Incident Response Monitoring
System One Holdings, LLC
Job Title: Incident Response Monitoring
Location: Hybrid Work Model Reporting to Winchester, VA, Pensacola, FL and Vienna, VA
Pay Rate: Open to Both C2C and W2 options
Position Type: Multiyear Contract Role Overview
The Principal Cybersecurity Detection Engineer - AI Driven Threats is a senior individual contributor responsible for advancing the effectiveness and maturity of the Cyber Security Operations Center (CSOC). This role designs, operationalizes, and scales high confidence detection capabilities to address AI enabled threats and related emerging attack techniques.
The position combines deep, hands on detection engineering expertise with applied knowledge of AI security and adversarial techniques. As a principal level individual contributor, this role drives the practical application of AI and emerging technologies within security operations, ensuring measurable improvements in detection fidelity, incident response outcomes, and analyst efficiency.
Key Responsibilities
AI & Emerging Threat Detection
Serve as the senior technical subject matter expert for AI focused threat detection within the CSOC.
Design, develop, deploy, and maintain advanced detection content across SIEM and security platforms to identify AI enabled and emerging attack techniques.
Engineer high confidence detections using complex query languages and techniques (e.g., SPL, KQL, regex, YARA, macros, lookups) across on premises, hybrid, and cloud environments.
Continuously evaluate detection coverage and fidelity, tuning or retiring content as adversary tactics, data sources, and operational needs evolve.
Research emerging AI and advanced technology threats (e.g., prompt injection, model poisoning, adversarial AI, data exposure) and translate them into actionable detection strategies.
Align detection use cases to industry frameworks such as MITRE ATT&CK, MITRE ATLAS, and NIST CSF.
Partner with threat intelligence, detection engineering, threat hunting, red team, and architecture teams to proactively strengthen detection capabilities.
Support proofs of concept and pilots that apply AI to detection engineering and SOC operations, ensuring solutions deliver measurable operational value.
Mentor and guide senior detection engineers and analysts on AI threat concepts and advanced detection strategies.
Communicate complex technical findings clearly to technical teams, leadership, and executive stakeholders. Required Qualifications
7+ years of experience in cybersecurity operations, detection engineering, or SIEM engineering in a senior individual contributor role.
Advanced expertise in detection engineering across the full content lifecycle (design, testing, deployment, tuning, and decommissioning).
Hands on experience applying AI or machine learning capabilities within SOC or detection workflows.
Familiarity with AI security frameworks (e.g., MITRE ATLAS, OWASP AI Security).
Advanced proficiency with SIEM query languages and multi source telemetry across on prem, cloud (IaaS/PaaS/SaaS), and hybrid environments.
Strong understanding of adversary TTPs, including emerging AI enabled threats.
Demonstrated ability to analyze large scale log and telemetry datasets to identify threats and detection gaps.
Strong communication skills, with the ability to present complex technical concepts to both technical and nontechnical audiences.
Preferred Qualifications
Experience leading or contributing to AI?focused SOC pilots, automation initiatives, or advanced detection programs.
Relevant certifications (e.g., CISSP, CySA+, CASP+, CCSP) or comparable credentials.
Bachelor's degree in Cybersecurity, Computer Science, Engineering, or a related field. #LI-KA1
#M1 Ref: #851-Rockville-S1
Location: Hybrid Work Model Reporting to Winchester, VA, Pensacola, FL and Vienna, VA
Pay Rate: Open to Both C2C and W2 options
Position Type: Multiyear Contract Role Overview
The Principal Cybersecurity Detection Engineer - AI Driven Threats is a senior individual contributor responsible for advancing the effectiveness and maturity of the Cyber Security Operations Center (CSOC). This role designs, operationalizes, and scales high confidence detection capabilities to address AI enabled threats and related emerging attack techniques.
The position combines deep, hands on detection engineering expertise with applied knowledge of AI security and adversarial techniques. As a principal level individual contributor, this role drives the practical application of AI and emerging technologies within security operations, ensuring measurable improvements in detection fidelity, incident response outcomes, and analyst efficiency.
Key Responsibilities
AI & Emerging Threat Detection
Serve as the senior technical subject matter expert for AI focused threat detection within the CSOC.
Design, develop, deploy, and maintain advanced detection content across SIEM and security platforms to identify AI enabled and emerging attack techniques.
Engineer high confidence detections using complex query languages and techniques (e.g., SPL, KQL, regex, YARA, macros, lookups) across on premises, hybrid, and cloud environments.
Continuously evaluate detection coverage and fidelity, tuning or retiring content as adversary tactics, data sources, and operational needs evolve.
Research emerging AI and advanced technology threats (e.g., prompt injection, model poisoning, adversarial AI, data exposure) and translate them into actionable detection strategies.
Align detection use cases to industry frameworks such as MITRE ATT&CK, MITRE ATLAS, and NIST CSF.
Partner with threat intelligence, detection engineering, threat hunting, red team, and architecture teams to proactively strengthen detection capabilities.
