Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. SOC Engineer (Splunk ES & SOAR)

SGA

Sr. SOC Engineering Consultant

Software Guidance & Assistance, Inc., (SGA), is searching for a Sr. SOC Engineering Consultant for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD, Tysons, VA, Dallas, TX, or New York, NY. Hybrid - 3x a week on-site

About the Role

  • Our Security Operations Center is evolving from foundational capabilities into a mature, comprehensive security operations program. We need an experienced SOC engineer who has been part of a top-tier SOC and can provide technical vision and leadership to guide our detection engineering and automation efforts.
  • This role focuses on building robust detection capabilities, automating security responses, and creating frameworks that enable our SOC analysts to effectively identify and respond to threats. You will work closely with our threat intelligence and hunting teams to translate security research into actionable detections and automated responses.

Team Structure & Growth Opportunity

  • This position reports to the Director of Security Platform Engineering and serves as a senior individual contributor with potential to transition into a technical lead role as the SOC engineering team expands. You will collaborate closely with SOC analysts, threat intelligence teams, threat hunters, and platform engineering teams.
  • The role offers the opportunity to shape SOC capabilities, establish engineering standards, and build a world-class detection and response program using industry-leading tools. This is a senior-level position requiring demonstrated experience in mature SOC environments and the ability to provide technical vision and mentorship.

Detection Engineering

• Design and implement comprehensive detection use cases aligned with the MITRE ATT&CK framework

• Conduct gap analysis of current detection coverage and develop roadmap to address gaps

• Build and tune correlation searches, alerts, and detection logic in Splunk Enterprise Security

• Implement Risk-Based Alerting (RBA) methodologies to improve signal-to-noise ratio

• Develop detection strategies for multi-cloud environments (AWS, GCP, Azure)

• Continuously evaluate and improve detection effectiveness based on SOC feedback

Security Automation & Orchestration

• Design and implement automated response playbooks using Splunk SOAR

• Build integrations between security tools to enable automated investigation and response workflows

• Develop scripts and automation (Python, Bash, PowerShell) to streamline SOC operations

• Create reusable automation frameworks that scale across multiple use cases

• Collaborate with platform engineering to ensure reliable automation infrastructure

SOC Architecture & Vision

• Define what a mature SOC capability looks like using Splunk ES, SOAR, and supporting tools

• Identify gaps and shortcomings in current SOC implementation and provide clear remediation guidance

• Establish best practices, standards, and frameworks for detection engineering and response

• Mentor platform engineering team on SOC-specific requirements and approaches

• Contribute to long-term SOC strategy and capability development

Cross-Functional Collaboration

• Partner with threat intelligence and threat hunting teams to operationalize research into detections

• Work with SOC analysts to understand investigation workflows and improve detection quality

• Collaborate with platform engineering teams to implement and maintain SOC infrastructure

• Participate in incident response activities to validate and refine detection and automation capabilities

• Document detection logic, playbooks, and technical architectures

Required Qualifications

• SOC Experience: 5+ years in a Security Operations Center environment with exposure to mature SOC operations and best practices

• SIEM Expertise: Hands-on experience with Splunk Enterprise Security or comparable enterprise SIEM platforms (building correlation searches, alerts, dashboards, and ES-specific frameworks)

• Detection Engineering: Proven experience developing security detections, use cases, and alert tuning methodologies

• MITRE ATT&CK Framework: Practical application of MITRE ATT&CK for detection coverage mapping and gap analysis

• Security Automation: Experience building automated response workflows and playbooks (SOAR platforms preferred)

• Scripting: Strong proficiency in Python, PowerShell, or Bash for automation and integration development

• Cloud Security: Understanding of cloud security monitoring and detection across AWS, GCP, and Azure environments

• Analytical Mindset: Ability to identify gaps, define clear vision for improvement, and guide teams toward maturity

Preferred Qualifications

• Splunk SOAR (Phantom) hands-on experience

• Splunk UEBA or behavioral analytics platform experience

• Risk-Based Alerting (RBA) implementation experience

• Threat hunting background with detection engineering application

• Infrastructure automation and CI/CD pipeline knowledge

• Experience mentoring or leading detection engineering teams

• Relevant certifications (GIAC, CISSP, or similar)

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. SOC Engineer (Splunk ES & SOAR) in McLean, VA vacancy
  • $77.5k - $140.9k

     ...world. Job Title: CyberSecurity SIEM Engineer (Senior SDC) About the job At EY,...  ...with an emphasis on integrating SIEM and SOAR capabilities into business operations....  ...and other SOAR products (Falcon Fusion, Splunk SOAR, Google Chronicle SecOps, LogicApps,... 
    Splunk
    Senior
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    McLean, VA
    4 days ago
  • $156k - $193k

     ...Sr. Information Systems Security Engineer Tysons Corner, VA We are seeking a skilled and motivated Sr. Information Systems Security Engineer to join...  ...and implementing log collection tools such as Splunk and performing querying and analysis of aggregated logs... 
    Splunk
    Senior
    Full time
    Work experience placement
    Local area
    Flexible hours

    MetroStar Corporation

    McLean, VA
    2 days ago
  • $229.9k - $262.4k

     ...Senior Lead Software Engineer, DevOps (Cloud Operations Resilience Engineering...  ...with monitoring tools (Splunk or Zabbix) ~3+ years of experience...  ..., VA: $229,900 - $262,400 for Sr. Lead Software Engineer...  ..., which may include cash bonus(es) and/or long term incentives (LTI... 
    Splunk
    Senior
    Full time
    Part time
    Internship
    Local area

    Capital One Financial Corp

    McLean, VA
    3 days ago
  •  ...Detection Engineer / Splunk Content Developer McLean, Virginia, United States 160,000.00 - 1...  ..., firewall, web application firewall SOAR, Proxy, SIEM systems Manages and administers...  ...background with Splunk, Splunk ES, Splunk Processing Language Experience... 
    Splunk
    Hourly pay
    Contract work
    Summer work

    Top Cleared Recruiting

    McLean, VA
    2 days ago
  • $95.86k - $208.27k

     ...is currently seeking a Senior Specialist, SOC Analyst Level II to join our Advisory...  ...dashboards, monitors, and collaborating with SIEM Engineers to refine alert logic and improve...  ...Google SecOps, MS Sentinel, CrowdStrike, Splunk, Qradar, LogRhythm, SolarWinds) Demonstrated... 
    Splunk
    Senior
    H1b
    Local area
    Shift work
    Night shift
    Weekend work

    KPMG

    McLean, VA
    1 day ago
  • $142.79k - $175.95k

     ...Cyber Engineer Position Location: USA VA McLean Full Part/Time: Full time Job Req: RQ219668 Type of Requisition: Regular Clearance...  ...Qualifications: Skills: Cybersecurity, Endpoint Security, Linux, Splunk Enterprise Security Certifications: None Experience: 8 + years... 
    Splunk
    Senior
    Full time
    Contract work
    Temporary work
    Part time
    Remote work
    Flexible hours

    General Dynamics

    McLean, VA
    1 day ago
  •  ...Hiring: Senior Java Site Reliability Engineer (SRE) Location: McLean ,VA Project : Hybrid Employment Type: Contract / Full-Time...  ...Actions, GitLab CI/CD, ArgoCD ✅ Terraform & Ansible ✅ Splunk, Datadog, Grafana, Prometheus, Moogsoft ✅ ServiceNow, JIRA, Confluence... 
    Splunk
    Senior
    Full time
    Contract work

    ClaidSphere Solutions

    McLean, VA
    2 days ago
  •  ...collaboratively with our staff of cybersecurity engineers in the fields of defensive cyber...  ...defense, and Security Operations Center (SOC) process improvement. Developing AI-enabled...  ...security analytics and dashboards in Splunk or Elastic and integrating new data feeds... 
    Splunk
    Work experience placement
    Internship
    Local area

    MITRE

    McLean, VA
    2 days ago
  • $314.8k - $359.3k

     ...Sr. Director, Cyber Technical (Cyber Hunt, Logging and Threat...  ...development using modern software engineering practices. You have a...  ...experience using security tools (e.g., Splunk, Crowdstrike, Qualys, or AWS...  ...which may include cash bonus(es) and/or long term incentives (... 
    Splunk
    Senior
    Full time
    Part time
    Local area

