Sr. Cyber Operations Engineer III (NOC/SOC) (6797)
$180,000–$220,000 year
On-siteWashington, United States
Job Summary
Conduct integrated NOC/SOC operations by designing, implementing, and optimizing centralized visibility into enterprise infrastructure, networks, cloud environments, and cybersecurity events. Implement and tune security monitoring, correlation rules, and threat detection capabilities using Microsoft Sentinel, Azure Monitor, Log Analytics, and Defender to identify suspicious activity and incidents. Lead technical investigation, triage, and resolution of network, infrastructure, and cybersecurity incidents while developing automated workflows, scripts, and SOAR capabilities to accelerate response. Monitor network availability, performance, and utilization to resolve critical issues, and maintain standard operating procedures, incident response playbooks, and knowledge documentation. Collaborate with client stakeholders and technical teams to ensure situational awareness and rapid issue resolution, while developing dashboards and KPIs to measure operational effectiveness. Requires Top Secret clearance, 10+ years in network/cybersecurity operations, and proficiency in PowerShell, Python, and KQL.
Required Qualifications
- Active Top Secret security clearance
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline
- 10+ years of experience in network operations, cybersecurity operations, infrastructure operations, systems engineering, or related technical roles
- 5+ years of experience supporting enterprise NOC, SOC, or integrated network/security operations environments
- Strong experience with Microsoft Sentinel, Microsoft Defender, Azure Monitor, Log Analytics, or comparable SIEM, security monitoring, and observability technologies
- Hands-on experience with network monitoring, SIEM, EDR/XDR, vulnerability management, incident management, and enterprise observability platforms
- Strong understanding of TCP/IP, DNS, routing, firewalls, VPNs, load balancing, network segmentation, and enterprise network architectures
- Experience monitoring and troubleshooting Microsoft Azure, hybrid cloud, on-premises infrastructure, networks, applications, and security services
- Experience developing detection rules, dashboards, alerts, automated response workflows, operational runbooks, and incident response playbooks
- Proficiency with PowerShell, Python, Kusto Query Language (KQL), or similar scripting/query languages used for operations and security automation
- Experience supporting large enterprise, public sector, or regulated environments and familiarity with NIST RMF, applicable security baselines, compliance requirements, and incident reporting processes
- CISSP, CySA+, GIAC, Microsoft Security, Azure, or equivalent certifications
- Strong troubleshooting, analytical, communication, and incident management skills with the ability to operate effectively during high-priority operational or cybersecurity events
- In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.