SOC Engineer in McLean, Virginia at Merlin International Inc
Explore Related Opportunities
Job Description
About Merlin Group
Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions.
At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact.
The Opportunity
We are looking for a SOC Engineer to build, operate, and improve the technical capabilities behind our security operations. While the role is primarily focused on security automation and platform engineering, detection engineering will play a large part as well. You will partner closely with SOC analysts to turn their needs into reliable detections, workflows, and infrastructure, and work with the SOC Manager, Engineering, Infrastructure, and GRC teams to keep the platform secure, compliant, and scalable.
Primary Duties & Responsibilities
- Design, build, and tune detections in Splunk using SPL, mapping coverage to knowledge bases like MITRE ATT&CK and managing rules through the team's detection-as-code process with version control, testing, and peer review, while tracking false positive rates, alert volume, and coverage gaps with analysts to prioritize tuning and new content
- Onboard, normalize, and maintain log sources and collection pipelines across AWS, Azure, and GCP, including CloudTrail, GuardDuty, Azure Activity and Entra ID logs, GCP Cloud Audit Logs, and endpoint, identity, and network telemetry, with forwarders, ingestion, retention, and integrity controls that satisfy FedRAMP audit logging requirements
- Build and maintain Torq workflows for alert enrichment, triage, containment, and case handling, integrating with Splunk, ServiceNow, cloud provider APIs, and other SOC tools so alerts arrive as enriched ServiceNow cases with consistent fields, ownership, and SLAs, reducing analyst toil and mean time to respond
- Engineer and operate the SOC tooling platform in AWS, including Infrastructure as Code (IaC), deployment pipelines, IAM, secrets management, and monitoring systems
- Produce and maintain documentation, runbooks, and architecture diagrams for detections, automation playbooks, and platform components, and supply evidence for audits and control assessments
- Serve as an engineering escalation point during incidents and participate in an on-call rotation for SOC platform issues
Qualifications
- 4+ years of experience in SOC engineering, detection engineering, security engineering, or a closely related role
- Deep hands-on experience with Splunk, including SPL, correlation searches, data models and CIM, knowledge object management, index and sourcetype design, and Splunk Enterprise Security
- Experience building automation with a Security Orchestration, Automation, and Response (SOAR) platform (Torq strongly preferred) and integrating tools through REST APIs and webhooks
- Proficiency in at least one scripting language, and comfort with Git-based workflows and CI/CD pipelines
- Working knowledge of AWS services relevant to security operations (IAM, CloudTrail, GuardDuty, Security Hub, Lambda, S3, VPC) and IaC tooling such as Terraform
- Experience working with an IT Service Management (ITSM) platform (ServiceNow preferred)
Preferred Qualifications
- Experience supporting FedRAMP Moderate or High environments or other NIST 800-53 based programs
- Experience with detection-as-code frameworks and CI/CD for security content, such as Sigma
- Experience configuring or integrating the ServiceNow Security Incident Response module
- Prior work in a managed security services or multi-tenant SOC environment
Success Attributes
- Commitment to personal and professional integrity and respect for others.
- Roll-up-your-sleeves attitude and low-ego approach.
- Commitment to teamwork and professional relationship development.
- Passion for lifelong learning, growth, and development.
- Flexible and nimble; comfortable with ambiguity and rapid change.
- Strong communication and functional project management skills.
- Desire to innovate, try new things, and creatively explore novel solutions to business challenges.
- Professional and respectful approach to the diversity of thought, action, identity, and attributes.
Benefits & Perks
We want to empower and inspire employees to be and do their best. Our workdays are dynamic, collegial, and fun. Our office features multiple places to work unconstrained by typical office barriers. Our wellness package provides access to an on-site gym and includes medical, dental, and vision insurance along with options for FSA and EAP. We offer 401(k) with employer match, unlimited PTO, and a culture respectful of the reality that not everything in one’s personal life is guaranteed to happen only after hours.
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran, or any other status protected by applicable federal, state, local, or international law.