    Capital One Financial Corp

    McLean, VA
    2 days ago
  • $314.8k - $359.3k

     ...Sr. Distinguished Engineer Sr. Distinguished Engineer, Software Engineer - Enterprise data storage and consumption platforms We are the Data...  ...based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary... 
    Senior
    Full time
    Part time
    Local area

    Capital One

    McLean, VA
    3 days ago
  •  ...Job Title: Network/Operations - Dev Ops Engineer Location: (100% Remote) Duration: Long Term Job Type: Contract AWS - Basic Understanding of AWS Services Splunk - Must (Heavy) New Relic - Good to have Troubleshooting... 
    Splunk
    Contract work
    Remote work

    TriOptus LLC

    McLean, VA
    4 days ago
  • $86.8k - $198k

     ...58 Enterprise Cybersecurity Automation Engineer The Opportunity: Cyber threats are...  ...integrate security systems into the existing SOAR Platform. You'll be responsible for...  ...including security management tools such as Splunk, Carbon Black, CrowdStrike, Nitro, or ArcSight... 
    Splunk
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  •  ...Job Description Job Description Please submit local candidates only! Role: Dynatrace Observability Engineer Skills: Digital: Splunk, Digital: Salesforce Development and Technical Design, Dynatrace (MUST HAVE) Exp: 10 & Above Role Descriptions 10 years... 
    Splunk
    Local area

    head-huntress.com

    McLean, VA
    10 days ago
  • $80k - $121k

     ...we are seeking a talented individual to join AIS as a Security Engineer. Core Knowledge & Skills: Applies advanced network security...  ...assignment, you will support the unique needs of our client as a SOC Engineer Tier 1/2. As aSOC Engineer Tier 1-2 you will use cutting... 
    Contract work
    Shift work
    Night shift
    Weekend work

    Applied Information Sciences

    McLean, VA
    1 day ago
  •  ...Role: Lead/Sr. Java FS Developer Location: McLean, VA Duration: C2...  ...applications • Experience with reverse engineering, troubleshooting and re-platforming applications...  ...Docker - Good to have • Monitoring - Splunk knowledge, Kafka, New Relic - good to... 
    Splunk
    Senior
    Full time
    Contract work

    Maintec Technologies

    McLean, VA
    2 days ago
  •  ...candidate to join our talented Team. Job Title: Barracuda WAF Engineer (SME). Location: McLean, VA. Job Description: ~ Need an experienced...  ...Monitoring & Incident Response: Analyze logs using tools like Splunk or Azure Monitor and respond to real-time security alerts and... 
    Splunk

    Ampcus

    McLean, VA
    2 days ago
  •  ...Grafan Netskope CASB Netskope Secure Web Gateway Splunk Nice To Have nsible Cisco AnyConnect VPN...  ...Python Secure Remote Access Job Description - Engineers solutions in alignment with the Cybersecurity engineering road... 
    Splunk
    Remote work

    RIT Solutions, Inc.

    McLean, VA
    1 day ago
  • Sr Principal Technologist 100% REMOTE STONG CLOUD/FIN OPS Exp Client is seeking a highly skilled and experienced Sr. Principal Technologist specializing in Financial Operations and Governance across multiple cloud platforms, primarily AWS and Azure, with some exposure... 
    Senior
    Remote work

    RIT Solutions, Inc.

    McLean, VA
    3 days ago
  •  ...Magazine's Top 5000 Fastest Growing Companies. As the Tanium Engineer, you will possess solid department of defense industry...  ...Exposure and/or experience with any of the following tools: Splunk, Crowdstrike, ZScaler, CRIBL, Tenable, Rapid 7, Microsoft Defender... 
    Splunk
    2 days per week
    3 days per week

    True Zero Technologies, LLC

    McLean, VA
    4 days ago
  •  ...issues) Experience with monitoring and analysis tools such as Splunk, Riverbed, and SolarWinds Familiarity with ServiceNow or...  ...to appropriate teams Engage vendors and internal Tier 3/engineering teams for issue resolution Company Benefits & Culture... 
    Splunk
    Work experience placement
    Immediate start
    Remote work
    All shifts
    Shift work
    Night shift
    Day shift
    Afternoon shift

    Artech

    McLean, VA
    2 days ago
  •  ...secure, and innovative power and technology solutions through engineering expertise and smart systems integration. Why Join Us? Our...  ...Exposure to monitoring and logging tools (e.g., AWS CloudWatch, Splunk, Nagios) is a plus; Familiarity with scripting in Bash,... 
    Splunk
    Work experience placement

    M.C. Dean, Inc.

