Sr. Cyber Operations Engineer III (NOC/SOC) (6797)

MetroStarWashington, DC
$180,000 - $220,000

About The Position

As Sr. Cyber Operations Engineer III (NOC/SOC), you’ll help strengthen the reliability and security of complex enterprise environments. You will bring together network operations, security operations, monitoring, automation, and incident response to improve situational awareness and operational resilience. At MetroStar, we are obsessed with our people and have led a two-decade legacy of building the best and brightest teams. Because we know our future relies on our deep understanding and relentless focus on our people, we live by our mission: A passion for our people. Value for our customers.

Requirements

  • Active Top Secret security clearance.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline.
  • 10+ years of experience in network operations, cybersecurity operations, infrastructure operations, systems engineering, or related technical roles.
  • 5+ years of experience supporting enterprise NOC, SOC, or integrated network/security operations environments.
  • Strong experience with Microsoft Sentinel, Microsoft Defender, Azure Monitor, Log Analytics, or comparable SIEM, security monitoring, and observability technologies.
  • Hands-on experience with network monitoring, SIEM, EDR/XDR, vulnerability management, incident management, and enterprise observability platforms.
  • Strong understanding of TCP/IP, DNS, routing, firewalls, VPNs, load balancing, network segmentation, and enterprise network architectures.
  • Experience monitoring and troubleshooting Microsoft Azure, hybrid cloud, on-premises infrastructure, networks, applications, and security services.
  • Experience developing detection rules, dashboards, alerts, automated response workflows, operational runbooks, and incident response playbooks.
  • Proficiency with PowerShell, Python, Kusto Query Language (KQL), or similar scripting/query languages used for operations and security automation.
  • Experience supporting large enterprise, public sector, or regulated environments and familiarity with NIST RMF, applicable security baselines, compliance requirements, and incident reporting processes.
  • CISSP, CySA+, GIAC, Microsoft Security, Azure, or equivalent certifications
  • Strong troubleshooting, analytical, communication, and incident management skills with the ability to operate effectively during high-priority operational or cybersecurity events.

Responsibilities

  • Support the design, implementation, and continuous improvement of integrated Network Operations Center (NOC) and Security Operations Center (SOC) capabilities that provide centralized visibility into enterprise infrastructure, networks, cloud environments, endpoints, applications, and cybersecurity events.
  • Implement and optimize enterprise monitoring using Microsoft Sentinel, Azure Monitor, Log Analytics, Microsoft Defender, and other network and security monitoring platforms to provide real-time visibility into system health, availability, performance, and security.
  • Develop and tune security monitoring, correlation rules, alerts, dashboards, and threat detection capabilities to identify suspicious activity, vulnerabilities, indicators of compromise, and potential cybersecurity incidents.
  • Monitor enterprise network availability, connectivity, utilization, latency, and performance while identifying and resolving issues affecting critical systems and services.
  • Lead technical investigation, triage, escalation, coordination, and resolution of network, infrastructure, cloud, and cybersecurity incidents while ensuring incidents are appropriately documented and communicated.
  • Configure and optimize Security Information and Event Management (SIEM), endpoint detection and response (EDR), network monitoring, vulnerability management, and security analytics platforms to improve operational awareness and threat detection.
  • Develop automated workflows, scripts, playbooks, and Security Orchestration, Automation, and Response (SOAR) capabilities using PowerShell, Python, Azure Logic Apps, or similar technologies to accelerate detection, response, remediation, and operational workflows.
  • Develop and maintain NOC/SOC standard operating procedures, incident response playbooks, escalation procedures, operational runbooks, and knowledge management documentation.
  • Develop operational dashboards, KPIs, SLA metrics, incident trends, availability reports, and security metrics to measure NOC/SOC effectiveness and identify opportunities for continuous improvement.
  • Work closely with client stakeholders, cybersecurity teams, network engineers, cloud engineers, system administrators, application teams, and leadership to maintain enterprise situational awareness and rapidly resolve operational and security issues.

Benefits

  • Health, dental, and vision insurance
  • 401(k) retirement plan with company match
  • Paid time off (PTO) and holidays
  • Parental Leave and dependent care
  • Flexible work arrangements
  • Professional development opportunities
  • Employee assistance and wellness programs
  • Performance-based bonuses
  • Company-paid training and/or certifications
  • Referral bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service