Come be a part of an exciting and ever-changing program that provides a comprehensive range of state-of-the-art solutions and hands-on assistance in designing, implementing, managing, and sustaining operations across various network environments for our customer.
We provide an environment that fosters and supports innovation and valuing "outside-the-box" thinking to solve complex problems. There are several training opportunities for team members that want to learn new technologies and stay current with their technical skillset. We are a highly technical group and nurture growth, with a technical culture of cross-trained teammates with opportunities to develop additional skillsets.
Work Schedule:
8hrs / day, 5 days per week, all onsite
Occasional after hours work for system maintenance
Essential Responsibilities:
We are seeking a highly motivated SOC Engineer to support the design, deployment, and continual improvement of enterprise Security Operations Center (SOC) capabilities. The successful candidate will serve as a key technical contributor responsible for SIEM engineering, log management architecture, threat detection development, security automation, and incident response support within classified environments.
This is a hands-on-keyboard position requiring expertise in deploying and maintaining security monitoring platforms, developing advanced detection capabilities, and improving the overall effectiveness of cyber defense operations. The SOC Engineer will work closely with cybersecurity analysts, incident responders, system administrators, network engineers, and customer stakeholders to enhance security visibility and defend critical mission systems against evolving threats.
Key Responsibilities include:
- Design, implement, configure, and maintain SIEM, log management, and security monitoring solutions supporting enterprise cybersecurity operations.
- Evaluate existing SOC architectures and recommend improvements to increase operational effectiveness, scalability, and threat visibility.
- Engineer and optimize log collection pipelines to ensure comprehensive security event coverage across network, system, application, and cloud environments.
- Develop, test, tune, and maintain detection content, including correlation searches, threat detections, alerts, signatures, and analytics.
- Identify gaps in detection coverage and implement solutions aligned with current threat intelligence and adversary techniques.
- Create and maintain SOC playbooks, standard operating procedures, and incident response workflows.
- Support security incident investigations through log analysis, endpoint analysis, malware analysis, and forensic data collection.
- Design and implement security automation and orchestration capabilities to reduce analyst workload and improve response times.
- Develop metrics, dashboards, and reporting capabilities to measure SOC performance, alert fidelity, detection effectiveness, and operational health.
- Participate in threat hunting activities to identify stealthy or previously undetected malicious activity.
- Support malware analysis efforts, including static and dynamic analysis techniques and reverse engineering activities when required.
- Author scripts and automation tools using languages such as Python, PowerShell, or Bash to improve SOC efficiency and detection capabilities.
- Document technical architectures, operational procedures, engineering designs, and implementation plans.
- Provide technical recommendations regarding emerging security technologies, tools, and best practices.
- Collaborate with customer stakeholders to understand mission requirements and translate those requirements into technical solutions.
Minimum Requirements:
- 6+ years of experience supporting Security Operations Centers (SOC), cybersecurity engineering, SIEM engineering, or Information System Security Engineering (ISSE).
- Experience deploying, administering, and maintaining Splunk Enterprise Security and/or other enterprise SIEM platforms.
- Strong understanding of security event management, log management, and threat detection methodologies.
- Experience developing SIEM correlation searches, analytic rules, dashboards, and detection use cases.
- Experience supporting cybersecurity operations within classified or highly regulated environments.
- Strong knowledge of Windows and Linux operating systems, including system administration and troubleshooting.
- Experience with scripting or automation using PowerShell, Python, Bash, or similar languages.
- Experience working within virtualized and containerized environments.
- Understanding of common attack frameworks such as MITRE ATT&CK and cyber kill chain methodologies.
- Knowledge of incident response, digital forensics, threat hunting and malware analysis principles.
- Experience producing technical documentation, architecture diagrams, implementation plans, and engineering reports.
- Strong communication and customer engagement skills with the ability to explain technical concepts to both technical