Demo

Sr. SOC Engineer (Splunk ES & SOAR)

Software Guidance & Assistance, Inc. (SGA, Inc.)
Rockville, MD Full Time
POSTED ON 3/24/2026
AVAILABLE BEFORE 7/21/2026
Software Guidance & Assistance, Inc., (SGA), is searching for an Sr. SOC Engineering Consultant for a CONTRACT assignment with one of our premier Regulatory clients in Rockville, MD or Tysons, VA.

Hybrid - 3x a week on-site

About The Role

  • Our Security Operations Center is evolving from foundational capabilities into a mature, comprehensive security operations program. We need an experienced SOC engineer who has been part of a top-tier SOC and can provide technical vision and leadership to guide our detection engineering and automation efforts.
  • This role focuses on building robust detection capabilities, automating security responses, and creating frameworks that enable our SOC analysts to effectively identify and respond to threats. You will work closely with our threat intelligence and hunting teams to translate security research into actionable detections and automated responses.

Team Structure & Growth Opportunity

  • This position reports to the Director of Security Platform Engineering and serves as a senior individual contributor with potential to transition into a technical lead role as the SOC engineering team expands. You will collaborate closely with SOC analysts, threat intelligence teams, threat hunters, and platform engineering teams.
  • The role offers the opportunity to shape SOC capabilities, establish engineering standards, and build a world-class detection and response program using industry-leading tools. This is a senior-level position requiring demonstrated experience in mature SOC environments and the ability to provide technical vision and mentorship.

Detection Engineering

  • Design and implement comprehensive detection use cases aligned with the MITRE ATT&CK framework
  • Conduct gap analysis of current detection coverage and develop roadmap to address gaps
  • Build and tune correlation searches, alerts, and detection logic in Splunk Enterprise Security
  • Implement Risk-Based Alerting (RBA) methodologies to improve signal-to-noise ratio
  • Develop detection strategies for multi-cloud environments (AWS, GCP, Azure)
  • Continuously evaluate and improve detection effectiveness based on SOC feedback

Security Automation & Orchestration

  • Design and implement automated response playbooks using Splunk SOAR
  • Build integrations between security tools to enable automated investigation and response workflows
  • Develop scripts and automation (Python, Bash, PowerShell) to streamline SOC operations
  • Create reusable automation frameworks that scale across multiple use cases
  • Collaborate with platform engineering to ensure reliable automation infrastructure

SOC Architecture & Vision

  • Define what a mature SOC capability looks like using Splunk ES, SOAR, and supporting tools
  • Identify gaps and shortcomings in current SOC implementation and provide clear remediation guidance
  • Establish best practices, standards, and frameworks for detection engineering and response
  • Mentor platform engineering team on SOC-specific requirements and approaches
  • Contribute to long-term SOC strategy and capability development

Cross-Functional Collaboration

  • Partner with threat intelligence and threat hunting teams to operationalize research into detections
  • Work with SOC analysts to understand investigation workflows and improve detection quality
  • Collaborate with platform engineering teams to implement and maintain SOC infrastructure
  • Participate in incident response activities to validate and refine detection and automation capabilities
  • Document detection logic, playbooks, and technical architectures

Required Qualifications

  • SOC Experience: 5 years in a Security Operations Center environment with exposure to mature SOC operations and best practices
  • SIEM Expertise: Hands-on experience with Splunk Enterprise Security or comparable enterprise SIEM platforms (building correlation searches, alerts, dashboards, and ES-specific frameworks)
  • Detection Engineering: Proven experience developing security detections, use cases, and alert tuning methodologies
  • MITRE ATT&CK Framework: Practical application of MITRE ATT&CK for detection coverage mapping and gap analysis
  • Security Automation: Experience building automated response workflows and playbooks (SOAR platforms preferred)
  • Scripting: Strong proficiency in Python, PowerShell, or Bash for automation and integration development
  • Cloud Security: Understanding of cloud security monitoring and detection across AWS, GCP, and Azure environments
  • Analytical Mindset: Ability to identify gaps, define clear vision for improvement, and guide teams toward maturity

Preferred Qualifications

  • Splunk SOAR (Phantom) hands-on experience
  • Splunk UEBA or behavioral analytics platform experience
  • Risk-Based Alerting (RBA) implementation experience
  • Threat hunting background with detection engineering application
  • Infrastructure automation and CI/CD pipeline knowledge
  • Experience mentoring or leading detection engineering teams
  • Relevant certifications (GIAC, CISSP, or similar)

SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at https://sgainc.com/ .

SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company EEO page to request an accommodation or assistance regarding our policy.

Salary : $72 - $80

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Software Guidance & Assistance, Inc. (SGA, Inc.)

  • Software Guidance & Assistance, Inc. (SGA, Inc.) Great Falls, MT
  • Software Guidance & Assistance, Inc., (SGA), is searching for an Accountant for a Contract to hire assignment with one of our premier Healthcare clients in... more
  • 13 Days Ago

  • Software Guidance & Assistance, Inc. (SGA, Inc.) Rockville, MD
  • Software Guidance & Assistance, Inc., (SGA), is searching for a Jr. Developer for a CONTRACT assignment with one of our premier Regulatory clients in the D... more
  • 13 Days Ago

  • Software Guidance & Assistance, Inc. (SGA, Inc.) Rockville, MD
  • Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Python/Angular Engineer for a contract assignment with one of our premier Financial ... more
  • 13 Days Ago

  • Software Guidance & Assistance, Inc. (SGA, Inc.) Aurora, IL
  • Software Guidance & Assistance, Inc., (SGA), is searching for a Senior Accountant for a Contract assignment with one of our premier Healthcare clients in A... more
  • 13 Days Ago


Not the job you're looking for? Here are some other Sr. SOC Engineer (Splunk ES & SOAR) jobs in the Rockville, MD area that may be a better fit.

  • SOC LLC Bethesda, MD
  • Sr. Cyber Range Engineer needed for a Direct Hire opportunity with SOC's client to work onsite in Annapolis Junction, MD. *Candidate must have an active To... more
  • 1 Month Ago

  • ConsultNet Technology Services and Solutions Rockville, MD
  • Title : Sr. SOC Engineer Location : DMV Target Start Date : ASAP Type : contract Pay Rate : DOE About the Role We are seeking a highly skilled Senior SOC S... more
  • 1 Month Ago

AI Assistant is available now!

Feel free to start your new journey!