Cybersecurity Operations Center Engineer

TX-HHSC-DSHS-DFPSAustin, TX
$7,015 - $11,865Onsite

About The Position

This position is open to U.S. Citizens and permanent residents. This onsite role requires the selected candidate to work from an HHS office in Austin, Texas. The Cybersecurity Analyst III performs senior-level cybersecurity engineering work with emphasis on security operations engineering, security platform administration, detection engineering, automation, orchestration, and cybersecurity infrastructure integration. The role supports agency on-premises and cloud environments by designing, implementing, maintaining, and enhancing security technologies used to protect agency systems, applications, hosts, networks, cloud services, and data. The Cybersecurity Analyst III also participates in incident response as needed. The Cybersecurity Operations Center (CSOC) Engineer is responsible for engineering and maintaining the technical capabilities that enable enterprise security monitoring, threat detection, incident response, threat hunting, and cybersecurity operations. This position provides senior-level expertise in SIEM engineering, security orchestration and automation, cloud security integrations, endpoint security platforms, security monitoring architecture, and detection development. The CSOC Engineer develops and maintains enterprise security monitoring infrastructure, enhances agency cybersecurity visibility, and implements technical solutions that improve the efficiency and effectiveness of security operations. This position serves as a critical technical resource responsible for ensuring security platforms generate reliable, actionable, and meaningful intelligence for cybersecurity analysts, engineers, and leadership. This position performs highly complex information security and cybersecurity engineering work. The Engineer works under limited supervision with considerable latitude for the use of initiative and independent judgment. The Engineer will research, evaluate, implement, and optimize new security technologies, detection methodologies, automation capabilities, integrations, and operational solutions used to prevent, detect, contain, and respond to cybersecurity threats. The Engineer provides expert guidance regarding cybersecurity technologies, monitoring architectures, logging standards, data onboarding strategies, security automation opportunities, and defensive engineering practices. This role partners closely with Cybersecurity Operations, Threat Hunting, Incident Response, Security Architecture, Infrastructure Services, Cloud Operations, and Application Development teams to strengthen the agency's cybersecurity posture. The Engineer also serves as a member of the Incident Response team.

Requirements

  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another.
  • At least 5+ years of experience in information technology, cybersecurity engineering, SIEM administration, security operations, detection engineering, systems/network administration, or related disciplines.
  • Experience working in a Security Operations Center (SOC).
  • Experience with one or more SIEM platforms.
  • Experience with security operations automation.
  • Knowledge of Security Operations Center architecture, processes, and cybersecurity monitoring methodologies.
  • Knowledge of SIEM, SOAR, EDR/XDR, NDR, IPS/IDS, NGFW, threat intelligence, cloud security, identity security, and vulnerability management technologies.
  • Knowledge of enterprise logging, event collection, correlation, and security analytics principles.
  • Knowledge of automation technologies, scripting methodologies, APIs, and systems integration practices.
  • Knowledge of cloud computing architectures, identity and access management, networking, operating systems, and enterprise security controls.
  • Knowledge of MITRE ATT&CK framework, cybersecurity threat landscapes, adversary behaviors, and defensive engineering concepts.
  • Knowledge of security frameworks and standards including NIST Cybersecurity Framework, NIST 800-53, CIS Controls, and State of Texas cybersecurity requirements (including TAC Chapter 202).
  • Skill in security platform administration and configuration.
  • Skill in detection engineering and security content development.
  • Skill in scripting, automation, and systems integration.
  • Skill in data analysis, event correlation, and security analytics.
  • Skill in troubleshooting complex cybersecurity technologies and integrations.
  • Skill in writing technical documentation, engineering procedures, and operational standards.
  • Skill in evaluating cybersecurity technologies and developing technical recommendations.
  • Ability to design, implement, and maintain enterprise cybersecurity monitoring capabilities.
  • Ability to process large security data sets to support incident response and SOC operations.
  • Ability to analyze complex technical environments and identify engineering improvements.
  • Ability to develop scalable and maintainable security engineering solutions.
  • Ability to communicate technical information to both technical and non-technical audiences.
  • Ability to work collaboratively across multiple teams and disciplines.
  • Ability to manage multiple projects, priorities, and engineering initiatives simultaneously.

Nice To Haves

  • Certified Information Systems Security Professional (CISSP)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • GIAC Continuous Monitoring Certification (GMON)
  • GIAC Certified Detection Analyst (GCDA)
  • GIAC Certified Enterprise Defender (GCED)
  • Splunk Enterprise Security Certified Admin
  • Splunk Core Certified Power User
  • CompTIA CySA+

Responsibilities

  • Administers, maintains, and optimizes enterprise cybersecurity technologies supporting security monitoring and incident response operations.
  • Designs, implements, and supports Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR/XDR), SOAR, threat intelligence, identity protection, cloud security, email security, network security, and vulnerability management platforms.
  • Manages platform configurations, data ingestion pipelines, integrations, scalability, availability, and operational health.
  • Develops and maintains logging standards, monitoring requirements, and telemetry collection strategies across enterprise environments.
  • Performs platform upgrades, configuration management, tuning activities, and technology lifecycle maintenance.
  • Designs, develops, and maintains security detections, correlation searches, behavioral analytics, dashboards, reports, and threat-hunting content.
  • Develops automation workflows and orchestration solutions to improve operational efficiency and response capabilities.
  • Creates use cases aligned to MITRE ATT&CK techniques, threat intelligence, and agency risk priorities.
  • Enhances alert quality through tuning, enrichment, suppression logic, and continuous improvement efforts.
  • Develops and maintains detection-as-code and content management processes where applicable.
  • Applies knowledge of scripting to automate repeatable tasks.
  • Integrates enterprise security technologies and data sources into cybersecurity monitoring platforms.
  • Collaborates with infrastructure, cloud, identity, networking, and application teams to onboard new systems and services into enterprise monitoring capabilities.
  • Develops data normalization, enrichment, correlation, and operational reporting solutions.
  • Ensures security event visibility across cloud, endpoint, network, application, middleware, database, and authentication systems.
  • Identifies gaps in telemetry coverage and develops solutions to improve security visibility.
  • Evaluates emerging security technologies and monitoring solutions to improve agency cybersecurity operations capabilities.
  • Participates in architecture reviews, project consultations, and cybersecurity planning efforts.
  • Supports incident response activities by providing subject matter expertise regarding security technologies and platform capabilities.
  • Provides technical guidance and mentorship to analysts, engineers, and project teams.
  • Performs additional cybersecurity engineering activities as assigned, including special projects, proof-of-concept evaluations, process improvements, operational readiness initiatives, audit support, and agency cybersecurity modernization efforts.

Benefits

  • 100% paid employee health insurance for full-time eligible employees
  • A defined benefit pension plan
  • Generous time off benefits
  • Numerous opportunities for career advancement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service