure Security certifications.Expected Deliverables – Year One* Develop a SIEM/SOAR engineering plan with integration of at least 80% of core security tools.* Deploy 20-50 tuned, risk-based detection use cases.* Document logging and visibility improvements across identity, network, endpoint, and cloud environments.* Support development of incident response runbooks and cross-functional operational documentation.* Conduct a baseline assessment of security tools and provide recommendations for future enhancements.* Deliver complete documentation for implemented controls, configurations, and integrations.Engagement Structure* Hybrid work model requiring four days onsite in North Chesterfield, VA.* May support technical evaluations, product assessments, procurement activities, and contributions to solution documentation.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer -- EX35495922860
Cyber Security Engineer -- EX35495922860

Compunnel Inc. • Richmond (VA)

On-site
USD 140,000 - 210,000
Senior Cybersecurity Engineer: SIEM/SOAR & Cloud Security
Senior Cybersecurity Engineer: SIEM/SOAR & Cloud Security

Apex Systems • Virginia (MN)

Hybrid
USD 83,000 - 152,000
Hybrid work model
Cybersecurity Engineer — Hybrid, 12-Month Contract
Cybersecurity Engineer — Hybrid, 12-Month Contract

Apex Systems • Richmond (VA)

Hybrid
USD 96,000 - 165,000
401K match
HSA
ESPP
+2
Cybersecurity Engineer
Cybersecurity Engineer

DataStaff, Inc. • Richmond (VA)

On-site
USD 110,000 - 150,000
Medical insurance
Dental coverage
Vision coverage
+2
Senior Security Engineer
Senior Security Engineer

Matlen Silver • Charlotte (NC)

Hybrid
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Matlen Silver • Chandler (AZ)

Hybrid
USD 120,000 - 160,000
Cybersecurity Engineer – Security Infrastructure & Automation Lead
Cybersecurity Engineer – Security Infrastructure & Automation Lead

Charter Global • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Cybersecurity Engineer | SIEM, SOAR, Security Operations & Cloud Security
Cybersecurity Engineer | SIEM, SOAR, Security Operations & Cloud Security

Apex Systems • Richmond (VA)

Hybrid
USD 96,000 - 165,000
401K match
HSA
ESPP
+2
Cybersecurity Engineer 3 – Contract Position
Cybersecurity Engineer 3 – Contract Position

BranCore Technologies • Richmond (VA)

On-site
USD 110,000 - 165,000
Analyst, Cyber Security II
Analyst, Cyber Security II

TALENT Software Services • Columbia (SC)

On-site
USD 90,000 - 140,000