SOC Engineer

Merlin International Inc•Mclean, VA
•Onsite

About The Position

Merlin Group operates at the intersection of cyber innovation, national security, and technology-driven transformation. With a mission to accelerate the adoption of high-impact technologies across the U.S. public sector and regulated commercial markets, Merlin is uniquely structured around three core tenets – Invest, Enable, and Scale – each designed to address a specific stage of the technology lifecycle. Together, our affiliates – Merlin Ventures, CGC, and Merlin Cyber – form a flywheel that builds enduring capability for customers, partners, and the broader cyber ecosystem, operationalizing technological advancement into mission-ready, enterprise-grade solutions. At Merlin, we believe our strength lies in our people. Team members are encouraged to be creative, collaborative, and nimble, pursuing paths to deliver the cutting-edge cybersecurity solutions that our customers rely on. From next-generation cyber defense to secure cloud and AI, we are united by one purpose – transforming innovation into mission impact. We are looking for a SOC Engineer to build, operate, and improve the technical capabilities behind our security operations. While the role is primarily focused on security automation and platform engineering, detection engineering will play a large part as well. You will partner closely with SOC analysts to turn their needs into reliable detections, workflows, and infrastructure, and work with the SOC Manager, Engineering, Infrastructure, and GRC teams to keep the platform secure, compliant, and scalable.

Requirements

  • 4+ years of experience in SOC engineering, detection engineering, security engineering, or a closely related role
  • Deep hands-on experience with Splunk, including SPL, correlation searches, data models and CIM, knowledge object management, index and sourcetype design, and Splunk Enterprise Security
  • Experience building automation with a Security Orchestration, Automation, and Response (SOAR) platform (Torq strongly preferred) and integrating tools through REST APIs and webhooks
  • Proficiency in at least one scripting language, and comfort with Git-based workflows and CI/CD pipelines
  • Working knowledge of AWS services relevant to security operations (IAM, CloudTrail, GuardDuty, Security Hub, Lambda, S3, VPC) and IaC tooling such as Terraform
  • Experience working with an IT Service Management (ITSM) platform (ServiceNow preferred)

Nice To Haves

  • Experience supporting FedRAMP Moderate or High environments or other NIST 800-53 based programs
  • Experience with detection-as-code frameworks and CI/CD for security content, such as Sigma
  • Experience configuring or integrating the ServiceNow Security Incident Response module
  • Prior work in a managed security services or multi-tenant SOC environment

Responsibilities

  • Design, build, and tune detections in Splunk using SPL, mapping coverage to knowledge bases like MITRE ATT&CK and managing rules through the team's detection-as-code process with version control, testing, and peer review, while tracking false positive rates, alert volume, and coverage gaps with analysts to prioritize tuning and new content
  • Onboard, normalize, and maintain log sources and collection pipelines across AWS, Azure, and GCP, including CloudTrail, GuardDuty, Azure Activity and Entra ID logs, GCP Cloud Audit Logs, and endpoint, identity, and network telemetry, with forwarders, ingestion, retention, and integrity controls that satisfy FedRAMP audit logging requirements
  • Build and maintain Torq workflows for alert enrichment, triage, containment, and case handling, integrating with Splunk, ServiceNow, cloud provider APIs, and other SOC tools so alerts arrive as enriched ServiceNow cases with consistent fields, ownership, and SLAs, reducing analyst toil and mean time to respond
  • Engineer and operate the SOC tooling platform in AWS, including Infrastructure as Code (IaC), deployment pipelines, IAM, secrets management, and monitoring systems
  • Produce and maintain documentation, runbooks, and architecture diagrams for detections, automation playbooks, and platform components, and supply evidence for audits and control assessments
  • Serve as an engineering escalation point during incidents and participate in an on-call rotation for SOC platform issues

Benefits

  • medical, dental, and vision insurance
  • FSA
  • EAP
  • 401(k) with employer match
  • unlimited PTO
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service