INFO SECURITY ANALYST IV
<p><strong>SOC Engineer</strong></p><p><strong>Location</strong>: Washington DC</p><p><strong>Clearance: Public Trust (Must be eligible)</strong></p><p><strong>Duration: </strong>6-month Contract to Hire</p><p><br></p><p><strong>Position Overview</strong></p><p>We are seeking a skilled and motivated SOC Engineer to join our cybersecurity operations team. This role is focused on engineering data feed solutions for the Security Operations Center (SOC), implementing SOAR capabilities, and ensuring the health and performance of data integrations through collaboration across technical teams.</p><p>The ideal candidate will bring deep cybersecurity expertise, particularly in network security, SIEM/SOAR platforms, incident response, and threat detection. This position also serves as the backup SOC Lead, stepping in to manage operations, escalations, and leadership communications during critical incidents when the primary lead is unavailable.</p><p><strong>Key Responsibilities</strong></p><ul><li>Microsoft Sentinel Engineering: Maintain and optimize Microsoft Sentinel SIEM/SOAR solutions in accordance with client needs and federal compliance standards.</li><li>Data Integration: Configure and manage log/data feeds from various sources including Fluent Bit, Windows Events, M365, cloud services, and endpoint/security platforms.</li><li>Parsing & Normalization: Develop and refine log parsing rules using Regex, DCRs, and custom transformations to ensure accurate data ingestion.</li><li>SOAR Development: Build automation and orchestration workflows using Microsoft Logic Apps, Azure Functions, and PowerShell/Python scripting.</li><li>Threat Detection Engineering: Design and tune analytic rules, UEBA, dashboards, and reports to enhance threat detection and response capabilities.</li><li>Cross-Team Collaboration: Work closely with network, endpoint, cloud, and IT operations teams to onboard new data sources and improve SOC functionality.</li><li>Documentation & Training: Create and maintain documentation for SOC architecture, onboarding processes, and automation playbooks; train SOC analysts on new tools and procedures.</li><li>Process Improvement: Conduct gap analyses and recommend enhancements to SOC capabilities and maturity.</li><li>Incident Response Support: Provide Tier 3 support and assist in complex investigations as needed.</li></ul>
<p><strong>Required Qualifications</strong></p><ul><li>2–5 years of experience in SOC engineering, network defense, or cybersecurity operations.</li><li>Hands-on experience with Microsoft Sentinel, including log onboarding, rule creation, and automation.</li><li>Proficiency in log parsing and normalization (Regex, Fluent Bit, DCRs, KQL).</li><li>Strong scripting skills in PowerShell and/or Python.</li><li>Experience managing data feeds across cloud, endpoint, network, and on-prem environments.</li><li>Familiarity with incident response, threat detection, and SOAR workflows.</li><li>Excellent communication skills and ability to collaborate across technical and non-technical teams.</li><li>Ability to obtain a Public Trust Clearance.</li></ul><p><strong>•Preferred Qualifications</strong></p><ul><li>Knowledge of federal cybersecurity mandates (e.g., M-21-31, NIST CSF, CISA Playbooks, BOD 22-01).</li><li>Experience with Microsoft Logic Apps, Azure Functions, or other SOAR platforms.</li><li>Familiarity with UEBA configuration and anomaly detection.</li><li>Exposure to AI/ML frameworks for cyber analytics.</li><li>Experience building SOC metrics, dashboards, and operational reports.</li><li>Familiarity with M365, Azure security tools, ServiceNow, and CISA CDM tools.</li><li>Relevant certifications such as CISSP, CISM, SC-200, or AZ-500.</li></ul>
<h3 class="rh-display-3--rich-text">Technology Doesn't Change the World, People Do.<sup>®</sup></h3>
<p>Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.</p>
<p>Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. <a href="https://www.roberthalf.com/us/en/mobile-app" target="_blank">Download the Robert Half app</a> and get 1-tap apply, notifications of AI-matched jobs, and much more.</p>
<p>All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit <a href="https://roberthalf.gobenefits.net/" target="_blank">roberthalf.gobenefits.net</a> for more information.</p>
<p>© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to <a href="https://www.roberthalf.com/us/en/terms">Robert Half’s Terms of Use</a>.</p>
- Washington Dc, DC
- onsite
- Temporary
-
50.00 - 55.00 USD / Hourly
- <p><strong>SOC Engineer</strong></p><p><strong>Location</strong>: Washington DC</p><p><strong>Clearance: Public Trust (Must be eligible)</strong></p><p><strong>Duration: </strong>6-month Contract to Hire</p><p><br></p><p><strong>Position Overview</strong></p><p>We are seeking a skilled and motivated SOC Engineer to join our cybersecurity operations team. This role is focused on engineering data feed solutions for the Security Operations Center (SOC), implementing SOAR capabilities, and ensuring the health and performance of data integrations through collaboration across technical teams.</p><p>The ideal candidate will bring deep cybersecurity expertise, particularly in network security, SIEM/SOAR platforms, incident response, and threat detection. This position also serves as the backup SOC Lead, stepping in to manage operations, escalations, and leadership communications during critical incidents when the primary lead is unavailable.</p><p><strong>Key Responsibilities</strong></p><ul><li>Microsoft Sentinel Engineering: Maintain and optimize Microsoft Sentinel SIEM/SOAR solutions in accordance with client needs and federal compliance standards.</li><li>Data Integration: Configure and manage log/data feeds from various sources including Fluent Bit, Windows Events, M365, cloud services, and endpoint/security platforms.</li><li>Parsing & Normalization: Develop and refine log parsing rules using Regex, DCRs, and custom transformations to ensure accurate data ingestion.</li><li>SOAR Development: Build automation and orchestration workflows using Microsoft Logic Apps, Azure Functions, and PowerShell/Python scripting.</li><li>Threat Detection Engineering: Design and tune analytic rules, UEBA, dashboards, and reports to enhance threat detection and response capabilities.</li><li>Cross-Team Collaboration: Work closely with network, endpoint, cloud, and IT operations teams to onboard new data sources and improve SOC functionality.</li><li>Documentation & Training: Create and maintain documentation for SOC architecture, onboarding processes, and automation playbooks; train SOC analysts on new tools and procedures.</li><li>Process Improvement: Conduct gap analyses and recommend enhancements to SOC capabilities and maturity.</li><li>Incident Response Support: Provide Tier 3 support and assist in complex investigations as needed.</li></ul>
- 2025-09-05T14:24:22Z