
Senior Security Operations Center Engineer - Security Tooling
Job Description
Everforth ECS is seeking a Senior Security Operations Center Engineer - Security Tooling to work in the National Capital Region covering the Pentagon, Falls Church, and Fairfax. Please Note: This position is contingent upon contract award.
The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP separates business and financial data from operational warfighting data, aiming to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.
The Senior Security Operations Center Engineer – Security Tooling serves as a senior-level cyber defense engineer responsible for the design, integration, and sustained operation of enterprise security tooling supporting WDP's cybersecurity posture across all classification tiers. This role bridges SOC operations and engineering disciplines to deliver scalable, automation-driven detection and response capabilities in direct support of WDP mission assurance and information advantage objectives.
• Provides advanced engineering support for enterprise cyber defense operations by designing, integrating, and sustaining security operations tooling across classified and unclassified environments.
• Architects, configures, and optimizes Security Information and Event Management platforms such as Splunk and Elastic to ingest, normalize, and correlate high-volume log data from network, endpoint, cloud, and application sources.
• Engineers security orchestration and automation workflows using SOAR platforms to accelerate detection, triage, containment, and response actions in alignment with Cyber Incident Handling Program guidance.
• Develops and tunes correlation rules, analytics queries, and threat detection logic to improve signal fidelity, reduce false positives, and increase adversary visibility.
• Integrates threat intelligence feeds, endpoint security platforms, vulnerability scanners, and cloud security tools to enable end-to-end situational awareness.
• Designs and maintains operational dashboards supporting SOC leadership decision-making, incident prioritization, and mission risk visibility.
• Supports continuous monitoring by maintaining tool health, data pipelines, and performance baselines while coordinating maintenance windows and upgrades.
• Collaborates with SOC analysts, incident responders, vulnerability management teams, and system engineers to translate operational requirements into scalable technical solutions.
• Produces automation artifacts, integration documentation, and operational metrics supporting readiness reporting, response efficiency, and sustained cyber defense effectiveness in support of mission assurance and information advantage.
• Performs other duties as assigned.