IT SOC Engineer I

ecsfederal

Virginia (MN)

Hybrid

USD 100,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Everforth ECS is seeking an IT SOC Engineer I to work remotely, supporting the DFC CISO within the OIT. The role entails governance, risk management, compliance, security architecture, standards, and CSF-aligned monitoring and threat intel.

The position requires a Secret clearance, 3+ years in cybersecurity, and hands-on SOC experience with SIEMs and tools like Splunk and Defender. Salary range is $100,000–$120,000 with full benefits.

Qualifications

  • Active Secret clearance required.
  • 3+ years technical cybersecurity experience.
  • 8570.01/8140.03 Cybersecurity certification (CompTIA Security+ CE).
  • Experience mitigating security control vulnerabilities (STIG, NIST SP 800-53, RMF).
  • Hands-on SOC operations experience in an enterprise environment.
  • Experience with SIEM platforms for Tier 1 monitoring, triage and escalation.
  • Experience managing and resolving SOC ticket queues.
  • Experience phishing triage and investigations.
  • Hands-on with Defender, Splunk, Security Onion, Absolute or similar.
  • Ability to analyze alerts and follow incident response procedures.

Responsibilities

  • Perform forensic analysis on digital media to identify and obfuscate incident content.
  • Consult with security operations on cybersecurity communications and investigations.
  • Provide expertise on adversary capabilities and assessments of CNE/CNA intentions.
  • Conduct onsite and remote vulnerability assessments as a sustained program.
  • Coordinate internal and external penetration testing to identify bypass methods.
  • Filter and prioritize threat data into concise intelligence.
  • Support SOC tools through research, testing, deployment, and maintenance.
  • Advise SOC architecture activities for information systems initiatives.
  • Create procedures for maintaining SOC hardware and software.
  • Document security changes and assess impact on information systems.
  • Oversee monitoring controls and remediation actions per POA&M.
  • Update System Security Plan, SAR, and POA&Ms; report risk status.
  • Work with DFC CIRT or external vendors during incidents.

Skills

Active Secret clearance
Cybersecurity
SOC operations
SIEM
Threat intelligence
Incident response

Tools

Splunk
Security Onion
Microsoft Defender
Absolute

Job description

Everforth ECS is seeking an IT SOC Engineer I to work remotely.

Everforth ECS currently seeks a Cybersecurity professional to join our team in support of US International Development Finance Corporation's (DFC)’s Chief Information Security Officer (CISO) within the Office of Information Technology (OIT). This position will provide governance, risk management, compliance support, security architecture, standards and design, cybersecurity monitoring (Detection, Response, and Prevention), and threat intelligence. The functions provided will comply with the NIST RMF per Office of Management and Budget (OMB) guidance and the NIST Cybersecurity Framework (CSF) Functions aligned with proven industry standards and best practices.

Responsibilities
  • Responsible for performance of forensic analysis on various digital media devices and mediums to identify, reverse engineer, and obfuscate content related to an incident, such as malicious content.
  • Consult with security operations regarding cybersecurity communications and deliver or request assistance or assist with investigations.
  • Provide technical expertise in cyber adversary capabilities and an assessment of the intentions of these groups to conduct Computer Network Exploitation (CNE) and Computer Network Attack (CNA) against U.S. private sector and Government networks and information systems.
  • Consult and provide onsite and remote vulnerability assessment capabilities as a sustained, full-time program independent of incident detection, recovery, or reporting activities.
  • Consult both internal and external penetration and security testing which mimics real-world attacks to identify methods for circumventing the security features of an application, system, and network.
  • Consult with teams to detect, prevent, and respond to threats posed by malicious, negligent, or compromised insiders by maintaining in-depth visibility into the DFC Enterprise and having a means of filtering and prioritizing threat data into concise, actionable intelligence.
  • Provide expert security engineering and subject matter expertise to conduct market research, product evaluation, testing, configuration, deployment, operations, and maintenance support for various SOC software tools and technologies.
  • Advise and assist with SOC architecture activities for all DFC SOC information systems initiatives supporting all SOC tools and capabilities.
  • Create procedures and documentation for maintaining SOC hardware and software.
  • Determine and document the security impact of proposed or actual changes to the information systems and their environment of operation.
  • Assess the technical, management, and operational security controls employed within and inherited by the information systems in accordance with the organization defined monitoring strategy.
  • Facilitate and perform remediation actions based on the results of ongoing monitoring activities and the outstanding items in the POA&M.
  • Update the System Security Plan, SAR, and POA&Ms. Key Deliverables: updated Residual Risk Statement and Risk Acceptance Recommendation Report.
  • Report the security status of information systems to appropriate organizational officials on an ongoing basis.
  • Review the reported security status of information systems ongoing Risk Determination and Acceptance.
  • Incident Assessment and Response Support; work with the DFC CIRT or any other pertinent parties (including external vendors) at any DFC location to recover from any incident.

Salary Range: $100,000 - $120,000

General Description of Benefits

  • Must possess an Active Secret clearance.
  • 3+ years of technical experience in Cybersecurity,maintaining IT security policies, processes, and guidance.
  • 8570.01/8140.03 Cybersecurity certification. (CompTia Security+CE)
  • Experience with mitigation of security control vulnerabilities based on Cybersecurity principles and tenets. (e.g., STIG, NIST SP 800-53, Cybersecurity Risk Management Framework, etc.).
  • Hands-on experience supporting Security Operations Center (SOC) operations in an enterprise environment.
  • Experience performing Tier 1 security alert monitoring, triage, investigation, and escalation using SIEM platforms.
  • Experience managing and resolving SOC ticket queues, including documenting findings, escalating incidents, and tracking issues through resolution.
  • Experience performing phishing email triage and analysis, including supporting phishing investigations and campaigns.
  • Hands-on experience with security tools and platforms such as Microsoft Defender, Splunk, Security Onion, and Absolute, or similar technologies.
  • Ability to analyze security alerts and events, identify potential threats, and follow established incident response and escalation procedures.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst IV
SOC Analyst IV

ecsfederal • Virginia (MN)

Hybrid
USD 120,000 - 140,000
Remote IT SOC Engineer I - Cyber Threat Defense
Remote IT SOC Engineer I - Cyber Threat Defense

ECS • Richmond (VA)

On-site
USD 100,000 - 120,000
Incident Detection/Response Manager (SOC Manager)
Incident Detection/Response Manager (SOC Manager)

ecsfederal • Virginia (MN)

Hybrid
USD 140,000 - 160,000
Remote IT SOC Engineer I — Cyber Defense
Remote IT SOC Engineer I — Cyber Defense

ecsfederal • Virginia (MN)

Hybrid
USD 100,000 - 120,000
SOC Analyst
SOC Analyst

Tactibit • Suitland (MD)

On-site
USD 85,000 - 110,000
Security Operations Center Technical SME
Security Operations Center Technical SME

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 120,000 - 150,000
Tier 2 Cybersecurity Engineer
Tier 2 Cybersecurity Engineer

On Call Computer Solutions, LLC • Houston (TX)

On-site
USD 110,000 - 170,000
Health insurance
Retirement plan
Disability insurance
+3
Tier 2 Cybersecurity Engineer
Tier 2 Cybersecurity Engineer

On Call Computer Solutions, LLC • Tallahassee (FL)

On-site
USD 110,000 - 150,000
Health insurance
Life insurance
128 Hours PTO
+1
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Senior SOC Analyst
Senior SOC Analyst

KeenLogic • Merrifield (VA)

On-site
USD 120,000 - 160,000
Health/dental/vision benefits
PTO
401k
+1