Security Operations Center (SOC) Engineer
Job Description
Job Description
Description:
Job Title: Security Operations Center (SOC) Engineer
Location: Northern Virginia
Department: Cyber Security Services
Reports To: Management
FLSA Status: Full Time/Non-exempt
Job Purpose:
The SOC Engineer plays a critical role in protecting the organization’s infrastructure and data by monitoring, analyzing, and responding to cybersecurity threats. This position ensures the effective operation of security technologies, provides incident response support, and helps optimize detection and prevention capabilities within the Security Operations Center (SOC). The SOC Engineer collaborates with IT, Cybersecurity, and business teams to strengthen defenses, minimize risk, and maintain compliance with security standards.
Duties & Responsibilities:
The SOC Engineer responsibilities include, but are not limited to:
- Monitor, analyze, and respond to security alerts and events from SIEM and other security appliances.
- Determine the relevance and priority of alerts; escalate incidents as appropriate.
- Tune and configure security appliances (IDS/IPS, next-gen firewalls, VPNs) to reduce false positives and optimize detection.
- Perform deep packet inspection, malware/phishing analysis, and forensic packet review using tools such as Wireshark or tcpdump.
- Participate in incident response activities, including investigation, containment, eradication, and recovery.
- Document security events, incidents, and processes in a clear, professional manner.
- Develop, implement, and maintain logging and auditing strategies in collaboration with IT and Cybersecurity, including integration of monitoring, SIEM, and ticketing systems.
- Provide subject matter expertise on security technologies such as IDS/IPS, firewalls, endpoint security, SIEM tools (Splunk, QRadar, Sentinel), and vulnerability management platforms (Nessus, Qualys, OpenVAS).
- Support the design, architecture, and deployment of secure network and cloud solutions across on-premises, hybrid, and cloud (AWS, Azure, GCP) environments.
- Collaborate with cross-functional teams to integrate security into network, application, and cloud operations.
- Develop SOPs, runbooks, and incident response playbooks aligned with ITIL, NIST, or DoD frameworks.
- Stay current with emerging cybersecurity threats, vulnerabilities, and advanced frameworks (e.g., Zero Trust, SASE).
- Mentor junior analysts and provide training to colleagues as needed.
- Ensure compliance with organizational standards, policies, and regulatory requirements (NIST, ISO 27001, CIS Controls, DoD 8530).
The SOC Engineer is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies.
Requirements:Qualifications
- Bachelor’s degree in Computer Science, Information Security, Network Engineering, or a related field (or equivalent experience).
- 3–5 years of experience in a SOC, NOSC, or cybersecurity engineering role, with hand-on operational or build experience.
- Strong understanding of TCP/IP, routing, switching, VLANs, VPNs, and firewall technologies (Palo Alto, Cisco ASA/Firepower).
- Proficiency with SIEM platforms (Splunk, QRadar, Sentinel) and monitoring tools (SolarWinds, PRTG, Zabbix, Datadog).
- Experience with IDS/IPS technologies, endpoint detection tools (CrowdStrike, SentinelOne, Microsoft Defender), and vulnerability management (Nessus, Qualys, OpenVAS).
- Familiarity with cloud security monitoring and controls in AWS, Azure, or GCP.
- Scripting and automation experience (Python, PowerShell, Ansible) strongly preferred.
- Familiarity with incident response processes and best practices.
- Strong understanding of cyber threats, attack vectors, and adversary tactics, techniques, and procedures (TTPs).
- Proficiency in analyzing logs, network traffic, and security events to identify anomalies.
- Relevant certifications strongly preferred: Security+, CEH, GCIA, GCIH, CISSP, CCNP Security, Splunk Certified Power User/Admin.
- Strong troubleshooting skills using network analysis and forensic tools.
- Familiarity with Zero Trust architectures, microsegmentation, and advanced security frameworks.
- Excellent communication and documentation skills; ability to explain technical security concepts clearly to both technical and non-technical audiences.
- Ability to work collaboratively in high-pressure situations and adapt to rapidly evolving threats.
Preferred Qualifications
- Cloud security expertise in AWS (Security Hub, GuardDuty), Azure (Defender, Sentinel), or GCP (Security Command Center).
- Experience with advanced automation/orchestration tools such as Terraform, Ansible, or Red Hat Ansible Automation.
- Familiarity with Zero Trust networking models, microsegmentation strategies, and SASE frameworks.
- Hands-on experience with forensic tools (FTK, EnCase, Volatility) or advanced packet analysis methods.
- Strong background in creating and managing incident response playbooks and operational runbooks.
- Prior experience building or enhancing SOC/NOSC environments and defining operational workflows.
- Additional certifications that would be advantageous:
- CISSP (Certified Information Systems Security Professional)
- CCNP Security / Enterprise
- Splunk Certified Power User or Admin
- GIAC certifications (GSEC, GCIA, GCIH, GCFA)
- PCNSE (Palo Alto Networks Certified Network Security Engineer)
- VMware VCP-NV (for network virtualization)
- Terraform Associate or other infrastructure-as-code certifications
Recommended Jobs
Product Owner (Remote - Virginia)
This position is posted by Jobgether on behalf of iTech AG. We are currently looking for a Product Owner in Virginia (USA). We are seeking a Product Owner to lead the delivery of high-value software…
Landscape Account Manager
Job Description Job Description RSG is growing here in Charlottesville, and we are looking to add an Account Manager to our amazing staff. In this position you will serve as the primary point of …
Senior Digital Marketing Analyst
Description Join Team CARFAX as a Senior Digital Marketing Analyst Isn't it time you bragged about where you work? At CARFAX, we do, every day. We pride ourselves on being mission-focused on …
General Maintenance Worker
Job Description Job Description Salary: General Maintenance Worker ATI is seeking a highly motivated, qualified, and experienced General Maintenance Worker for a new facility located in Spr…
Ophthalmic Scribe - New College Grads Welcome, Training Provided! Full benefits, paid local travel,
Job Description Job Description EyeCare Partners is the nation's leading provider of clinically integrated eye care. Our national network of over 300 ophthalmologists and 700 optometrists provide…
Mechanical Piping Foreman
Job Description Job Description Job Title: Piping Foreman - Commercial Construction Position Overview: We are seeking a motivated and dedicated individual to join our Commercial Construction…
Senior Acquisition Specialist - APSO
Job Description Job Description Overview JST is currently seeking a Senior Acquisition Specialist - APSO (Acquisition function) to join our team. This is a full-time Onsite position with poten…
Dishwasher/Janitor
For this position, pay will be variable by location - See additional job details and benefits below. As our Dishwasher, it'll be your job to ensure everything is clean, spotless and sanit…
Brewery Server
Join our team at our Front Royal location! Tipped Wage: Average Total Pay $23-27 per hour Applicants must have flexible and weekend availability Craft Beer and Food! – Vibrissa Beer is a produc…
Level IV Financial Analyst (Audit-Secret Cleared)
Level IV Financial Analyst Location: Alexandria, VA (Onsite 2 days per week) Division: Redhawk Administrative Services EEO Class: Professional FLSA Classification: Exempt Employment…