SOC Engineer

Merlin Group

McLean (VA)

On-site

USD 120,000 - 150,000

Full time

36 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

On-site gym & wellness benefits
401(k) with employer match

Job summary

Merlin Group in McLean, VA is seeking a SOC Engineer to design, build, and operate the security operations platform with a focus on automation and detection engineering. You will partner with SOC analysts to develop reliable detections, workflows, and infrastructure that scale as needs grow.

You will collaborate with the SOC Manager, Engineering, Infrastructure, and GRC teams to maintain security, compliance, and scalable operation of the SOC tooling.

Qualifications

  • 4+ years of experience in SOC-related roles.
  • Deep hands-on experience with Splunk, SPL, CIM, and Enterprise Security.
  • Experience with SOAR platforms and REST/webhooks integration.
  • Proficiency in at least one scripting language and Git-based CI/CD.
  • Working knowledge of AWS security services and Terraform.
  • Experience with ITSM platforms (ServiceNow preferred).

Responsibilities

  • Design, build, and tune detections in Splunk, mapping coverage to MITRE ATT&CK and managing rules with version control and peer review.
  • Onboard and maintain log sources across AWS, Azure, and GCP with forwarders and retention controls for FedRAMP audit logging.
  • Build and maintain Torq workflows for alert enrichment, triage, containment, and case handling, integrating with Splunk, ServiceNow, cloud APIs, and other SOC tools.
  • Engineer and operate the SOC platform in AWS, including IaC, deployment pipelines, IAM, secrets management, and monitoring.
  • Produce and maintain runbooks and architecture diagrams for detections and automation.
  • Serve as engineering escalation point during incidents and participate in on-call rotations.

Skills

SOC engineering
Detection engineering
Automation
Scripting
CI/CD
Git workflows

Tools

Splunk
Torq
ServiceNow
AWS
Terraform
REST APIs

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Full Time McLean, VA, US

About Merlin Group

Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions.

At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact.

The Opportunity

We are looking for a SOC Engineer to build, operate, and improve the technical capabilities behind our security operations. While the role is primarily focused on security automation and platform engineering, detection engineering will play a large part as well. You will partner closely with SOC analysts to turn their needs into reliable detections, workflows, and infrastructure, and work with the SOC Manager, Engineering, Infrastructure, and GRC teams to keep the platform secure, compliant, and scalable.

Primary Duties & Responsibilities
  • Design, build, and tune detections in Splunk using SPL, mapping coverage to knowledge bases like MITRE ATT&CK and managing rules through the team's detection-as-code process with version control, testing, and peer review, while tracking false positive rates, alert volume, and coverage gaps with analysts to prioritize tuning and new content
  • Onboard, normalize, and maintain log sources and collection pipelines across AWS, Azure, and GCP, including CloudTrail, GuardDuty, Azure Activity and Entra ID logs, GCP Cloud Audit Logs, and endpoint, identity, and network telemetry, with forwarders, ingestion, retention, and integrity controls that satisfy FedRAMP audit logging requirements
  • Build and maintain Torq workflows for alert enrichment, triage, containment, and case handling, integrating with Splunk, ServiceNow, cloud provider APIs, and other SOC tools so alerts arrive as enriched ServiceNow cases with consistent fields, ownership, and SLAs, reducing analyst toil and mean time to respond
  • Engineer and operate the SOC tooling platform in AWS, including Infrastructure as Code (IaC), deployment pipelines, IAM, secrets management, and monitoring systems
  • Produce and maintain documentation, runbooks, and architecture diagrams for detections, automation playbooks, and platform components, and supply evidence for audits and control assessments
  • Serve as an engineering escalation point during incidents and participate in an on-call rotation for SOC platform issues
Qualifications
  • 4+ years of experience in SOC engineering, detection engineering, security engineering, or a closely related role
  • Deep hands-on experience with Splunk, including SPL, correlation searches, data models and CIM, knowledge object management, index and sourcetype design, and Splunk Enterprise Security
  • Experience building automation with a Security Orchestration, Automation, and Response (SOAR) platform (Torq strongly preferred) and integrating tools through REST APIs and webhooks
  • Proficiency in at least one scripting language, and comfort with Git-based workflows and CI/CD pipelines
  • Working knowledge of AWS services relevant to security operations (IAM, CloudTrail, GuardDuty, Security Hub, Lambda, S3, VPC) and IaC tooling such as Terraform
  • Experience working with an IT Service Management (ITSM) platform (ServiceNow preferred)
Preferred Qualifications
  • Experience supporting FedRAMP Moderate or High environments or other NIST 800-53 based programs
  • Experience with detection-as-code frameworks and CI/CD for security content, such as Sigma
  • Experience configuring or integrating the ServiceNow Security Incident Response module
  • Prior work in a managed security services or multi-tenant SOC environment
Success Attributes
  • Commitment to personal and professional integrity and respect for others.
  • Roll-up-your-sleeves attitude and low-ego approach.
  • Commitment to teamwork and professional relationship development.
  • Passion for lifelong learning, growth, and development.
  • Flexible and nimble; comfortable with ambiguity and rapid change.
  • Strong communication and functional project management skills.
  • Desire to innovate, try new things, and creatively explore novel solutions to business challenges.
  • Professional and respectful approach to the diversity of thought, action, identity, and attributes.

We want to empower and inspire employees to be and do their best. Our workdays are dynamic, collegial, and fun. Our office features multiple places to work unconstrained by typical office barriers.

  • Our wellness package provides access to an on-site gym and includes medical, dental, and vision insurance along with options for FSA and EAP.
  • We offer 401(k) with employer match, unlimited PTO, and a culture respectful of the reality that not everything in one’s personal life is guaranteed to happen only after hours.

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

CGC • McLean (VA), Northern (KY)

Hybrid
USD 120,000 - 160,000
On-site gym and health insurance
401(k) with employer match
Unlimited PTO
SOC Engineer
SOC Engineer

Constellation GovCloud • McLean (VA)

On-site
USD 120,000 - 170,000
On-site gym
Medical, dental, and vision insurance
FSA and EAP
+2
SOC Engineer
SOC Engineer

Merlin International Inc • McLean (VA)

On-site
USD 110,000 - 140,000
SOC Engineer
SOC Engineer

Amentum • Ellicott City (MD)

On-site
USD 145,000 - 190,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+6
SOC Engineer
SOC Engineer

Bayview Fund Management, LLC • Coral Gables (FL)

On-site
USD 160,000 - 180,000
Remote role
Bonus eligibility
SOC Engineer
SOC Engineer

Bayview Asset Management, LLC • Coral Gables (FL)

Remote
USD 160,000 - 180,000
IT Security Engineer
IT Security Engineer

Pike Corporation • Fort Mill (SC)

On-site
USD 120,000 - 180,000
Dev/Ops Engineer
Dev/Ops Engineer

Constellation GovCloud • McLean (VA)

On-site
USD 120,000 - 180,000
On-site gym
401(k) with employer match
Unlimited PTO
Dev/Ops Engineer
Dev/Ops Engineer

Merlin International Inc • McLean (VA)

On-site
USD 110,000 - 150,000
On-site gym
Medical insurance
Dental insurance
+3
Information Systems Security Manager
Information Systems Security Manager

Merlin International Inc • McLean (VA)

On-site
USD 140,000 - 190,000
On-site gym
Medical, dental, and vision insurance
401(k) with employer match
+1