Sr. SOC Engineer (Splunk ES & SOAR)
SGA
Sr. SOC Engineering Consultant
Software Guidance & Assistance, Inc., (SGA), is searching for a Sr. SOC Engineering Consultant for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD, Tysons, VA, Dallas, TX, or New York, NY. Hybrid - 3x a week on-site
About the Role
- Our Security Operations Center is evolving from foundational capabilities into a mature, comprehensive security operations program. We need an experienced SOC engineer who has been part of a top-tier SOC and can provide technical vision and leadership to guide our detection engineering and automation efforts.
- This role focuses on building robust detection capabilities, automating security responses, and creating frameworks that enable our SOC analysts to effectively identify and respond to threats. You will work closely with our threat intelligence and hunting teams to translate security research into actionable detections and automated responses.
Team Structure & Growth Opportunity
- This position reports to the Director of Security Platform Engineering and serves as a senior individual contributor with potential to transition into a technical lead role as the SOC engineering team expands. You will collaborate closely with SOC analysts, threat intelligence teams, threat hunters, and platform engineering teams.
- The role offers the opportunity to shape SOC capabilities, establish engineering standards, and build a world-class detection and response program using industry-leading tools. This is a senior-level position requiring demonstrated experience in mature SOC environments and the ability to provide technical vision and mentorship.
Detection Engineering
• Design and implement comprehensive detection use cases aligned with the MITRE ATT&CK framework
• Conduct gap analysis of current detection coverage and develop roadmap to address gaps
• Build and tune correlation searches, alerts, and detection logic in Splunk Enterprise Security
• Implement Risk-Based Alerting (RBA) methodologies to improve signal-to-noise ratio
• Develop detection strategies for multi-cloud environments (AWS, GCP, Azure)
• Continuously evaluate and improve detection effectiveness based on SOC feedback
Security Automation & Orchestration
• Design and implement automated response playbooks using Splunk SOAR
• Build integrations between security tools to enable automated investigation and response workflows
• Develop scripts and automation (Python, Bash, PowerShell) to streamline SOC operations
• Create reusable automation frameworks that scale across multiple use cases
• Collaborate with platform engineering to ensure reliable automation infrastructure
SOC Architecture & Vision
• Define what a mature SOC capability looks like using Splunk ES, SOAR, and supporting tools
• Identify gaps and shortcomings in current SOC implementation and provide clear remediation guidance
• Establish best practices, standards, and frameworks for detection engineering and response
• Mentor platform engineering team on SOC-specific requirements and approaches
• Contribute to long-term SOC strategy and capability development
Cross-Functional Collaboration
• Partner with threat intelligence and threat hunting teams to operationalize research into detections
• Work with SOC analysts to understand investigation workflows and improve detection quality
• Collaborate with platform engineering teams to implement and maintain SOC infrastructure
• Participate in incident response activities to validate and refine detection and automation capabilities
• Document detection logic, playbooks, and technical architectures
Required Qualifications
• SOC Experience: 5+ years in a Security Operations Center environment with exposure to mature SOC operations and best practices
• SIEM Expertise: Hands-on experience with Splunk Enterprise Security or comparable enterprise SIEM platforms (building correlation searches, alerts, dashboards, and ES-specific frameworks)
• Detection Engineering: Proven experience developing security detections, use cases, and alert tuning methodologies
• MITRE ATT&CK Framework: Practical application of MITRE ATT&CK for detection coverage mapping and gap analysis
• Security Automation: Experience building automated response workflows and playbooks (SOAR platforms preferred)
• Scripting: Strong proficiency in Python, PowerShell, or Bash for automation and integration development
• Cloud Security: Understanding of cloud security monitoring and detection across AWS, GCP, and Azure environments
• Analytical Mindset: Ability to identify gaps, define clear vision for improvement, and guide teams toward maturity
Preferred Qualifications
• Splunk SOAR (Phantom) hands-on experience
• Splunk UEBA or behavioral analytics platform experience
• Risk-Based Alerting (RBA) implementation experience
• Threat hunting background with detection engineering application
• Infrastructure automation and CI/CD pipeline knowledge
• Experience mentoring or leading detection engineering teams
• Relevant certifications (GIAC, CISSP, or similar)
$77.5k - $140.9k
...world. Job Title: CyberSecurity SIEM Engineer (Senior SDC) About the job At EY,... ...with an emphasis on integrating SIEM and SOAR capabilities into business operations.... ...and other SOAR products (Falcon Fusion, Splunk SOAR, Google Chronicle SecOps, LogicApps,...SplunkSeniorWork experience placementSummer holidayFlexible hours$156k - $193k
...Sr. Information Systems Security Engineer Tysons Corner, VA We are seeking a skilled and motivated Sr. Information Systems Security Engineer to join... ...and implementing log collection tools such as Splunk and performing querying and analysis of aggregated logs...SplunkSeniorFull timeWork experience placementLocal areaFlexible hours$229.9k - $262.4k
...Senior Lead Software Engineer, DevOps (Cloud Operations Resilience Engineering... ...with monitoring tools (Splunk or Zabbix) ~3+ years of experience... ..., VA: $229,900 - $262,400 for Sr. Lead Software Engineer... ..., which may include cash bonus(es) and/or long term incentives (LTI...SplunkSeniorFull timePart timeInternshipLocal area- ...Detection Engineer / Splunk Content Developer McLean, Virginia, United States 160,000.00 - 1... ..., firewall, web application firewall SOAR, Proxy, SIEM systems Manages and administers... ...background with Splunk, Splunk ES, Splunk Processing Language Experience...SplunkHourly payContract workSummer work
$95.86k - $208.27k
...is currently seeking a Senior Specialist, SOC Analyst Level II to join our Advisory... ...dashboards, monitors, and collaborating with SIEM Engineers to refine alert logic and improve... ...Google SecOps, MS Sentinel, CrowdStrike, Splunk, Qradar, LogRhythm, SolarWinds) Demonstrated...SplunkSeniorH1bLocal areaShift workNight shiftWeekend work$142.79k - $175.95k
...Cyber Engineer Position Location: USA VA McLean Full Part/Time: Full time Job Req: RQ219668 Type of Requisition: Regular Clearance... ...Qualifications: Skills: Cybersecurity, Endpoint Security, Linux, Splunk Enterprise Security Certifications: None Experience: 8 + years...SplunkSeniorFull timeContract workTemporary workPart timeRemote workFlexible hours- ...Hiring: Senior Java Site Reliability Engineer (SRE) Location: McLean ,VA Project : Hybrid Employment Type: Contract / Full-Time... ...Actions, GitLab CI/CD, ArgoCD ✅ Terraform & Ansible ✅ Splunk, Datadog, Grafana, Prometheus, Moogsoft ✅ ServiceNow, JIRA, Confluence...SplunkSeniorFull timeContract work
- ...collaboratively with our staff of cybersecurity engineers in the fields of defensive cyber... ...defense, and Security Operations Center (SOC) process improvement. Developing AI-enabled... ...security analytics and dashboards in Splunk or Elastic and integrating new data feeds...SplunkWork experience placementInternshipLocal area
$314.8k - $359.3k
...Sr. Director, Cyber Technical (Cyber Hunt, Logging and Threat... ...development using modern software engineering practices. You have a... ...experience using security tools (e.g., Splunk, Crowdstrike, Qualys, or AWS... ...which may include cash bonus(es) and/or long term incentives (...SplunkSeniorFull timePart timeLocal area$314.8k - $359.3k
...Sr. Distinguished Engineer Sr. Distinguished Engineer, Software Engineer - Enterprise data storage and consumption platforms We are the Data... ...based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary...SeniorFull timePart timeLocal area- ...Job Title: Network/Operations - Dev Ops Engineer Location: (100% Remote) Duration: Long Term Job Type: Contract AWS - Basic Understanding of AWS Services Splunk - Must (Heavy) New Relic - Good to have Troubleshooting...SplunkContract workRemote work
$86.8k - $198k
...58 Enterprise Cybersecurity Automation Engineer The Opportunity: Cyber threats are... ...integrate security systems into the existing SOAR Platform. You'll be responsible for... ...including security management tools such as Splunk, Carbon Black, CrowdStrike, Nitro, or ArcSight...SplunkFull timeContract workPart timeWork at officeLocal areaRemote work- ...Job Description Job Description Please submit local candidates only! Role: Dynatrace Observability Engineer Skills: Digital: Splunk, Digital: Salesforce Development and Technical Design, Dynatrace (MUST HAVE) Exp: 10 & Above Role Descriptions 10 years...SplunkLocal area
$80k - $121k
...we are seeking a talented individual to join AIS as a Security Engineer. Core Knowledge & Skills: Applies advanced network security... ...assignment, you will support the unique needs of our client as a SOC Engineer Tier 1/2. As aSOC Engineer Tier 1-2 you will use cutting...Contract workShift workNight shiftWeekend work- ...Role: Lead/Sr. Java FS Developer Location: McLean, VA Duration: C2... ...applications • Experience with reverse engineering, troubleshooting and re-platforming applications... ...Docker - Good to have • Monitoring - Splunk knowledge, Kafka, New Relic - good to...SplunkSeniorFull timeContract work
- ...candidate to join our talented Team. Job Title: Barracuda WAF Engineer (SME). Location: McLean, VA. Job Description: ~ Need an experienced... ...Monitoring & Incident Response: Analyze logs using tools like Splunk or Azure Monitor and respond to real-time security alerts and...Splunk
- ...Grafan Netskope CASB Netskope Secure Web Gateway Splunk Nice To Have nsible Cisco AnyConnect VPN... ...Python Secure Remote Access Job Description - Engineers solutions in alignment with the Cybersecurity engineering road...SplunkRemote work
- Sr Principal Technologist 100% REMOTE STONG CLOUD/FIN OPS Exp Client is seeking a highly skilled and experienced Sr. Principal Technologist specializing in Financial Operations and Governance across multiple cloud platforms, primarily AWS and Azure, with some exposure...SeniorRemote work
- ...Magazine's Top 5000 Fastest Growing Companies. As the Tanium Engineer, you will possess solid department of defense industry... ...Exposure and/or experience with any of the following tools: Splunk, Crowdstrike, ZScaler, CRIBL, Tenable, Rapid 7, Microsoft Defender...Splunk2 days per week3 days per week
- ...issues) Experience with monitoring and analysis tools such as Splunk, Riverbed, and SolarWinds Familiarity with ServiceNow or... ...to appropriate teams Engage vendors and internal Tier 3/engineering teams for issue resolution Company Benefits & Culture...SplunkWork experience placementImmediate startRemote workAll shiftsShift workNight shiftDay shiftAfternoon shift
- ...secure, and innovative power and technology solutions through engineering expertise and smart systems integration. Why Join Us? Our... ...Exposure to monitoring and logging tools (e.g., AWS CloudWatch, Splunk, Nagios) is a plus; Familiarity with scripting in Bash,...SplunkWork experience placement
- ..., IntelliJ, VSCode Versioning Control: Bitbucket Others: JUnit, Gradle, JSON, Restful Webservices, GraphQL, ELK, Splunk, Kafka, AMQ, JMS, XML/XSD, Dynatrace Preferred Skills: Excellent problem solving and analytical, and technical skills...SplunkSeniorFlexible hours
$186k - $240k
...Job Description Federal Systems Engineer - Tysons, VA The Sr Systems Engineer will provide systems and infrastructure administration for... ...system monitoring and logging tools (e.g., SCOM, Nagios, Splunk, or equivalents). • Experience implementing and maintaining...SplunkContract workWork at office- ...Systems Engineer SME (TS/SCI with Poly Required) GCI embodies excellence, integrity and professionalism. The employees supporting our... ...test failures (e.g., CloudWatch logs/metrics; or Splunk/ELK). Demonstrated performance and reliability testing experience...SplunkWork experience placement
- ...Cybersecurity Engineer II The Cybersecurity Engineer II provides comprehensive cybersecurity support for the Product Manager Biometrics... .../ML; Windows Server Update Services (WSUS); SIEM tools such as Splunk, Cloud Security Infrastructure products and tools; Cloud...SplunkTemporary workImmediate startFlexible hours
- ...has an active TS, that's a huge plus. Title: Cyber Operations Engineer Job Id: 1083 Location: Alexandria, VA Clearance:... ...support security automation Experience with STIG Manager, Splunk Enterprise Security, or similar orchestration tools EEO...SplunkFull timeApprenticeshipLocal area
- ...Job Posting Prior banking and financial experience is required, local to Mclean, VA preferred. DevOps engineer experience is needed. The candidate needs to be really independent with the task, as other engineers will be assigning him the tasks. Deployment...SeniorLocal area
- ...TLA is seeking an Information System Security Engineer (ISSE). This is a critical role responsible for designing, developing, implementing... ...such as vulnerability scanners (Nessus/ACAS), SIEM platforms (Splunk, LogRhythm), and security configuration tools (DISA STIGs, SCAP...Splunk
- ...Job Title: Dev Ops Engineer - Sr Location: Mclean (preferred) & Richmond - Hybrid. Quantity: 4 Duration: 12 months - no conversion, no extension. Interview : 2 rounds. 1 hour and 30 min resp. Project Overview : These roles support Capital One's EP Tech...Senior
- ...Sr. DevOps Engineer Candidates must be able to work in the U.S. without sponsorship 100% Remote... ...or managing Application Monitoring, Splunk, or Dynatrace • Working knowledge in... ...least privilege and compliance (e.g., SOC 2, ISO 27001, HIPAA as relevant). •...SplunkSeniorWork experience placementRemote workShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. SOC Engineer (Splunk ES & SOAR). Be the first to apply!
- senior game producer McLean, VA
- senior manager process engineering McLean, VA
- senior manager clinical operations McLean, VA
- senior lead project manager McLean, VA
- senior manager quality engineering McLean, VA
- senior full stack developer McLean, VA
- senior hvac project manager McLean, VA
- senior strategy analyst McLean, VA
- senior work from home McLean, VA
- senior wealth advisor McLean, VA


