Sr. SOC Engineer (Splunk ES & SOAR)
SGA
Sr. SOC Engineering Consultant
Software Guidance & Assistance, Inc., (SGA), is searching for a Sr. SOC Engineering Consultant for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD, Tysons, VA, Dallas, TX, or New York, NY. Hybrid - 3x a week on-site
About the Role
- Our Security Operations Center is evolving from foundational capabilities into a mature, comprehensive security operations program. We need an experienced SOC engineer who has been part of a top-tier SOC and can provide technical vision and leadership to guide our detection engineering and automation efforts.
- This role focuses on building robust detection capabilities, automating security responses, and creating frameworks that enable our SOC analysts to effectively identify and respond to threats. You will work closely with our threat intelligence and hunting teams to translate security research into actionable detections and automated responses.
Team Structure & Growth Opportunity
- This position reports to the Director of Security Platform Engineering and serves as a senior individual contributor with potential to transition into a technical lead role as the SOC engineering team expands. You will collaborate closely with SOC analysts, threat intelligence teams, threat hunters, and platform engineering teams.
- The role offers the opportunity to shape SOC capabilities, establish engineering standards, and build a world-class detection and response program using industry-leading tools. This is a senior-level position requiring demonstrated experience in mature SOC environments and the ability to provide technical vision and mentorship.
Detection Engineering
• Design and implement comprehensive detection use cases aligned with the MITRE ATT&CK framework
• Conduct gap analysis of current detection coverage and develop roadmap to address gaps
• Build and tune correlation searches, alerts, and detection logic in Splunk Enterprise Security
• Implement Risk-Based Alerting (RBA) methodologies to improve signal-to-noise ratio
• Develop detection strategies for multi-cloud environments (AWS, GCP, Azure)
• Continuously evaluate and improve detection effectiveness based on SOC feedback
Security Automation & Orchestration
• Design and implement automated response playbooks using Splunk SOAR
• Build integrations between security tools to enable automated investigation and response workflows
• Develop scripts and automation (Python, Bash, PowerShell) to streamline SOC operations
• Create reusable automation frameworks that scale across multiple use cases
• Collaborate with platform engineering to ensure reliable automation infrastructure
SOC Architecture & Vision
• Define what a mature SOC capability looks like using Splunk ES, SOAR, and supporting tools
• Identify gaps and shortcomings in current SOC implementation and provide clear remediation guidance
• Establish best practices, standards, and frameworks for detection engineering and response
• Mentor platform engineering team on SOC-specific requirements and approaches
• Contribute to long-term SOC strategy and capability development
Cross-Functional Collaboration
• Partner with threat intelligence and threat hunting teams to operationalize research into detections
• Work with SOC analysts to understand investigation workflows and improve detection quality
• Collaborate with platform engineering teams to implement and maintain SOC infrastructure
• Participate in incident response activities to validate and refine detection and automation capabilities
• Document detection logic, playbooks, and technical architectures
Required Qualifications
• SOC Experience: 5+ years in a Security Operations Center environment with exposure to mature SOC operations and best practices
• SIEM Expertise: Hands-on experience with Splunk Enterprise Security or comparable enterprise SIEM platforms (building correlation searches, alerts, dashboards, and ES-specific frameworks)
• Detection Engineering: Proven experience developing security detections, use cases, and alert tuning methodologies
• MITRE ATT&CK Framework: Practical application of MITRE ATT&CK for detection coverage mapping and gap analysis
• Security Automation: Experience building automated response workflows and playbooks (SOAR platforms preferred)
• Scripting: Strong proficiency in Python, PowerShell, or Bash for automation and integration development
• Cloud Security: Understanding of cloud security monitoring and detection across AWS, GCP, and Azure environments
• Analytical Mindset: Ability to identify gaps, define clear vision for improvement, and guide teams toward maturity
Preferred Qualifications
• Splunk SOAR (Phantom) hands-on experience
• Splunk UEBA or behavioral analytics platform experience
• Risk-Based Alerting (RBA) implementation experience
• Threat hunting background with detection engineering application
• Infrastructure automation and CI/CD pipeline knowledge
• Experience mentoring or leading detection engineering teams
• Relevant certifications (GIAC, CISSP, or similar)
- ...you will build and mature our SOC capabilities within our MSSP practice... ...team ) and a strong security engineering background across EDR/MDR,... ...365/Windows Defender , SIEM, SOAR, email security, vulnerability... ...Analytics, Sentinel). SIEM: Splunk, Microsoft Sentinel, Elastic,...SplunkSeniorTemporary workWork at officeLocal areaRemote workVisa sponsorshipFlexible hoursShift work
- ...Job Title: Sr. SOC Analyst Duration: 12+ Months (Possible extension... ...Will leverage SIEM, EDR, and SOAR tooling to investigate... ...compromise. ~ Partner with Engineering teams to tune detections,... ...proficiency with SIEM (e.g., Splunk, QRadar, Sentinel), EDR (e.g....SplunkSenior
- ...Sr. Endpoint Detection & Response (EDR) Tools Engineer Location: Washington DC / Los Angeles / Seattle / NYC Duration... ...within a Security Operations Center (SOC) environment, including but not... ...aggregation and analysis tools, such as Splunk ~ EDR vendor certifications...SplunkSeniorLong term contract
- ...program. We have a functioning SOC built on Google SecOps (... ...function. Key Responsibilities: SIEM/SOAR Operations (Google SecOps) Own... ...Google SecOps RBAC Detection Engineering Build and deploy production... ...equivalent enterprise SIEM such as Splunk, Sentinel, or QRadar, with...SplunkSeniorPermanent employmentRemote workFlexible hours
- ...validation tools like Chaos Monkey, Gremlin, Resiliency Studio etc Experience in APM toolsets (DynaTrace, AppDynamics, Datadog, Splunk) Experience in defining Non-Functional Requirements (NFR) & strategy to achieve NFR Experience in testing and optimizing high...SplunkSenior
- ...Cybersecurity Engineer MetTel is a global communications solutions... ...toolset including CyberArk, Splunk, OKTA, Tenable, SOAR platforms, and other... ...Splunk Enterprise Security (ES) for security monitoring and... ...security operations center (SOC) activities and on-call rotation...Splunk
- ...Fastest Growing Companies. The candidate will be part of a team of Splunk Engineers maintaining various clients' Splunk instances with a heavy... ...Requirements Splunk Consultant Certification Splunk ES Accreditation Experience with RBA is highly suggested Ability...Splunk
$168k - $195k
...skilled Senior Cyber Security Engineer - SIEM and Automation to lead... ...Collaborate with SOC analysts to refine detection logic... ...and orchestration efforts with SOAR integrations where applicable... ...experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar, Elastic...SplunkSeniorWork at officeLocal areaImmediate startRemote workRelocation- ...We are seeking a Principal Splunk Engineer to lead the design, operation,... ...is a critical component of our SOC and threat-detection capabilities... ...Admin, Enterprise Architect, ES Analyst/ES Admin, or equivalent... ...Enterprise Security (ES) SOAR (Phantom or comparable) AWS/...SplunkSeniorWork at officeShift workDay shift
- ...Join to apply for the Senior SOC Analyst/Engineer (Tier 3) role at STIG STIGroup’s Managed Security Operations (MSO) team provides cybersecurity... ...workflows. Contribute to Automation improvements (e.g., SOAR). Produce incident reports and communicate findings to stakeholders...SeniorRemote workVisa sponsorshipFlexible hours
$125k - $160k
...Responsibilities Summary: As a Senior Incident Response Engineer, you will work with a team of highly... ...aspects of our services. Successful Sr. Incident Response Engineers at Frontdoor... ...a logging platform like LogScale, ELK or Splunk. Experience with cloud security in AWS,...SplunkSeniorFull timeFor contractorsRemote work$80 - $90 per hour
...Stefanini Group is looking for Sr Endpoint Security Engineer for a globally recognized company... ...or similar, including managed SOC integrations) You'll help drive... ...Integrate with SIEM/SOAR platforms (e.g., Sentinel, Splunk) Compliance & Governance...SplunkSeniorRemote work- ...pipeline etc [Required] Familiarity with monitoring related tools and frameworks like Splunk, ElasticSearch, Prometheus, AppDynamics Job Profile Associate Principal, Software Engineering: Java Technical Skills & Background [Required] Java-based software development...SplunkSeniorImmediate start
- ...remote role, we will consider applicants based in LATAM. Our Engineering team is having a blast while delivering the most sophisticated... ...monitoring and observability experience (Grafana, VictoriaMetrics, Splunk, AlertManager). Solid Linux systems knowledge, networking...SplunkSeniorLocal areaRemote work
$140k
...Description Job Description Job Title: Senior Cybersecurity Engineer Location: 405 Lexington Avenue, New York, NY 10174... ...systems for in-depth analysis of data and trends, including Splunk/Splunk ES (3+ years), Cisco AMP (1-2 years), Varonis (1-2 years) Practical...SplunkSeniorWork at office2 days per week3 days per week$106k - $170k
