Security Operations Center Technical SME

Athletes Global

• $160K — $177K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Degree in Computer Science, Information Systems, Engineering, or related field preferred.
  • 7+ years of information security experience, particularly in SIEM administration and log analysis.
  • Proficiency with SIEM platforms like Splunk, QRadar, Elastic, or Sentinel required.
  • Familiarity with threat intelligence integration is strongly preferred.
  • Certifications such as CySA+, GCIA, GCIH, or CISSP are required.

Responsibilities

  • Analyze logs from various sources to identify anomalies and indicators of compromise.
  • Monitor and optimize SIEM platforms to enhance detection accuracy.
  • Evaluate log ingestion and retention to identify data coverage gaps.
  • Develop and maintain detection rules and use cases based on threat intelligence.
  • Act as an escalation point for complex investigations and incident analysis.
  • Utilize and maintain proficiency in security tool stacks including SIEM and EDR.
  • Support incident response efforts as a senior technical responder.
  • Collaborate with the SOC Program Manager on metrics and operational effectiveness.
  • Recommend process improvements and automation to enhance SOC efficiency.
  • Stay updated on emerging threats and incorporate intelligence into detection strategies.

Benefits

  • Health insurance
  • Health savings account
Full Job Description
Pay: $160,000.00 - $177,000.00 per year

Job description:

The SOC Technical SME reports directly to the SOC Program Manager and serves as the technical backbone of a 24/7 security operations center, providing deep expertise in log analysis, SIEM administration and tuning, and detection engineering. This role is responsible for interrogating high-volume log sources, identifying gaps in visibility and coverage, and ensuring the toolset and detection logic keep pace with evolving adversary tradecraft.

Essential Duties:

- Deeply analyze and interrogate logs across diverse sources (network, host, application, cloud, identity) to identify anomalies, gaps, and indicators of compromise
- Monitor, tune, and optimize SIEM platforms to improve detection fidelity and reduce false positive/negative rates
- Evaluate log volume, retention, and ingestion pipelines to ensure completeness of data and identify blind spots in coverage
- Develop, refine, and maintain correlation rules, use cases, and detection content aligned to current threat intelligence techniques
- Serve as an escalation point for Tier 1/2 analysts on complex triage, investigation, and incident analysis
- Utilize and maintain proficiency across relevant security tool stacks (SIEM, EDR, NDR, SOAR, threat intel platforms, packet capture/analysis tools)
- Support containment, eradication, and recovery efforts during security incidents as a senior technical responder
- Collaborate with the SOC Program Manager to report on SOC metrics, detection coverage, and operational effectiveness
- Recommend and support implementation of process improvements, automation, and playbooks to increase SOC efficiency
- Stay current on emerging threats, adversary TTPs, and industry best practices, incorporating relevant intelligence into detection strategy
- Assist in mentoring and upskilling junior SOC analysts on log analysis and investigative techniques

Qualifications:

A degree in Computer Science, Information Systems, Engineering, or a related discipline is preferred. At least seven (7) years of information security experience, with demonstrated depth in SIEM administration/engineering, log analysis, and security tool stacks in a SOC environment. Experience with one or more SIEM platforms (e.g., Splunk, QRadar, Elastic, Sentinel) required. Familiarity with threat intelligence integration strongly preferred. CySA+, GCIA, GCIH, or CISSP required.

Benefits:

  • Health insurance
  • Health savings account


Application Question(s):

  • Do you have experience with one or more SIEM platforms (e.g., Splunk, QRadar, Elastic, Sentinel)?
  • Are you familiar with threat intelligence integration?
  • Do you have information security experience, with demonstrated depth in SIEM administration/engineering, log analysis, and security tool stacks in a SOC environment?
  • Do you have a degree in Computer Science, Information Systems, Engineering, or a related discipline?


License/Certification:

  • CySA+, GCIA, GCIH, or CISSP (Required)


Ability to Commute:

  • Fort Meade, MD 20755 (Required)


Work Location: In person

Similar Jobs

More Information Technology Jobs

Find similar Security Operations Center Technical SME jobs: