Security Operations Engineer
Core
Monitor and analyze system logs, network traffic, and user behavior to identify, investigate, and remediate security incidents for US federal government clients.
Role type
Senior Security Operations Engineer (SOC)
Builds
Incident response actions and security event documentation for Joint Staff and CNMF operations
Domain
US Federal Government / Cybersecurity Operations
Deliverable
client delivery
Required skills
Security Operations Center (SOC) management, SIEM/IDS/IPS tool usage, incident investigation and response, threat intelligence analysis, security policy development, cloud security (GovCloud/AWS/Azure/GCP), compliance with NIST and DOD regulations
Preferred skills
Cyber operations infrastructure development, operational employment of cyber systems
Technologies
SIEM, IDS/IPS, NIST, GovCloud, AWS, Azure, Google Cloud
Responsibilities
Monitor and analyze system logs, network traffic, and user behavior; Utilize intrusion detection systems, firewalls, and SIEM to detect incidents; Conduct thorough investigations to determine incident nature and scope; Execute containment, mitigation, and remediation actions; Document incidents and resolutions; Develop and refine enterprise-level security policies
Seniority
Senior, hands-on IC