SOC Engineer

Posted 21 Days Ago
Be an Early Applicant
Columbia, MD, USA
In-Office
145K-190K Annually
Senior level
Security • Cybersecurity
The Role
Designs, deploys, and maintains SOC capabilities including SIEM, log management, detection engineering, threat hunting, incident response, security automation, and dashboards. Supports investigations, malware analysis, digital forensics, and classified cyber defense operations. Develops scripts, playbooks, technical documentation, and architecture recommendations while collaborating with analysts, engineers, and customer stakeholders. The role is fully onsite, with occasional after-hours maintenance work.
Summary Generated by Built In

Come be a part of an exciting and ever-changing program that provides a comprehensive range of state-of-the-art solutions and hands-on assistance in designing, implementing, managing, and sustaining operations across various network environments for our customer.

We provide an environment that fosters and supports innovation and valuing “outside-the-box” thinking to solve complex problems.  There are several training opportunities for team members that want to learn new technologies and stay current with their technical skillset.  We are a highly technical group and nurture growth, with a technical culture of cross-trained teammates with opportunities to develop additional skillsets.

Work Schedule:

8hrs / day, 5 days per week, all onsite

Occasional after hours work for system maintenance

Essential Responsibilities:

We are seeking a highly motivated SOC Engineer to support the design, deployment, and continual improvement of enterprise Security Operations Center (SOC) capabilities. The successful candidate will serve as a key technical contributor responsible for SIEM engineering, log management architecture, threat detection development, security automation, and incident response support within classified environments.

This is a hands-on-keyboard position requiring expertise in deploying and maintaining security monitoring platforms, developing advanced detection capabilities, and improving the overall effectiveness of cyber defense operations. The SOC Engineer will work closely with cybersecurity analysts, incident responders, system administrators, network engineers, and customer stakeholders to enhance security visibility and defend critical mission systems against evolving threats.

Key Responsibilities include:

  • Design, implement, configure, and maintain SIEM, log management, and security monitoring solutions supporting enterprise cybersecurity operations.
  • Evaluate existing SOC architectures and recommend improvements to increase operational effectiveness, scalability, and threat visibility.
  • Engineer and optimize log collection pipelines to ensure comprehensive security event coverage across network, system, application, and cloud environments.
  • Develop, test, tune, and maintain detection content, including correlation searches, threat detections, alerts, signatures, and analytics.
  • Identify gaps in detection coverage and implement solutions aligned with current threat intelligence and adversary techniques.
  • Create and maintain SOC playbooks, standard operating procedures, and incident response workflows.
  • Support security incident investigations through log analysis, endpoint analysis, malware analysis, and forensic data collection.
  • Design and implement security automation and orchestration capabilities to reduce analyst workload and improve response times.
  • Develop metrics, dashboards, and reporting capabilities to measure SOC performance, alert fidelity, detection effectiveness, and operational health.
  • Participate in threat hunting activities to identify stealthy or previously undetected malicious activity.
  • Support malware analysis efforts, including static and dynamic analysis techniques and reverse engineering activities when required.
  • Author scripts and automation tools using languages such as Python, PowerShell, or Bash to improve SOC efficiency and detection capabilities.
  • Document technical architectures, operational procedures, engineering designs, and implementation plans.
  • Provide technical recommendations regarding emerging security technologies, tools, and best practices.
  • Collaborate with customer stakeholders to understand mission requirements and translate those requirements into technical solutions.

Minimum Requirements:

  • 6+ years of experience supporting Security Operations Centers (SOC), cybersecurity engineering, SIEM engineering, or Information System Security Engineering (ISSE).
  • Experience deploying, administering, and maintaining Splunk Enterprise Security and/or other enterprise SIEM platforms.
  • Strong understanding of security event management, log management, and threat detection methodologies.
  • Experience developing SIEM correlation searches, analytic rules, dashboards, and detection use cases.
  • Experience supporting cybersecurity operations within classified or highly regulated environments.
  • Strong knowledge of Windows and Linux operating systems, including system administration and troubleshooting.
  • Experience with scripting or automation using PowerShell, Python, Bash, or similar languages.
  • Experience working within virtualized and containerized environments.
  • Understanding of common attack frameworks such as MITRE ATT&CK and cyber kill chain methodologies.
  • Knowledge of incident response, digital forensics, threat hunting, and malware analysis principles.
  • Experience producing technical documentation, architecture diagrams, implementation plans, and engineering reports.
  • Strong communication and customer engagement skills with the ability to explain technical concepts to both technical and non-technical stakeholders.