    McLean, VA
    3 days ago
  •  ..., IntelliJ, VSCode Versioning Control: Bitbucket Others: JUnit, Gradle, JSON, Restful Webservices, GraphQL, ELK, Splunk, Kafka, AMQ, JMS, XML/XSD, Dynatrace Preferred Skills: Excellent problem solving and analytical, and technical skills... 
    Splunk
    Senior
    Flexible hours

    PALNAR

    McLean, VA
    1 day ago
  • $186k - $240k

     ...Job Description Federal Systems Engineer - Tysons, VA The Sr Systems Engineer will provide systems and infrastructure administration for...  ...system monitoring and logging tools (e.g., SCOM, Nagios, Splunk, or equivalents). • Experience implementing and maintaining... 
    Splunk
    Contract work
    Work at office

    Dell

    McLean, VA
    13 hours ago
  •  ...Systems Engineer SME (TS/SCI with Poly Required) GCI embodies excellence, integrity and professionalism. The employees supporting our...  ...test failures (e.g., CloudWatch logs/metrics; or Splunk/ELK). Demonstrated performance and reliability testing experience... 
    Splunk
    Work experience placement

    GCI

    McLean, VA
    2 days ago
  •  ...Cybersecurity Engineer II The Cybersecurity Engineer II provides comprehensive cybersecurity support for the Product Manager Biometrics...  .../ML; Windows Server Update Services (WSUS); SIEM tools such as Splunk, Cloud Security Infrastructure products and tools; Cloud... 
    Splunk
    Temporary work
    Immediate start
    Flexible hours

    Integral Federal

    McLean, VA
    1 day ago
  •  ...has an active TS, that's a huge plus. Title: Cyber Operations Engineer Job Id: 1083 Location: Alexandria, VA Clearance:...  ...support security automation Experience with STIG Manager, Splunk Enterprise Security, or similar orchestration tools EEO... 
    Splunk
    Full time
    Apprenticeship
    Local area

    LanceSoft

    McLean, VA
    3 days ago
  •  ...Job Posting Prior banking and financial experience is required, local to Mclean, VA preferred. DevOps engineer experience is needed. The candidate needs to be really independent with the task, as other engineers will be assigning him the tasks. Deployment... 
    Senior
    Local area

    Software Technology Inc

    McLean, VA
    4 days ago
  •  ...TLA is seeking an Information System Security Engineer (ISSE). This is a critical role responsible for designing, developing, implementing...  ...such as vulnerability scanners (Nessus/ACAS), SIEM platforms (Splunk, LogRhythm), and security configuration tools (DISA STIGs, SCAP... 
    Splunk

    TLA Inc

    McLean, VA
    13 hours ago
  •  ...Job Title: Dev Ops Engineer - Sr Location: Mclean (preferred) & Richmond - Hybrid. Quantity: 4 Duration: 12 months - no conversion, no extension. Interview : 2 rounds. 1 hour and 30 min resp. Project Overview : These roles support Capital One's EP Tech... 
    Senior

    Artech

    McLean, VA
    1 day ago
  •  ...Sr. DevOps Engineer Candidates must be able to work in the U.S. without sponsorship 100% Remote...  ...or managing Application Monitoring, Splunk, or Dynatrace • Working knowledge in...  ...least privilege and compliance (e.g., SOC 2, ISO 27001, HIPAA as relevant). •... 
    Splunk
    Senior
    Work experience placement
    Remote work
    Shift work

    System One Holdings, LLC

    McLean, VA
    13 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. SOC Engineer (Splunk ES & SOAR). Be the first to apply!