Single-owner corp to corp OR 1099 are encouraged to apply!Cyber Engineer (TO2 SOC)-Virginia Beach, VARequired Education: Bachelor's Degree in Information Technology or related field.Required Experience: 6-8years of cybersecurity engineering with SIEM and ingestion pipelinesLocation: Virginia Beach, VA-100% on Customer siteRequired Clearance: Active SECRET with TS/SCI eligibilityDescription:This individual will provide Cyber Engineering support for building and operating a Security Operations Center (SOC). The engineer will initially help assess the customer's current environment, document existing SOC-related capabilities across multiple contracts, identify gaps, and support development of a roadmap to establish an integrated and fully operational SOC. Once the SOC is operational, the engineer will manage, integrate, and optimize security technologies, leveraging existing enterprise services via customer-defined agreements, while actively supporting SOC monitoring, detection, and response functions.
Responsibilities:- Perform weekly project management tasks, including tracking project tasks and deliverables, and ensuring delivery timelines are met
- Act as team leader for other SOC staff and customers, local single point of contact for issues
- Support assessment of the customer's current SOC-related tools and processes, identifying existing coverage and gaps.
- Demonstrated ability to successfully manage complex cybersecurity programs in a fast-paced operational environment, coordinating resources, schedules, risks, and dependencies across multiple teams.
- Install, configure, and maintain ingestion pipelines across Splunk and Elastic environments.
- Administer and optimize Microsoft Azure, Intune, Defender Endpoint Security, and Active Directory in support of SOC functions.
- Manage and support production Zscaler platforms, implementing Zero Trust (ZT) security controls.
- Partner with security teams to ensure data ingestion, analysis, correlation, and visualization supports SOC operations.
- Contribute to the roadmap for building a unified, customer-run SOC, integrating existing enterprise services into the new construct.
- Maintain compliance with DoDD 8140.01 Cyber Workforce requirements for CNDSP Level III roles.
- Provide subject matter expertise and guidance on SOC technologies and processes, including incident detection, response, and continuous monitoring.
- Engage with customer stakeholders and partner teams to build consensus, align processes, and support SOC governance activities.
Required Qualifications- Flexibility to meet any threat scenario 24/7/365 as mission dictates.
- Active SECRET clearance with TS/SCI eligibility.
- U.S. Citizenship.
- Meets DoDD 8140.01 CSWF requirements for CNDSP Level III.
- 4+ years of experience installing, configuring, and maintaining ingestion pipelines (Splunk/Elastic).
- 2+ years of experience with Microsoft Azure, Intune, Defender Endpoint Security, and Active Directory.
- 2+ years of project management experience
- 2+ years of team lead experience for a SOC or similar leadership role
- Experience managing production Zscaler platforms with Zero Trust controls.
- Working knowledge of/experience with SOC processes such as incident response, threat hunting, and continuous monitoring.
- Strong interpersonal skills with the ability to communicate technical concepts to both technical and non-technical stakeholders.
Desirable Qualifications:- Certified Splunk Architect and/or Elastic/OpenSearch Engineer.
- CISSP, Security+, or relevant Microsoft/Azure security certifications.
- Project Management Professional (PMP)® Certification
- Security Onion SIEM experience
- Experience as a security advisor or consultant for procurement and deployment of new security technologies.
- Experience with Security Orchestration, Automation and Response (SOAR) tools and technologies (e.g. Splunk Phantom, Ansible, Python, etc.)