Security Clearance Required:

  • TS / SCI

Minimum Education:

  • High School Diploma or equivalent

Preferred

  • Bachelor's Degree in Information Technology, Computer Science, Engineering, or related field

Required Certifications:

This is an IAT3 level billet. Applicant must have:

  • Required IAT Certs: one or more of the following: CISM, CISSP, or equivalent senior-level baseline certification
  • Required vendor certification in one or more relevant technologies (e.g., Microsoft, VMware, Cisco, NetApp, Pure Storage, HP, Dell, Linux+, Red Hat, HBSS, ACAS). Candidates without an active certification must obtain at least one within 6 months of hire

Preferred Qualifications: AI if applicable to your program

  • Experience with Splunk Enterprise Security, Security Onion, Corelight, Zeek, Suricata, Elastic, or similar cybersecurity platforms.
  • Experience with Logstash, Docker, Podman, and containerized application deployments.
  • Experience integrating threat intelligence feeds into SIEM and detection platforms.
  • Familiarity with SOAR technologies and security automation frameworks.
  • Experience performing malware analysis, reverse engineering, or digital forensics.
  • Experience supporting DoD, Intelligence Community, or classified enterprise networks.
  • Experience with Red Hat Enterprise Linux administration.
  • Familiarity with cloud security platforms including AWS, Azure, or Google Cloud.
  • Experience with NIST RMF, NIST 800-53, STIGs, CIS Benchmarks, or equivalent compliance frameworks.
  • Experience with VMware, Hyper-V, Nutanix, or other enterprise virtualization platforms.
  • Experience with enterprise backup, disaster recovery, and business continuity solutions.
  • Prior Security Operations Center experience
  • Experience with Zero Trust architectures
  • Prior Military experience

#javelin

       

Compensation Details:

$145,000 - $190,000

       

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.


Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance


Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

       

Original Posting:

09/18/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

       

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed,  marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.

Skills Required

  • 6+ years of experience supporting SOC, cybersecurity engineering, SIEM engineering, or Information System Security Engineering functions
  • Experience deploying, administering, and maintaining Splunk Enterprise Security or other enterprise SIEM platforms
  • Strong understanding of security event management, log management, and threat detection methodologies
  • Experience developing SIEM correlation searches, analytic rules, dashboards, and detection use cases
  • Experience supporting cybersecurity operations in classified or highly regulated environments
  • Strong knowledge of Windows and Linux administration and troubleshooting
  • Experience with PowerShell, Python, Bash, or similar scripting and automation languages
  • Experience working within virtualized and containerized environments
  • Understanding of MITRE ATT&CK and cyber kill chain methodologies
  • Knowledge of incident response, digital forensics, threat hunting, and malware analysis principles
  • Experience producing technical documentation, architecture diagrams, implementation plans, and engineering reports
  • Strong communication and customer engagement skills
  • TS/SCI security clearance
  • High school diploma or equivalent
  • One or more IAT certification credentials, including CISM, CISSP, or equivalent senior-level baseline certification
  • At least one relevant vendor certification, or ability to obtain one within six months of hire
  • Bachelor’s degree in information technology, computer science, engineering, or a related field
  • Experience with Splunk Enterprise Security, Security Onion, Corelight, Zeek, Suricata, Elastic, or similar platforms
  • Experience with Logstash, Docker, Podman, and containerized application deployments
  • Experience integrating threat intelligence feeds into SIEM and detection platforms
  • Familiarity with SOAR technologies and security automation frameworks
  • Experience in malware analysis, reverse engineering, or digital forensics
  • Experience supporting DoD, Intelligence Community, or classified enterprise networks
  • Experience with Red Hat Enterprise Linux administration
  • Familiarity with AWS, Azure, or Google Cloud security platforms
  • Experience with NIST RMF, NIST 800-53, STIGs, CIS Benchmarks, or equivalent compliance frameworks
  • Experience with VMware, Hyper-V, Nutanix, or other enterprise virtualization platforms
  • Experience with enterprise backup, disaster recovery, and business continuity solutions
  • Prior Security Operations Center experience
  • Experience with Zero Trust architectures
  • Prior military experience

Amentum Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Amentum and has not been reviewed or approved by Amentum.

  • Healthcare Strength — Healthcare offerings are described as comprehensive, with medical, dental, and vision plans and multiple PPO/HSA options. Mental health support via an employee assistance program and other wellness resources is also included in the benefits mix.
  • Retirement Support — Retirement support is positioned as a meaningful part of total rewards through a 401(k) plan with employer matching. Profit-sharing contributions and immediate or near-term vesting in some cases further strengthen the retirement value proposition.
  • Leave & Time Off Breadth — Time-off benefits are presented as solid for the sector, including tiered PTO accrual by tenure and a set of paid holidays. Role-dependent flexible or remote work options and leave programs add to perceived work-life support.

Amentum Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chantilly, VA
18,261 Employees

What We Do

Amentum is a premier global technical and engineering services partner supporting critical programs of national significance across defense, security, intelligence, energy, and environment. We draw from a century-old heritage of operational excellence, mission focus, and successful execution underpinned by a strong culture of safety and ethics. Headquartered in Germantown, Md., we employ more than 20,000 people in 48 states and 28 foreign countries and territories. Visit us at amentum.com to explore how we deliver excellence for our customers’ most vital missions.

Similar Jobs

Remote or Hybrid
2 Locations
132624 Employees
In-Office
2 Locations
62K-141K Annually

INTOO Logo INTOO

Software Engineer

Other • Professional Services
Remote or Hybrid
14 Locations
70 Employees
100K-125K Annually

Wipfli Logo Wipfli

Data Management & Governance Analyst III

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
88K-132K Annually

Similar Companies Hiring

SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account