Sr. SOC Engineer (Splunk ES & SOAR)

Rockville, MD, US • Posted 30+ days ago • Updated 6 hours ago
Contract W2
On-site
USD $72.00 - 80.00 per hour
Company Branding Image
Fitment

Dice Job Match Score™

🛠️ Calibrating flux capacitors...

Job Details

Skills

  • Leadership
  • Security Analysis
  • IT Management
  • Roadmaps
  • Cloud Computing
  • Orchestration
  • Threat Analysis
  • Research
  • Collaboration
  • Incident Management
  • Security Operations
  • System On A Chip
  • SIEM
  • Dashboard
  • Elasticsearch
  • Use Cases
  • Mapping
  • Gap Analysis
  • Workflow
  • Scripting
  • Python
  • Windows PowerShell
  • Bash
  • Cloud Security
  • Amazon Web Services
  • Google Cloud Platform
  • Google Cloud
  • Microsoft Azure
  • Analytical Skill
  • Splunk
  • Analytics
  • Continuous Integration
  • Continuous Delivery
  • Mentorship
  • CISSP
  • MEAN Stack
  • Customer Service
  • Training And Development
  • SAP BASIS

Summary

Software Guidance & Assistance, Inc., (SGA), is searching for an Sr. SOC Engineering Consultant for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD or Tysons, VA.
Hybrid - 3x a week on-site
About the Role
  • Our Security Operations Center is evolving from foundational capabilities into a mature, comprehensive security operations program. We need an experienced SOC engineer who has been part of a top-tier SOC and can provide technical vision and leadership to guide our detection engineering and automation efforts.
  • This role focuses on building robust detection capabilities, automating security responses, and creating frameworks that enable our SOC analysts to effectively identify and respond to threats. You will work closely with our threat intelligence and hunting teams to translate security research into actionable detections and automated responses.

Team Structure & Growth Opportunity
  • This position reports to the Director of Security Platform Engineering and serves as a senior individual contributor with potential to transition into a technical lead role as the SOC engineering team expands. You will collaborate closely with SOC analysts, threat intelligence teams, threat hunters, and platform engineering teams.
  • The role offers the opportunity to shape SOC capabilities, establish engineering standards, and build a world-class detection and response program using industry-leading tools. This is a senior-level position requiring demonstrated experience in mature SOC environments and the ability to provide technical vision and mentorship.

Detection Engineering
Design and implement comprehensive detection use cases aligned with the MITRE ATT&CK framework
Conduct gap analysis of current detection coverage and develop roadmap to address gaps
Build and tune correlation searches, alerts, and detection logic in Splunk Enterprise Security
Implement Risk-Based Alerting (RBA) methodologies to improve signal-to-noise ratio
Develop detection strategies for multi-cloud environments (AWS, Google Cloud Platform, Azure)
Continuously evaluate and improve detection effectiveness based on SOC feedback
Security Automation & Orchestration
Design and implement automated response playbooks using Splunk SOAR
Build integrations between security tools to enable automated investigation and response workflows
Develop scripts and automation (Python, Bash, PowerShell) to streamline SOC operations
Create reusable automation frameworks that scale across multiple use cases
Collaborate with platform engineering to ensure reliable automation infrastructure
SOC Architecture & Vision
Define what a mature SOC capability looks like using Splunk ES, SOAR, and supporting tools
Identify gaps and shortcomings in current SOC implementation and provide clear remediation guidance
Establish best practices, standards, and frameworks for detection engineering and response
Mentor platform engineering team on SOC-specific requirements and approaches
Contribute to long-term SOC strategy and capability development
Cross-Functional Collaboration
Partner with threat intelligence and threat hunting teams to operationalize research into detections
Work with SOC analysts to understand investigation workflows and improve detection quality
Collaborate with platform engineering teams to implement and maintain SOC infrastructure
Participate in incident response activities to validate and refine detection and automation capabilities
Document detection logic, playbooks, and technical architectures
Required Qualifications
SOC Experience: 5+ years in a Security Operations Center environment with exposure to mature SOC operations and best practices
SIEM Expertise: Hands-on experience with Splunk Enterprise Security or comparable enterprise SIEM platforms (building correlation searches, alerts, dashboards, and ES-specific frameworks)
Detection Engineering: Proven experience developing security detections, use cases, and alert tuning methodologies
MITRE ATT&CK Framework: Practical application of MITRE ATT&CK for detection coverage mapping and gap analysis
Security Automation: Experience building automated response workflows and playbooks (SOAR platforms preferred)
Scripting: Strong proficiency in Python, PowerShell, or Bash for automation and integration development
Cloud Security: Understanding of cloud security monitoring and detection across AWS, Google Cloud Platform, and Azure environments
Analytical Mindset: Ability to identify gaps, define clear vision for improvement, and guide teams toward maturity
Preferred Qualifications
Splunk SOAR (Phantom) hands-on experience
Splunk UEBA or behavioral analytics platform experience
Risk-Based Alerting (RBA) implementation experience
Threat hunting background with detection engineering application
Infrastructure automation and CI/CD pipeline knowledge
Experience mentoring or leading detection engineering teams
Relevant certifications (GIAC, CISSP, or similar)

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: sgainc
  • Position Id: 26-00204
  • Posted 30+ days ago

Company Info

About Software Guidance & Assistance

Founded in 1981, SGA is a technology and resource solutions provider with a national footprint and headquartered in the shadow of Wall Street. We’re a certified women-owned business. We provide contingent staffing, direct placement, and professional and managed services to transform businesses and evolve careers. We’re small enough to tailor our services to each client and big enough to deliver for some of the world’s largest employers. Our professionals are experts in areas such as IT, finance, accounting, risk, and clinical.

SGA provides contingent staffing, direct placement, and professional and managed services nationwide for Fortune 500 companies, mid-size businesses and select startups.

Our core skillsets include all areas of technology – business & data analysis, cyber & network security, database administration, development & architecture, infrastructure, program & project management, quality assurance & testing. We also deliver talent across professional business functions such as finance, accounting, risk, and clinical.

Our Professional & Managed Services team delivers IT projects through onshore, offshore and hybrid delivery models. We develop software products, modernize applications, add features, and integrate and maintain systems. Our scope covers, among others, complex application suites, data management and visualizations, machine learning and mobile applications.

About_Company_OneAbout_Company_Two
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Holmdel, New Jersey

Today

Contract

USD 72.46 - 83.33 per hour

New York, New York

Today

Full-time

USD 210,000.00 - 225,000.00 per year

New York, New York

Today

Full-time

USD 160,000.00 - 180,000.00 per year

Remote

Today

Contract

Search all similar jobs