Senior Security Operations Engineer

Tensley Consulting
Annapolis Junction, MD, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$130,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Active Directory Bash Shell Code Review Signals Intelligence Cyber Security Github Intrusion Detection and Prevention Python (Programming Language) Log Analysis Microsoft Software Network Forensics
+16 more
Windows PowerShell Kusto Query Language Security Information and Event Management Wireshark Scripting Mitre Att&ck Cyber Threat Analysis Gitlab Git Microsoft InTune Cybercrime Microsoft Sentinel Cyber Warfare Splunk Software Version Control Vulnerability Analysis

Job description

The Senior Security Operations Engineer is the named operational owner of security monitoring, detection engineering, incident response, threat hunting, vulnerability operations, insider risk review, supply chain and software risk assessment, security training and exercise design, security code and configuration review, and assessor-facing evidence collection. The role operationalizes a Microsoft 365 GCC High security stack that is configurationally complete but not yet operated as a coordinated function. The platforms (Sentinel, Defender XDR, Entra ID, Purview, Intune) are deployed. The work is detection authoring, tuning, hunting, evidence assembly, supply chain risk operations, code and content review, training program ownership, and the operational paper trail the C3PAO and DIBCAC will examine. The role draws on senior production experience operating enterprise SIEM, EDR, and intrusion-analysis platforms in regulated federal environments. The Microsoft stack ramp is structured into the first ninety days. The platform transition leverages established detection engineering, threat hunting, and audit-discipline practices rather than requiring greenfield skill development. The first thirty days are environment review, paper-trail establishment, and supply chain baseline inventory. The first ninety days produce the first documented threat hunt, the first tabletop exercise, the first code review cycle on detection content, and the first operating-cadence pass at the SOC operationalization claim. The role contributes to CMMC Level 2 certification documentation (July 2026), supports the Level 2 C3PAO mock (June 2026), and prepares the operational evidence for Level 3 DIBCAC assessment in the late-2026 to early-2027 window., About TensleyTensley Consulting is a Service-Disabled Veteran-Owned Small Business focused on mission engineering in support of the United States Intelligence Community and the Department of Defense. Our team consists of System Engineers, Software Engineers, Test Engineers, and Signals Analysts performing work throughout the Continental United States (CONUS) and Outside the Continental United States (OCONUS). Equal Opportunity, Diversity & InclusionWe aim to build a team that represents a variety of backgrounds, perspectives, and skills. We embrace inclusion and ensure equal employment opportunity without discrimination or harassment based on race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, national origin, marital or domestic/civil partnership status, genetic information, citizenship status, military or veteran status, or any other personal characteristic.

Requirements

Do you have experience in Vulnerability scanning?, 15+ years in security operations, detection engineering, incident response, or defensive cyber operations in a federal or regulated environment Hands-on production experience with enterprise SIEM (Splunk Enterprise Security, Microsoft Sentinel, or equivalent) including correlation search authoring, hunting, and content management Production experience with intrusion analysis and network forensics platforms (Security Onion, Wireshark, ACAS, HBSS, or equivalent) Working proficiency with a SIEM query language with demonstrated ability to author custom correlation logic at production scale; capacity to ramp to KQL within sixty days Experience leading or supervising a Security Operations Center, Cyber Protection Team, or equivalent operational element with multi-person team composition Experience contributing to federal compliance assessments, operational readiness inspections, or audit-equivalent review (CMMC, NIST SP 800-171, NIST SP 800-53, RMF, intelligence community oversight, or equivalent) Experience authoring or contributing to security plans, control implementation statements, or assessor-facing artifacts Experience designing and delivering technical cyber training, exercise content, or curriculum at the equivalent of advanced leader course level Active U.S. security clearance (TS/SCI or higher preferred for broader program value) Frameworks and Methodology Working knowledge of NIST risk management frameworks (any of NIST SP 800-53, NIST SP 800-171, NIST SP 800-37 RMF) with demonstrated ability to map across frameworks Familiarity with NIST SP 800-30 risk assessment methodology Working knowledge of NIST SP 800-61 Rev 2 incident handling Familiarity with NIST SP 800-161 supply chain risk management or equivalent SCRM methodology MITRE ATT&CK framework: tactics, techniques, sub-techniques, and detection mapping Tooling and Skills Threat intelligence consumption with experience translating multi-source telemetry into actionable findings (SIGINT correlation experience translates directly) Vulnerability scanning and analysis (ACAS, HBSS, or commercial equivalent) Version control familiarity for security content (Git, GitLab, or GitHub) Scripting in Python, PowerShell, Shell, or equivalent Endpoint and identity audit (Conditional Access review, sign-in log analysis, privileged access audit) on Entra ID, Active Directory, or equivalent identity platform Communication, Training, and Review Demonstrated ability to author technical documentation at assessor-facing quality Comfortable participating in formal assessment interviews, operational readiness inspections, or oversight reviews Able to explain configuration intent and operational behavior to non-technical executives Demonstrated capacity to design, deliver, and evaluate technical security training Experience leading after-action reviews or operational lessons-learned processes Demonstrated capacity to review detection content, security configuration, or operational artifacts for correctness and provide actionable feedback

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Paid time off
  • Vision insurance
  • Health savings account
  • Dental insurance, Salary: $130,000-$150,000. This represents the typical salary range for this position, but is not guaranteed. Salary is based on experience, location and contractual requirements which could fall outside of the range listed., 100% paid medical coverage with HSA and company contribution 100% paid vision, dental, short-term, and long-term premium 12% 401(k) contribution (not a match) Education and training budget 6 weeks and 3 days of PTO And much more!

Come grow with us!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all