SOC Engineer

6 days ago


Washington, DC, United States ABBTECH Professional Resources Full time
Location: Remote with quarterly travel to DC

Clearance: Active Public Trust


This role focuses on engineering SOC data feed solutions, implementing SOAR capabilities, and ensuring feed health through cross-team collaboration. The ideal candidate will have strong cybersecurity expertise, including network security, SIEM, incident response, and threat detection.

They will also serve as the backup SOC Lead, overseeing operations, managing escalations, and providing updates to senior leadership during critical incidents when the primary lead is unavailable.

Key Responsibilities
- Microsoft Sentinel Engineering: Maintain and optimize a Microsoft Sentinel SIEM/SOAR solution in alignment with client requirements, industry best practices, and federal compliance mandates.
- Data Integration: Configure and manage log/data feeds from diverse sources (e.g., Fluent Bit, Windows Events, M365, cloud services, endpoint/security platforms).
- Parsing & Normalization: Develop and refine log parsing rules using Regex, DCRs, and custom transformations to ensure accurate and usable data in Sentinel.
- SOAR Development: Engineer automation and orchestration solutions using Microsoft Logic Apps, Azure Functions, and PowerShell/Python scripts to improve SOC efficiency and incident response.
- Threat Detection Engineering: Build, tune, and optimize analytic rules, UEBA, dashboards, and reports to improve detection and response coverage.
- Collaboration: Partner with cross-functional teams (network, endpoint, cloud, IT ops) to integrate new data sources and deliver actionable SOC capabilities.
- Documentation & Knowledge Transfer: Develop and maintain clear documentation of SOC architecture, log source onboarding, and automation playbooks; provide training for SOC analysts on new tools and processes.
- Advisory & Improvement: Conduct gap analyses of existing SOC capabilities, recommend improvements, and contribute to SOC process maturity.
- Incident Response Support: Provide Tier 3 support and assist with complex investigations when required.

Required Qualifications
- Ability to obtain Public Trust clearance.
- 2-5 years of experience in network defense, SOC engineering, or cybersecurity operations.
- Hands-on experience with Microsoft Sentinel, including log onboarding, rule development, and automation.
- Proficiency with log parsing and normalization (Regex, Fluent Bit, DCRs, KQL).
- Strong scripting skills in PowerShell and/or Python for automation and data handling.
- Experience configuring and maintaining data feeds for SOC visibility (cloud, endpoint, network, and on-prem).
- Familiarity with incident response concepts, threat detection engineering, and SOAR workflows.
- Excellent written and verbal communication skills with ability to work across technical and non-technical teams.

Preferred Qualifications
- Knowledge of federal cybersecurity mandates (M-21-31, NIST Cybersecurity Framework, CISA Incident/Vulnerability Playbooks, BOD 22-01).
- Experience with Microsoft Logic Apps, Azure Functions, or other SOAR development platforms.
- Experience with UEBA configuration to enhance anomaly detection.
- Background in AI/ML frameworks for cyber analytics.
- Experience building SOC metrics, dashboards, and reporting for operational visibility.
- Familiarity with M365, Azure security tools, ServiceNow workflows, and CISA CDM tools.
- Relevant certifications such as CISSP, CISM, Microsoft Security Operations Analyst (SC-200), or Azure Security Engineer (AZ-500).

Education & Experience
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).
- 5+ years of progressive cybersecurity/SOC experience (engineering and ope)

Position Details:

  • Pay Rate / Range:_______$52-$62.50_______
The above salary range represents the range expected for the position; however, final salary offers are based on a number of factors such as the position's responsibilities; the candidate's experience, education, and skills; location; travel required; and current market conditions.
  • Benefits (Regular, Full Time Employees):
  • Medical, Dental, and Vision offerings
  • Weekly Direct Deposit
  • Paid Holidays and Personal Time Off
  • 401(k) with match
  • Voluntary Life and AD&D, Short / Long Term Disability, plus other voluntary coverages
  • Pre-Paid Legal and Employee Assistance Programs
  • Northwest Federal Credit Union Membership
  • BB&T @ Work Program
This program requires US Citizenship

ABBTECH is an EOE/Minorities/Women/Disabled Individuals/Veterans
  • SOC Engineer

    1 week ago


    Washington, DC, United States System One Full time

    SOC Engineer REMOTE (DC Area Preferred) Must be willing to come in once a quarter for a team meeting US citizenship required per government contract Must be able to obtain Public Trust clearance This role focuses on engineering SOC data feed solutions, implementing SOAR capabilities, and ensuring feed health through cross-team collaboration. The ideal...

  • SOC Engineer

    2 weeks ago


    Washington, DC, United States System One Full time

    SOC Engineer REMOTE (DC Area Preferred) Must be willing to come in once a quarter for a team meeting US citizenship required per government contract Must be able to obtain Public Trust clearance This role focuses on engineering SOC data feed solutions, implementing SOAR capabilities, and ensuring feed health through cross-team collaboration. The ideal...

  • SOC Engineer

    2 weeks ago


    Washington, DC, United States System One Full time

    SOC Engineer REMOTE (DC Area Preferred) Must be willing to come in once a quarter for a team meeting US citizenship required per government contract Must be able to obtain Public Trust clearance This role focuses on engineering SOC data feed solutions, implementing SOAR capabilities, and ensuring feed health through cross-team collaboration. The ideal...

  • SOC Engineer

    2 weeks ago


    Washington, DC, United States Apex Systems Full time

    Apex Systems is seeking a SOC Engineer whi can work remotely within the U.S. The candidate should be willing to go onsite in Washington, D.C. once per quarter. Therefore, local candidates are preferred. Summary: This role focuses on engineering SOC data feed solutions, implementing SOAR capabilities, and ensuring feed health through cross-team collaboration....

  • SOC Analysts

    1 week ago


    Washington, DC, United States eTeam Full time

    We are looking for a proactive and analytical Security Operations Center (SOC) Analyst to join our AI-driven threat detection and incident response team. The ideal candidate will be experienced in monitoring, analyzing, and responding to security threats using both traditional methods and modern AI-powered tools. Key Responsibilities: Monitor and analyze...


  • Washington, DC, United States BOOZ, ALLEN & HAMILTON, INC. Full time

    SOC Project Technical Manager The Opportunity: We are seeking an experienced Security Operations Center (SOC) Project Technical Manager to lead the operations and technical direction of a large-scale government SOC. This role is responsible for managing SOC personnel, driving operational excellence, overseeing SOC analyst functions, and ensuring effective...


  • Washington, DC, United States BOOZ, ALLEN & HAMILTON, INC. Full time

    SOC Project Technical Manager The Opportunity: We are seeking an experienced Security Operations Center (SOC) Project Technical Manager to lead the operations and technical direction of a large-scale government SOC. This role is responsible for managing SOC personnel, driving operational excellence, overseeing SOC analyst functions, and ensuring effective...


  • Washington, DC, United States ABBTECH Professional Resources Full time

    Mid - SOC Analyst / Splunk Administrator Washington DC (Hybrid 1 day a week in office) Onsite on Tuesdays 7 AM to 3:30 PM Public Trust This position is a hybrid position designed to bridge SOC Analysis with Splunk Engineering and Content Creation. The candidate should have competency with administering Splunk, creating custom content with SPL, data...

  • SIEM Engineer

    1 week ago


    Washington, DC, United States Tyto Athene, LLC Full time

    Description Tyto Athene is searching for an experienced SIEM Engineer that will be responsible for deployment, administration, log ingestion, health monitoring, and content creation for the SIEM. In addition to SIEM engineering, you will be helping to administer a variety of other security tools within the client environment. Responsibilities: Administer...

  • SIEM Engineer

    4 days ago


    Washington, DC, United States Tyto Athene, LLC Full time

    Description Tyto Athene is searching for an experienced SIEM Engineer that will be responsible for deployment, administration, log ingestion, health monitoring, and content creation for the SIEM. In addition to SIEM engineering, you will be helping to administer a variety of other security tools within the client environment. Responsibilities: Administer...