Pay: $160,000.00 - $177,000.00 per year
Job description:
The SOC Technical SME reports directly to the SOC Program Manager and serves as the technical backbone of a 24/7 security operations center, providing deep expertise in log analysis, SIEM administration and tuning, and detection engineering. This role is responsible for interrogating high-volume log sources, identifying gaps in visibility and coverage, and ensuring the toolset and detection logic keep pace with evolving adversary tradecraft.
Essential Duties:- Deeply analyze and interrogate logs across diverse sources (network, host, application, cloud, identity) to identify anomalies, gaps, and indicators of compromise
- Monitor, tune, and optimize SIEM platforms to improve detection fidelity and reduce false positive/negative rates
- Evaluate log volume, retention, and ingestion pipelines to ensure completeness of data and identify blind spots in coverage
- Develop, refine, and maintain correlation rules, use cases, and detection content aligned to current threat intelligence techniques
- Serve as an escalation point for Tier 1/2 analysts on complex triage, investigation, and incident analysis
- Utilize and maintain proficiency across relevant security tool stacks (SIEM, EDR, NDR, SOAR, threat intel platforms, packet capture/analysis tools)
- Support containment, eradication, and recovery efforts during security incidents as a senior technical responder
- Collaborate with the SOC Program Manager to report on SOC metrics, detection coverage, and operational effectiveness
- Recommend and support implementation of process improvements, automation, and playbooks to increase SOC efficiency
- Stay current on emerging threats, adversary TTPs, and industry best practices, incorporating relevant intelligence into detection strategy
- Assist in mentoring and upskilling junior SOC analysts on log analysis and investigative techniques
Qualifications:A degree in Computer Science, Information Systems, Engineering, or a related discipline is preferred. At least seven (7) years of information security experience, with demonstrated depth in SIEM administration/engineering, log analysis, and security tool stacks in a SOC environment. Experience with one or more SIEM platforms (e.g., Splunk, QRadar, Elastic, Sentinel) required. Familiarity with threat intelligence integration strongly preferred. CySA+, GCIA, GCIH, or CISSP required.
Benefits:
- Health insurance
- Health savings account
Application Question(s):
- Do you have experience with one or more SIEM platforms (e.g., Splunk, QRadar, Elastic, Sentinel)?
- Are you familiar with threat intelligence integration?
- Do you have information security experience, with demonstrated depth in SIEM administration/engineering, log analysis, and security tool stacks in a SOC environment?
- Do you have a degree in Computer Science, Information Systems, Engineering, or a related discipline?
License/Certification:
- CySA+, GCIA, GCIH, or CISSP (Required)
Ability to Commute:
- Fort Meade, MD 20755 (Required)
Work Location: In person