SOC Engineer

Constellation GovCloud

McLean (VA)

On-site

USD 120,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

On-site gym
Medical, dental, and vision insurance
FSA and EAP
401(k) with employer match
Unlimited PTO

Job summary

Merlin Group in McLean, VA is seeking a SOC Engineer to build and improve security operations. You will partner with SOC analysts to turn needs into detections, workflows, and infrastructure, and collaborate with SOC Manager and IT teams to keep the platform secure and scalable.

The role emphasizes security automation, detection engineering, and platform engineering across AWS, Azure, and GCP, with on-call rotation and incident escalation.

Qualifications

  • 4+ years of experience in SOC engineering or related security roles.
  • Hands-on Splunk experience (SPL, CIM, ES).
  • Automation with SOAR (Torq preferred) and API/webhook integration.
  • Proficiency in a scripting language and Git-based CI/CD workflows.
  • Knowledge of AWS security services (IAM, CloudTrail, GuardDuty, Security Hub) and Terraform.
  • Experience with ITSM platforms (ServiceNow preferred).

Responsibilities

  • Design, implement, and tune detections in Splunk with detectors and mapping to MITRE ATT&CK.
  • Onboard and maintain log sources across AWS, Azure, and GCP with FedRAMP-ready controls.
  • Build Torq workflows for alert enrichment, triage, containment, and case handling.
  • Engineer and operate the SOC tooling platform in AWS with IaC and CI/CD pipelines.
  • Produce runbooks and architecture diagrams for detections and automation.
  • Serve as engineering escalation during incidents and participate in on-call rotations.

Skills

SOC engineering
Splunk
SOAR automation
Scripting language
AWS security services
ITSM/ServiceNow

Tools

Torq
Terraform
ServiceNow

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Full Time McLean, VA, US

About Merlin Group

Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions.

At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact.

The Opportunity

We are looking for a SOC Engineer to build, operate, and improve the technical capabilities behind our security operations. While the role is primarily focused on security automation and platform engineering, detection engineering will play a large part as well. You will partner closely with SOC analysts to turn their needs into reliable detections, workflows, and infrastructure, and work with the SOC Manager, Engineering, Infrastructure, and GRC teams to keep the platform secure, compliant, and scalable.

Primary Duties & Responsibilities
  • Design, build, and tune detections in Splunk using SPL, mapping coverage to knowledge bases like MITRE ATT&CK and managing rules through the team's detection-as-code process with version control, testing, and peer review, while tracking false positive rates, alert volume, and coverage gaps with analysts to prioritize tuning and new content
  • Onboard, normalize, and maintain log sources and collection pipelines across AWS, Azure, and GCP, including CloudTrail, GuardDuty, Azure Activity and Entra ID logs, GCP Cloud Audit Logs, and endpoint, identity, and network telemetry, with forwarders, ingestion, retention, and integrity controls that satisfy FedRAMP audit logging requirements
  • Build and maintain Torq workflows for alert enrichment, triage, containment, and case handling, integrating with Splunk, ServiceNow, cloud provider APIs, and other SOC tools so alerts arrive as enriched ServiceNow cases with consistent fields, ownership, and SLAs, reducing analyst toil and mean time to respond
  • Engineer and operate the SOC tooling platform in AWS, including Infrastructure as Code (IaC), deployment pipelines, IAM, secrets management, and monitoring systems
  • Produce and maintain documentation, runbooks, and architecture diagrams for detections, automation playbooks, and platform components, and supply evidence for audits and control assessments
  • Serve as an engineering escalation point during incidents and participate in an on-call rotation for SOC platform issues
Qualifications
  • 4+ years of experience in SOC engineering, detection engineering, security engineering, or a closely related role
  • Deep hands-on experience with Splunk, including SPL, correlation searches, data models and CIM, knowledge object management, index and sourcetype design, and Splunk Enterprise Security
  • Experience building automation with a Security Orchestration, Automation, and Response (SOAR) platform (Torq strongly preferred) and integrating tools through REST APIs and webhooks
  • Proficiency in at least one scripting language, and comfort with Git-based workflows and CI/CD pipelines
  • Working knowledge of AWS services relevant to security operations (IAM, CloudTrail, GuardDuty, Security Hub, Lambda, S3, VPC) and IaC tooling such as Terraform
  • Experience working with an IT Service Management (ITSM) platform (ServiceNow preferred)
Preferred Qualifications
  • Experience supporting FedRAMP Moderate or High environments or other NIST 800-53 based programs
  • Experience with detection-as-code frameworks and CI/CD for security content, such as Sigma
  • Experience configuring or integrating the ServiceNow Security Incident Response module
  • Prior work in a managed security services or multi-tenant SOC environment
Success Attributes
  • Commitment to personal and professional integrity and respect for others.
  • Roll-up-your-sleeves attitude and low-ego approach.
  • Commitment to teamwork and professional relationship development.
  • Passion for lifelong learning, growth, and development.
  • Flexible and nimble; comfortable with ambiguity and rapid change.
  • Strong communication and functional project management skills.
  • Desire to innovate, try new things, and creatively explore novel solutions to business challenges.
  • Professional and respectful approach to the diversity of thought, action, identity, and attributes.

We want to empower and inspire employees to be and do their best. Our workdays are dynamic, collegial, and fun. Our office features multiple places to work unconstrained by typical office barriers.

Our wellness package provides access to an on-site gym and includes medical, dental, and vision insurance along with options for FSA and EAP. We offer 401(k) with employer match, unlimited PTO, and a culture respectful of the reality that not everything in one’s personal life is guaranteed to happen only after hours.

  • access to an on-site gym
  • medical, dental, and vision insurance
  • options for FSA and EAP
  • 401(k) with employer match
  • unlimited PTO

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

Merlin International Inc • McLean (VA)

On-site
USD 110,000 - 140,000
SOC Engineer
SOC Engineer

Amentum • Ellicott City (MD)

On-site
USD 145,000 - 190,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+6
SOC Engineer
SOC Engineer

Bayview Fund Management, LLC • Coral Gables (FL)

On-site
USD 160,000 - 180,000
Remote role
Bonus eligibility
SOC Engineer
SOC Engineer

Bayview Asset Management, LLC • Coral Gables (FL)

Remote
USD 160,000 - 180,000
IT Security Engineer
IT Security Engineer

Pike Corporation • Fort Mill (SC)

On-site
USD 120,000 - 180,000
Information Systems Security Manager
Information Systems Security Manager

Merlin International Inc • McLean (VA)

On-site
USD 140,000 - 190,000
On-site gym
Medical, dental, and vision insurance
401(k) with employer match
+1
SOC Engineer - Detections, Automation | Unlimited PTO
SOC Engineer - Detections, Automation | Unlimited PTO

Merlin International Inc • McLean (VA)

On-site
USD 110,000 - 140,000
SOC Manager
SOC Manager

Qnity • Wilmington (DE)

On-site
USD 140,000 - 190,000
Competitive pay
Benefits package
Senior SOC Analyst
Senior SOC Analyst

FlexTrade • Village of Great Neck (NY)

On-site
USD 120,000 - 180,000
Hybrid work schedule
Professional development budget
Comprehensive benefits
Lead OT SOC Architect
Lead OT SOC Architect

Jacobs • Baton Rouge (LA)

On-site
USD 145,000 - 180,000