SIEM/SOAR Engineer - Cloud Sec Spec 3

Softthink Solutions

Washington (District of Columbia)

On-site

USD 180,000 - 240,000

Full time

10 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Softthink Solutions is seeking a seasoned SIEM/SOAR Engineer to design and optimize the Google SecOps SIEM/SOAR environment for enterprise operations in Washington, DC.

You will configure ingestion pipelines, validate log flows, and implement detections and automation to support secure monitoring. The role requires cloud telemetry experience and strong collaboration with incident response teams.

Qualifications

  • 10+ years of experience in SIEM/SOAR platforms (Google SecOps preferred).
  • Experience building detection rules, automation workflows, and parser validation.
  • Experience with cloud telemetry ingestion (Azure, AWS, on‑prem).

Responsibilities

  • Configure ingestion pipelines and validate end‑to‑end log flow.
  • Implement Google curated detections and build custom detection rules.
  • Develop SOAR playbooks for SBA’s top incident categories.
  • Integrate threat intelligence sources (Mandiant, Virus Total).
  • Tune detections to meet false‑positive thresholds.
  • Support UEBA dashboard configuration and risk scoring.
  • Assist with runbook creation, analyst training, and operational transition.

Skills

SIEM/SOAR expertise
Google SecOps
Threat intelligence integration
Cloud telemetry ingestion
Detection rule development
Automation workflows
Parser validation
UEBA configuration

Education

Bachelor’s degree in Cybersecurity/IT or related field

Tools

GCP Security Suite
Cloud telemetry tools (Azure/AWS)

Job description

SIEM/SOAR Engineer (Cloud Sec Spec 3)
Location: Washington, DC
Work Authorization: US Citizen
Role Summary

The SIEM/SOAR Engineer builds and configures the Google SecOps SIEM/SOAR environment, ensuring ingestion pipelines, detections, playbooks, and automation workflows are fully operational and optimized for SBA’s enterprise security operations.

Roles & Responsibilities
  • Configure ingestion pipelines and validate end‑to‑end log flow.
  • Implement Google curated detections and build custom detection rules.
  • Develop SOAR playbooks for SBA’s top incident categories.
  • Integrate threat intelligence sources (Mandiant, Virus Total).
  • Tune detections to meet false‑positive thresholds.
  • Support UEBA dashboard configuration and risk scoring.
  • Assist with runbook creation, analyst training, and operational transition.
Professional Experience Required
  • 10+ years of experience with SIEM/SOAR platforms (Google SecOps preferred).
  • Experience building detection rules, automation workflows, and parser validation.
  • Experience with cloud telemetry ingestion (Azure, AWS, on‑prem).
  • Experience with threat intelligence integration.
Educational Qualification
  • Bachelor’s degree in Cybersecurity, IT, or related field.
Certifications
  • Google SecOps, GIAC, CISSP, or equivalent preferred.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SIEMSOAR Engineer Cloud Sec Spec 3
SIEMSOAR Engineer Cloud Sec Spec 3

Softthink Solutions Inc • Washington

On-site
USD 180,000 - 210,000
Cloud SecOps SIEM/SOAR Engineer (Google SecOps)
Cloud SecOps SIEM/SOAR Engineer (Google SecOps)

Softthink Solutions Inc • Washington

On-site
USD 180,000 - 210,000
Lead SecOps Engineer Cloud Sec Spec 3
Lead SecOps Engineer Cloud Sec Spec 3

Softthink Solutions Inc • Washington

On-site
USD 170,000 - 210,000
Lead SecOps Engineer - Cloud Sec Spec 3
Lead SecOps Engineer - Cloud Sec Spec 3

Softthink Solutions • Washington

On-site
USD 180,000 - 240,000
Cloud SecOps SIEM/SOAR Engineer
Cloud SecOps SIEM/SOAR Engineer

Softthink Solutions • Washington

On-site
USD 180,000 - 240,000
Senior SecOps Architect - Cloud Security & SIEM Lead
Senior SecOps Architect - Cloud Security & SIEM Lead

Softthink Solutions • Washington

On-site
USD 180,000 - 240,000
Senior SecOps Engineer - Cloud Security Lead
Senior SecOps Engineer - Cloud Security Lead

Softthink Solutions Inc • Washington

On-site
USD 170,000 - 210,000
Zero Trust / IAM Engineer Cloud Sec Spec 3
Zero Trust / IAM Engineer Cloud Sec Spec 3

Softthink Solutions • Washington

On-site
USD 140,000 - 180,000
Detection Engineering SME
Detection Engineering SME

Softthink Solutions Inc • Washington

On-site
USD 150,000 - 190,000
Security Operations Engineer - Level 3
Security Operations Engineer - Level 3

Veriipro • Blue Ash (OH)

On-site
USD 105,000 - 145,000