...global investment firm in New York is seeking an Associate Security Engineer. The role involves providing security platform engineering... ...cloud technologies, and hands-on experience with SIEM tools like Splunk. The position offers a competitive salary ranging from $106,000...Splunk- ...Framework Ventures is seeking a SOC Analyst III to enhance security posture by analyzing alerts and leading incident responses. Ideal candidates will have 4–6 years in security operations and strong skills in security monitoring, incident investigation, and threat hunting...Senior
- ...A leading technology firm is seeking a Senior SOC Security Engineer focused on application and supply chain security. This remote role involves monitoring incidents in a 24/7 environment, leading investigations into software supply chain security threats, and mentoring...SeniorRemote workNight shift
- ...development and at least 4 years of direct ServiceNow experience. Other responsibilities include developing integrations with tools like Splunk and collaborating with various IT teams. This role supports digital transformation within the organization and offers opportunities...SplunkSenior
- ...Senior Tealeaf Engineer Senior Tealeaf Engineer job at Akaasa Technologies. Remote. Years of Exp.: 8+ years exp. Work Location: Remote... ...for web questions tealeaf replay cloud tealeaf implementation splunk Position Description Tealeaf installation, upgrades and patching...SplunkSeniorLocal areaRemote work
- ...Gravity Engineering Services Pvt Ltd. is seeking a DFT Engineer to implement Design for Test methodologies in semiconductor designs, ensuring testability of complex Systems on Chip (SoCs). You will collaborate with RTL designers and troubleshoot DFT-related issues during...Senior
- ...in the United States is seeking a Senior Professional Services Engineer to deliver security solutions while providing managed services to... ...the field. Responsibilities include leading deployments, managing SOC operations, and ensuring customer satisfaction. This role also...Senior
$165k - $200k
...response, threat detection, SIEM engineering, log management, and third-... ...pipelines, and help mature StubHub's SOC-less approach to Detection &... ...tooling where needed (SIEM, SOAR, EDR, etc.) Security... ...familiarity with SIEM platforms (e.g., Splunk, ELK, Chronicle, Panther, or...SplunkWork at officeRemote workWorldwideFlexible hours- ...SOC Analyst We are a specialized technology staffing agency... ...Partner with the security engineering and platform engineering teams... ...~ Experience with SIEM tools (Splunk, SumoLogic, Sentinel, QRadar,... ...controls a plus. ~ Experience in SOAR (Security Orchestration Automation...Splunk
- ...Galaxy is seeking a Security Engineer to oversee SOC operations, manage cybersecurity threats, and develop custom security scripts. The ideal candidate will have SOC experience and strong scripting skills (Python, PowerShell). Responsibilities include incident management...Senior
$40 per hour
...Information Security Analyst/SOC Analyst Location: Chandler, AZ... ...Collaborate with infrastructure, engineering, and support teams during... ...on SIEM experience, preferably Splunk Enterprise-level cybersecurity... ...Splunk certifications Exposure to SOAR or automation tools is a plus...SplunkTemporary workWork at officeRemote workWeekend workAfternoon shift$77.5k - $140.9k
...world. Job Title: CyberSecurity SIEM Engineer (Senior SDC) About the job At EY, you... ...with an emphasis on integrating SIEM and SOAR capabilities into business operations. An... ...and other SOAR products (Falcon Fusion, Splunk SOAR, Google Chronicle SecOps, LogicApps,...SplunkSeniorFull timeWork experience placementSummer holidayFlexible hours- ...Our client, a leader in critical infrastructure and security solutions, is seeking a dedicated and experienced Senior SOC Consultant Analyst to join their dynamic team. As a Senior SOC Consultant Analyst, you will be instrumental in supporting both IT and OT security operations...SeniorWeekly payContract workTemporary workRemote workFlexible hours
$95.86k - $208.27k
...is currently seeking a Senior Specialist, SOC Analyst Level II to join our Advisory... ...dashboards, monitors, and collaborating with SIEM Engineers to refine alert logic and improve... ...Google SecOps, MS Sentinel, CrowdStrike, Splunk, Qradar, LogRhythm, SolarWinds) Demonstrated...SplunkSeniorH1bLocal areaShift workNight shiftWeekend work$260k - $270k
...Built for the most demanding enterprise workloads, from AI to Splunk Observability, genomics and PACS medical imaging, geospatial datasets... ...: ~8+ years in a customer-facing technical role (Systems Engineer, Solutions Architect, or Healthcare Solutions Engineer) at a...SplunkSeniorLocal areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. SOC Engineer (Splunk ES & SOAR). Be the first to apply!
- senior game producer New York, NY
- senior manager process engineering New York, NY
- senior manufacturing engineer New York, NY
- senior director fp&a New York, NY
- senior manager clinical operations New York, NY
- senior community manager New York, NY
- senior lead project manager New York, NY
- senior manager quality engineering New York, NY
- senior device engineer New York, NY
- senior full stack developer New York, NY


