> Markdown version of [/jobs/ext/1448777-federal-soc-engineer-detect-and-respond-analyst-us-citizen](https://www.wearedevelopers.com/jobs/ext/1448777-federal-soc-engineer-detect-and-respond-analyst-us-citizen). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Federal SOC Engineer Detect and Respond Analyst (US Citizen) - **Company:** PSI Services LLC - **Location:** Salem, OR, United States (Remote available) - **Experience:** Experienced - **Salary:** $125,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, User Authentication, Microsoft Azure, Cyber Security, Intrusion Detection and Prevention, Intrusion Detection Systems, Network Security, Linux System Administration, Windows PowerShell, Cloud Services, Security Information and Event Management, Software Vulnerability Management, Data Logging, Software Security, Mttr, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cybercrime, CIS Benchmarks - **Published:** July 26, 2026 - **Apply:** https://dejobs.org/x/x/D66E2A3E03524C41ABFA5D77AB427847/job/ ## About the Role * US Citizenship required due to Government client requirements * Bachelor's degree in computer science or equivalent training/certification. * 7+ years of working experience as a Security Engineer or Systems Engineer * 3+ years of working experience with email security tools such as Proofpoint * 3+ years of working experience with CrowdStrike EDR and SIEM solutions * Ability to achieve federal security clearance, must be a US Citizen * Experience with FedRamp security controls * In-depth knowledge and understanding of the integration of AWS with fundamental Information Security methodologies for both architectural review and implementation * Strong knowledge of Windows and Linux environments * Experience drafting and promoting security policy with all levels of business stakeholders * Experience and detailed technical knowledge of security engineering, system and network security, authentication and security protocols, cryptography, and application security * Good written and verbal communication skills with the ability to follow a project from beginning to end while providing updates along the way, while prioritizing time and dealing with multiple projects * Experience with CIS Hardening Standards and/or DISA STIGs ## Description The SOC Engineer Detect and Respond Analyst is responsible for designing, implementing, and operating PSI's security infrastructure while actively monitoring, detecting, and responding to security threats across the enterprise. This hybrid role combines engineering ownership of security platforms with hands-on SOC operations , ensuring that systems are not only secure by design but continuously monitored and defended. This role partners with senior management, business units, and technology teams to build scalable security solutions and maintain a strong operational security posture aligned with ISO 27001, NIST, CIS, SOC 2, and FedRAMP standards. The individual operates as both a technical leader for security tooling and a front-line responder for security incidents, bridging the gap between engineering and operations. The SOC Engineer Detect and Respond Analyst works within a global team to design, implement, tune, and monitor security controls, improve detection capabilities, and respond to evolving cyber threats. Role Responsibilities Security Engineering & Platform Ownership * Lead projects to evaluate, select, implement, and optimize security technologies * Design, configure, implement, and maintain enterprise security platforms: * SIEM and log aggregation solutions * EDR/XDR (CrowdStrike) * Email security (Proofpoint or equivalent) * Firewalls, IDS/IPS, DLP, and vulnerability management tools * Develop and tune detection rules, correlation logic, and alerting within SIEM and EDR platforms * Integrate cloud (AWS/Azure) telemetry and security controls into centralized monitoring * Maintain and enhance security logging architecture across infrastructure and applications * Ensure systems are hardened and aligned with CIS benchmarks and DISA STIGs * Participate in architecture reviews for on-prem and cloud solutions * Automate security processes using scripting (PowerShell, etc.) SOC Operations & Threat Monitoring * Monitor security alerts, logs, and events to identify potential threats and anomalies * Perform tier 2/3 incident analysis, including investigation, containment, eradication, and recovery * Conduct root cause analysis and develop remediation recommendations * Perform threat hunting based on attacker TTPs and emerging intelligence * Enrich alerts with contextual data from multiple sources (SIEM, EDR, threat intel) * Maintain and improve SOC playbooks and response procedures * Participate in on-call rotation and incident response activities Governance, Compliance & Documentation * Ensure adherence to ISO 27001, NIST, SOC2, CIS, and FedRAMP controls * Support audits by providing evidence of monitoring, detection, and response capabilities * Define and maintain technical security standards and runbooks * Maintain accurate and up-to-date documentation of security architecture and processes * Report on SOC metrics (MTTD, MTTR, incident trends, detection coverage ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers)