SOC Engineer

Amentum

Columbia (MD)

On-site

USD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Amentum is seeking a highly skilled SOC Engineer to design, deploy, and optimize enterprise SIEM and log management capabilities in support of mission-critical environments. You will build detection content, automate responses, and collaborate with analysts, system admins, and customers to strengthen cyber defense.

The role emphasizes hands-on work in SIEM engineering, incident response, and threat detection, with opportunities to improve architectures and playbooks in a demanding, onsite

Qualifications

  • 6+ years of experience in SOC, cybersecurity engineering, SIEM engineering, or ISSE.
  • Experience deploying and maintaining Splunk Enterprise Security or other enterprise SIEMs.
  • Strong understanding of security event management, log management, and threat detection.
  • Experience developing SIEM correlation searches, analytic rules, dashboards, and detection use cases.
  • Experience in highly regulated/classified environments.
  • Strong knowledge of Windows and Linux OS, including administration.
  • Experience with scripting/automation (PowerShell, Python, Bash).
  • Experience in virtualized/containerized environments.
  • Knowledge of incident response, digital forensics, threat hunting and malware analysis.

Responsibilities

  • Design, implement, configure, and maintain SIEM, log management, and security monitoring solutions.
  • Evaluate existing SOC architectures and recommend improvements for scalability and threat visibility.
  • Engineer and optimize log collection pipelines across network, system, application, and cloud environments.
  • Develop, test, and maintain detection content, including correlation searches and analytics.
  • Identify gaps in detection coverage and implement threat-informed solutions.
  • Create and maintain SOC playbooks, SOPs, and incident response workflows.
  • Support investigations via log analysis, endpoint analysis, malware analysis, and forensics.
  • Design security automation/orchestration to reduce analyst workload and speed responses.
  • Develop SOC metrics, dashboards, and reporting for performance and health.
  • Participate in threat hunting to identify stealthy activity.
  • Support malware analysis activities and reverse engineering as needed.
  • Author scripts/tools in Python/PowerShell/Bash to improve SOC efficiency.
  • Document architectures, procedures, and engineering designs.
  • Provide technical recommendations on emerging security technologies.
  • Collaborate with customer stakeholders to translate mission requirements to solutions.

Skills

SIEM engineering
Log management
Threat detection
Security automation
Incident response
Python
PowerShell
Bash
Windows
Linux
MITRE ATT&CK
Threat hunting

Tools

Splunk Enterprise Security

Job description

Come be a part of an exciting and ever-changing program that provides a comprehensive range of state-of-the-art solutions and hands-on assistance in designing, implementing, managing, and sustaining operations across various network environments for our customer.

We provide an environment that fosters and supports innovation and valuing "outside-the-box" thinking to solve complex problems. There are several training opportunities for team members that want to learn new technologies and stay current with their technical skillset. We are a highly technical group and nurture growth, with a technical culture of cross-trained teammates with opportunities to develop additional skillsets.

Work Schedule:

8hrs / day, 5 days per week, all onsite

Occasional after hours work for system maintenance

Essential Responsibilities:

We are seeking a highly motivated SOC Engineer to support the design, deployment, and continual improvement of enterprise Security Operations Center (SOC) capabilities. The successful candidate will serve as a key technical contributor responsible for SIEM engineering, log management architecture, threat detection development, security automation, and incident response support within classified environments.

This is a hands-on-keyboard position requiring expertise in deploying and maintaining security monitoring platforms, developing advanced detection capabilities, and improving the overall effectiveness of cyber defense operations. The SOC Engineer will work closely with cybersecurity analysts, incident responders, system administrators, network engineers, and customer stakeholders to enhance security visibility and defend critical mission systems against evolving threats.

Key Responsibilities include:
  • Design, implement, configure, and maintain SIEM, log management, and security monitoring solutions supporting enterprise cybersecurity operations.
  • Evaluate existing SOC architectures and recommend improvements to increase operational effectiveness, scalability, and threat visibility.
  • Engineer and optimize log collection pipelines to ensure comprehensive security event coverage across network, system, application, and cloud environments.
  • Develop, test, tune, and maintain detection content, including correlation searches, threat detections, alerts, signatures, and analytics.
  • Identify gaps in detection coverage and implement solutions aligned with current threat intelligence and adversary techniques.
  • Create and maintain SOC playbooks, standard operating procedures, and incident response workflows.
  • Support security incident investigations through log analysis, endpoint analysis, malware analysis, and forensic data collection.
  • Design and implement security automation and orchestration capabilities to reduce analyst workload and improve response times.
  • Develop metrics, dashboards, and reporting capabilities to measure SOC performance, alert fidelity, detection effectiveness, and operational health.
  • Participate in threat hunting activities to identify stealthy or previously undetected malicious activity.
  • Support malware analysis efforts, including static and dynamic analysis techniques and reverse engineering activities when required.
  • Author scripts and automation tools using languages such as Python, PowerShell, or Bash to improve SOC efficiency and detection capabilities.
  • Document technical architectures, operational procedures, engineering designs, and implementation plans.
  • Provide technical recommendations regarding emerging security technologies, tools, and best practices.
  • Collaborate with customer stakeholders to understand mission requirements and translate those requirements into technical solutions.
Minimum Requirements:
  • 6+ years of experience supporting Security Operations Centers (SOC), cybersecurity engineering, SIEM engineering, or Information System Security Engineering (ISSE).
  • Experience deploying, administering, and maintaining Splunk Enterprise Security and/or other enterprise SIEM platforms.
  • Strong understanding of security event management, log management, and threat detection methodologies.
  • Experience developing SIEM correlation searches, analytic rules, dashboards, and detection use cases.
  • Experience supporting cybersecurity operations within classified or highly regulated environments.
  • Strong knowledge of Windows and Linux operating systems, including system administration and troubleshooting.
  • Experience with scripting or automation using PowerShell, Python, Bash, or similar languages.
  • Experience working within virtualized and containerized environments.
  • Understanding of common attack frameworks such as MITRE ATT&CK and cyber kill chain methodologies.
  • Knowledge of incident response, digital forensics, threat hunting and malware analysis principles.
  • Experience producing technical documentation, architecture diagrams, implementation plans, and engineering reports.
  • Strong communication and customer engagement skills with the ability to explain technical concepts to both technical
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Center (SOC) Analyst
Security Operations Center (SOC) Analyst

10xTalents • Washington

On-site
USD 80,000 - 110,000
Security Operations Center Technical SME
Security Operations Center Technical SME

Evans & Chambers Technology • Fort Meade (MD)

On-site
USD 120,000 - 150,000
SOC Engineer
SOC Engineer

Socket.dev • Columbia (MD)

On-site
USD 145,000 - 190,000
Health insurance
401(k) matching
Educational reimbursement
+5
SOC Engineer
SOC Engineer

Amentum • Ellicott City (MD)

On-site
USD 145,000 - 190,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+6
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000
Senior SOC Engineer
Senior SOC Engineer

Inversion6 • Westlake (OH)

Hybrid
USD 110,000 - 150,000
Senior Cyber Security Architect
Senior Cyber Security Architect

Jobtailor • Duluth (GA)

On-site
USD 90,000 - 120,000
SIEM Engineer III
SIEM Engineer III

ECS Corporate Services • Fairfax (VA)

On-site
USD 120,000 - 170,000
Senior SOC Engineer
Senior SOC Engineer

TRG • Westlake (OH)

Hybrid
USD 110,000 - 160,000
Senior Security Operations Center (SOC) Engineer
Senior Security Operations Center (SOC) Engineer

IT Data Consulting, LLC • Reston (VA)

On-site
USD 110,000 - 140,000