Security Operations Center Engineer III

MartinFederal Consulting, LLC.
Arlington, VA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Systems Engineering Cloud Computing Cloud Computing Security Cyber Security Information Systems Digital Forensics Identity and Access Management Intrusion Detection and Prevention Network Security Security Information and Event Management Software Vulnerability Management
+9 more
Cloud Platform System Mitre Att&ck Malware Cyber Threat Analysis SC Clearance Information Technology Cybercrime Cyber Warfare Splunk

Job description

MartinFed is seeking a highly experienced Security Operations Center (SOC) Engineer III to provide advanced cybersecurity monitoring, detection, analysis, and incident response support within a complex enterprise environment. The ideal candidate will serve as a senior technical resource responsible for engineering, optimizing, and maintaining security operations platforms while leading efforts to detect, investigate, and mitigate cybersecurity threats., + Lead security monitoring operations utilizing SIEM technologies, including Splunk and Cribl platforms.

  • Design, implement, configure, and maintain enterprise security monitoring and logging solutions.

  • Perform advanced threat detection, threat hunting, and incident analysis activities across enterprise networks and cloud environments.

  • Investigate security alerts, incidents, and anomalies to determine root cause, impact, and remediation actions.

  • Develop and maintain security use cases, correlation searches, dashboards, reports, and automated workflows.

  • Engineer and optimize log collection, normalization, enrichment, and retention strategies.

  • Support the deployment, administration, and optimization of Splunk Enterprise, Splunk Cloud, and Cribl environments.

  • Develop security content to improve detection capabilities for emerging cyber threats and adversarial tactics.

  • Lead incident response activities and coordinate containment, eradication, recovery, and lessons learned efforts.

  • Conduct security assessments and identify opportunities to improve monitoring, visibility, and operational effectiveness.

  • Collaborate with cloud, network, and systems engineering teams to integrate security controls and monitoring solutions.

  • Develop operational procedures, technical documentation, and standard operating procedures (SOPs).

  • Provide technical leadership and mentorship to junior SOC analysts and engineers.

  • Generate executive-level reports, metrics, and briefings regarding security incidents, trends, and organizational risk.

  • Support compliance initiatives, audits, and security assessments in accordance with federal cybersecurity requirements.

  • Stay current on emerging threats, attack techniques, and cybersecurity technologies to enhance defensive capabilities.

Requirements

  • United States Citizen with a DoD Secret clearance.

  • Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a closely related technical field. Relevant experience may be considered in lieu of degree requirements.

  • Minimum of 10 years of experience performing IT Security Operations in enterprise or government environments.

  • Demonstrated experience supporting Security Operations Centers (SOCs), Cyber Defense Operations, or Security Monitoring Programs.

  • Advanced experience administering, engineering, and supporting Splunk Enterprise and/or Splunk Cloud environments.

  • Experience implementing and maintaining log management, SIEM, and security analytics platforms.

  • Strong knowledge of incident response, threat hunting, digital forensics, malware analysis, and vulnerability management.

  • Experience with cloud security monitoring and AWS security services.

  • Knowledge of cybersecurity frameworks and standards, including:

  • NIST Cybersecurity Framework (CSF)

  • NIST 800 Series

  • Risk Management Framework (RMF)

  • FISMA

  • Security Technical Implementation Guides (STIGs)

  • MITRE ATT&CK Framework

  • Strong understanding of network security, endpoint security, identity and access management, and security architecture.

  • Experience developing security dashboards, correlation searches, alerts, reports, and automation workflows.

  • Excellent analytical, troubleshooting, communication, and leadership skills.

PHYSICAL REQUIREMENTS & ENVIRONMENTAL CONDITIONS

  • Inside office environment.

  • Working on a computer for long periods of time.

About the company

Founded in 2007 in Huntsville, AL, MartinFed provides the U.S. government with customer-focused, performance-based solutions using technology and an empowered workforce as an engine to drive its customers’ missions. Our goal is to attract the best and brightest within their field.

We invest in our people because they are our greatest asset. They cultivate our purpose, embody and reflect our core values, and define our culture. MartinFed’s core values that set us apart are the following:

  • Be Driven - We are fueled by the hunger to learn more and do more.

  • Be Curious - We engage in continuous improvement - never accepting the status quo.

  • Be Humble - We seek honest feedback to strengthen our relationships.

  • Pursue Excellence - We strive to achieve extraordinary results and do not settle for mediocrity.

Strive for excellence and consider joining our growing team today!

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

Videos

See all

Related articles

See all