Support proofs of concept and pilots that apply AI to detection engineering and SOC operations, ensuring solutions deliver measurable operational value.
Mentor and guide senior detection engineers and analysts on AI threat concepts and advanced detection strategies.
Communicate complex technical findings clearly to technical teams, leadership, and executive stakeholders. Required Qualifications
7+ years of experience in cybersecurity operations, detection engineering, or SIEM engineering in a senior individual contributor role.
Advanced expertise in detection engineering across the full content lifecycle (design, testing, deployment, tuning, and decommissioning).
Hands on experience applying AI or machine learning capabilities within SOC or detection workflows.
Familiarity with AI security frameworks (e.g., MITRE ATLAS, OWASP AI Security).
Advanced proficiency with SIEM query languages and multi source telemetry across on prem, cloud (IaaS/PaaS/SaaS), and hybrid environments.
Strong understanding of adversary TTPs, including emerging AI enabled threats.
Demonstrated ability to analyze large scale log and telemetry datasets to identify threats and detection gaps.
Strong communication skills, with the ability to present complex technical concepts to both technical and nontechnical audiences.
Preferred Qualifications
Experience leading or contributing to AI?focused SOC pilots, automation initiatives, or advanced detection programs.
Relevant certifications (e.g., CISSP, CySA+, CASP+, CCSP) or comparable credentials.
Bachelor's degree in Cybersecurity, Computer Science, Engineering, or a related field. #LI-KA1
#M1 Ref: #851-Rockville-S1
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Incident Response Monitoring in Fairfax, VA vacancy
- ...Manager to lead a complex operations environment. The successful candidate will manage 24x7 incident response, oversee an operations team, and implement enterprise monitoring tools like Splunk and SolarWinds. Requires at least five years of experience in a similar role...SuggestedFull time
- ...role requires overseeing a 24x7 operation, leading a team responsible for incident response across a diverse IT environment. Candidates should... ...secret-level security clearance. The position focuses on monitoring tools, operational efficiency, and managing critical incidents...Suggested
- ...in McLean, VA, is looking for a Security Monitor 3 to manage surveillance systems and ensure the safety of the premises. Responsibilities include conducting regular patrols, monitoring access points, and responding to incidents. Candidates should have at least 3 years...Suggested
- ...Manager to lead its enterprise information security operations in Fairfax, Virginia. The role involves overseeing security monitoring, incident response, and compliance activities. Responsibilities include maintaining security posture, managing incidents, and ensuring...Suggested
- A leading security services provider is seeking a Security Monitor 2 in McLean, VA. Responsibilities include monitoring surveillance systems, conducting patrols, and responding to incidents. Ideal candidates will have 1+ year(s) of experience in a high-security environment...Suggested
- Overview DecisionPoint is seeking an experienced Monitoring Incident and Event Management Advisory Specialist to join our team supporting... ...Center (TOC) in Arlington, Virginia. This role is largely responsible for providing operational incident and event advisory reports...For contractorsWork experience placementLocal areaAfternoon shift
$27 per hour
...Onsite Transportation Monitoring Operator/Call Center AECOM is seeking Onsite Traffic... ...Operations Center (TOC) Operators are responsible for using Advanced Traffic Management Systems... ...Department roadways and manage events/incidents; dispatching incident management...Work at officeLocal areaRelocation packageAll shiftsFlexible hoursShift workDay shiftAfternoon shift$22.4 per hour
...Security Officer Enhanced Part Time Desk Monitor in MC LEAN, VA , this role is... ...the option to scale back when needed. Responsibilities: Provide customer service to visitors... ...and document visitor, delivery, and/or incident information in a professional manner....Full timePart timeWork at officeLocal areaFlexible hoursShift work- ...Shelter Monitor FUNCTION: The Shelter Monitor is responsible for monitoring the activities of residents of the shelter/center and to ensure compliance with... ...log procedures. Follow appropriate critical incident protocol and accompanying documentation Maintain...Full timeWork at officeMonday to FridayShift work
$25 per hour
...Security Monitor Amentum has an opportunity for a Security Monitor that has an active... ...$25.00 an hour on an SCA contract. Responsibilities Include: ~ Monitor and escort... ...security, facility, or personnel issues/incidents ~ Maintain visual contact and proper...Hourly payContract workFor contractorsLong distance- ...special! The Lead Systems Engineer is responsible for leading the design, implementation,... ...support of enterprise‑grade monitoring and observability solutions for cloud‑hosted... .../JVM performance analysis, and leading incident triage efforts for AWS‑hosted applications...Flexible hours
- ...brightest, we welcome you to apply! Join our team as a Roadway Monitor where you'll play a vital role in overseeing contractor... ...field operations. We have opportunities throughout Virginia. Responsibilities Oversee contractor performance for roadway maintenance, construction...Daily paidContract workFor contractorsWork at officeFlexible hours
- ...RiVidium is seeking a SOC Analyst (Security Monitoring). This role supports IT, Cybersecurity... ...upon contract award. . Key Responsibilities Monitor security events, alerts... ...defined procedures. Coordinate with incident response, engineering, and support...Full timeContract workPart timeShift workNight shift
$34 - $40 per hour
...for a US intelligence community customer. As a Security Monitor, you will be responsible for the security and integrity of the facilities. Amentum... ...communication skills, including the ability to describe incidents via verbal briefing and written report Must have...Hourly payContract workLocal areaRelocation$66k - $106k
...Cloud Security Monitoring and Reporting Engineer (Journeyman) Job Locations... ...Technology Clearance Secret Responsibilities Peraton is seeking a Cloud Security... ...administrators and development teams. Supports incident response and escalation procedures,...Contract workRemote workShift work$107.9k - $195.05k
...seeking an experienced Senior Continuous Monitoring Analyst to support the delivery,... ...national security outcomes. Primary Responsibilities Execute continuous monitoring of security... ...local law enforcement and report the incident to the U.S. Federal Trade Commission (...Local areaImmediate start$89.2k - $147.06k
...full spectrum of operations. AT&T has an opening for a Consolidated Systems Monitoring Administrator to provide 24x7 monitoring of server and network operations. Job Duties/Responsibilities: Provide 24 x 7 monitoring support to Client/Server and Network...Temporary workWork at officeLocal area- ...Administrators (multiple openings) to provide 24x7x365 health monitoring of platform services, infrastructure, and... ...monitoring tools, respond to alerts, coordinate incident management, and serve as the first line of response for outages affecting NIPR, SIPR, and JWICS...Local areaShift workNight shiftRotating shift
$41 per hour
...Job Description Construction Security Monitor with TS/SCI Clearance with CI-Poly Springfield... ...activities, and reporting of security incidents and anomalies. The Security Monitor... ...active construction environment and is responsible for maintaining security awareness and enforcing...Hourly payDaily paidLocal areaImmediate startMonday to Friday$131.3k - $237.35k
...national security outcomes. Primary Responsibilities: ~ Develops automated dashboards... ...visualization tools to support continuous monitoring of IT systems throughout their... ...local law enforcement and report the incident to the U.S. Federal Trade Commission....Local areaImmediate start- ...Cybersecurity Analyst (Vulnerability Management & Continuous Monitoring) Oakton, VA Are you ready to enhance your skills and build... ...with the Risk Management Framework (RMF). This role is responsible for identifying, assessing, prioritizing, and tracking vulnerabilities...
$75.2k - $158.1k
...Job Title: Infrastructure Monitoring Tools Specialist Job Category: Information Technology... ...across the IT landscape. Responsibilities • Implement, integrate, and maintain... ...monitoring and alerting. • Analyze incidents, identify patterns, and develop monitoring...Full timeContract workWork experience placementLocal areaFlexible hours$75.2k - $158.1k
...Infrastructure Monitoring Tools Specialist The Infrastructure Monitoring Tools Specialist... ...across the IT landscape. Responsibilities: Implement, integrate, and maintain... ...proactive monitoring and alerting. Analyze incidents, identify patterns, and develop...- ...senior-level ELK Stack Subject Matter Expert (SME) . The team is responsible for enterprise infrastructure, application, and network... ...for the platform. Responsibilities: Maintain and deploy monitoring and alerting systems within the ELK Stack . Design, configure...Long term contractRemote work
- ...support mission-critical applications and services. The role involves system administration and monitoring, with a focus on ensuring operational health and incident response management. Candidates must have experience with Red Hat Linux, Ansible, Git, Docker, and scripting...
- ...Senior Monitoring Tools Administrator/Engineer Immediate need for a talented Senior Monitoring Tools Administrator/Engineer with... ...McLean, VA. Please review the job description below. Key Responsibilities and Requirements: Strong candidate with expertise in ElasticStack...Contract workImmediate start
- ...Under the supervision of a Manager or Team Lead, the Crosswalk Monitor is responsible for ensuring the safety of customers and clients while crossing the street. The Crosswalk Monitor provides courteous, reliable, and efficient customer services while enforcing safety...
$20 per hour
...role, and you must be willing to work from 5pm-5am on Wednesday, Thursday, and Friday. Please send your resume today. Responsibilities: Pull, transfer, deduct jobs Count and verify (audit) raw materials and completed materials Process...Shift workNight shift$20 per hour
...overnight role, and you must be willing to work from 5pm-5am on Wednesday, Thursday, and Friday. Please send your resume today. Responsibilities Pull, transfer, deduct jobs Count and verify (audit) raw materials and completed materials Process scrap, destroy...Shift workNight shift$26 per hour
...Position Summary With limited direction, this role is responsible for the productivity of collection crews. This includes direct... ...$26 Full-Time/Part-Time Full-Time Position Route Monitor Location VA Residential About the Organization For...Full timeContract workPart time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Incident Response Monitoring. Be the first to apply!


