... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
Signals & Defense Engineer, Junior
Mclean, VA · On-site
$55K - $126K/yr
Develop scripts and automation to improve SOC efficiency and reduce manual processes. * Participate ... Document engineering processes, detection logic, and technical solutions. Join us. The world can't ...
Signals & Defense Engineer, Junior
Mclean, VA · On-site
$55K - $126K/yr
Develop scripts and automation to improve SOC efficiency and reduce manual processes. * Participate ... Document engineering processes, detection logic, and technical solutions. Join us. The world can't ...
Signals & Defense Engineer, Junior
Mclean, VA · On-site
$55K - $126K/yr
Develop scripts and automation to improve SOC efficiency and reduce manual processes. * Participate ... Document engineering processes, detection logic, and technical solutions. Join us. The world can't ...
Signals & Defense Engineer, Junior
Mclean, VA · On-site
$55K - $126K/yr
Develop scripts and automation to improve SOC efficiency and reduce manual processes. * Participate ... Document engineering processes, detection logic, and technical solutions. Join us. The world can't ...
... automation processes. • Support Security Operations Center (SOC) missions through advanced log analytics, SIEM engineering, and detection content development. • Support Incident Response (IR ...
... automation processes. • Support Security Operations Center (SOC) missions through advanced log analytics, SIEM engineering, and detection content development. • Support Incident Response (IR ...
SRE - Linux
Reston, VA · On-site +1
$135K - $183K/yr
The SRE is part of a highly skilled engineering and infrastructure team responsible for the design ... SOC and SOX controls Design and implement automation to improve system reliability, scalability ...
SRE - Linux
Reston, VA · On-site +1
$135K - $183K/yr
The SRE is part of a highly skilled engineering and infrastructure team responsible for the design ... SOC and SOX controls Design and implement automation to improve system reliability, scalability ...
TS SCI w/ CI Poly Cleared SOC Analyst with Security Clearance
Reston, VA · On-site
$67.50 - $97.50/hr
... similar automation tools • Experience supporting federal, DoD, or Intelligence Community ... detection engineering, use case tuning, or reducing false positives • DoD 8570 IAT Level II ...
TS SCI w/ CI Poly Cleared SOC Analyst with Security Clearance
Reston, VA · On-site
$67.50 - $97.50/hr
... similar automation tools • Experience supporting federal, DoD, or Intelligence Community ... detection engineering, use case tuning, or reducing false positives • DoD 8570 IAT Level II ...
SRE - Linux
Reston, VA · On-site
$135K - $183K/yr
The SRE is part of a highly skilled engineering and infrastructure team responsible for the design ... SOC and SOX controls * Design and implement automation to improve system reliability, scalability ...
SRE - Linux
Reston, VA · On-site
$135K - $183K/yr
The SRE is part of a highly skilled engineering and infrastructure team responsible for the design ... SOC and SOX controls * Design and implement automation to improve system reliability, scalability ...
Cybersecurity AI/ML Engineer
Mclean, VA · On-site +1
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
Cybersecurity AI/ML Engineer
Mclean, VA · On-site +1
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
Cybersecurity AI/ML Engineer
Mclean, VA · On-site +1
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
Cybersecurity AI/ML Engineer
Mclean, VA · On-site +1
... triage automation, LLM and agentic analyst tooling, and SOC platform integrations while guiding teams through MLSecOps, secure-AI engineering, and responsible AI practices. Perform code and ...
Collaborate with NOC and SOC analysts to define KPIs and ensure accurate visibility into network ... Integrate Splunk with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms ...
Collaborate with NOC and SOC analysts to define KPIs and ensure accurate visibility into network ... Integrate Splunk with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms ...
Collaborate with NOC and SOC analysts to define KPIs and ensure accurate visibility into network ... Integrate Splunk with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms ...
Collaborate with NOC and SOC analysts to define KPIs and ensure accurate visibility into network ... Integrate Splunk with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms ...
SOC Analyst
Mclean, VA · On-site
Collaborate with IT, Cloud, and DevOps teams to support security best practices. Participate in ... Exposure to scripting or automation (e.g., Python, Bash). * Familiarity with threat intelligence ...
SOC Analyst
Mclean, VA · On-site
Collaborate with IT, Cloud, and DevOps teams to support security best practices. Participate in ... Exposure to scripting or automation (e.g., Python, Bash). * Familiarity with threat intelligence ...
SOC Analyst with Security Clearance
Alexandria, VA · On-site
$65 - $75/hr
... Automation and Response (SOAR), Endpoint and Network Detection and Response (EDR/NDR) and User ... queries in Splunk Programming Language (SPL). • • Education: • Bachelors • Required ...
SOC Analyst with Security Clearance
Alexandria, VA · On-site
$65 - $75/hr
... Automation and Response (SOAR), Endpoint and Network Detection and Response (EDR/NDR) and User ... queries in Splunk Programming Language (SPL). • • Education: • Bachelors • Required ...
Splunk Engineer
Herndon, VA · On-site
... NOC and SOC operations. • Onboard new data sources including network appliances, servers ... with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms) for improved ...
Splunk Engineer
Herndon, VA · On-site
... NOC and SOC operations. • Onboard new data sources including network appliances, servers ... with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms) for improved ...
Splunk Engineer
Herndon, VA · On-site
... NOC and SOC operations. • Onboard new data sources including network appliances, servers ... with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms) for improved ...
Splunk Engineer
Herndon, VA · On-site
... NOC and SOC operations. • Onboard new data sources including network appliances, servers ... with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms) for improved ...
... automation. The SOC Engineer III will collaborate with cybersecurity teams, system administrators, network engineers, and organizational leadership to strengthen the organization's security posture ...
Quick apply
... automation. The SOC Engineer III will collaborate with cybersecurity teams, system administrators, network engineers, and organizational leadership to strengthen the organization's security posture ...
... automation. The SOC Engineer III will collaborate with cybersecurity teams, system administrators, network engineers, and organizational leadership to strengthen the organization's security posture ...
... automation. The SOC Engineer III will collaborate with cybersecurity teams, system administrators, network engineers, and organizational leadership to strengthen the organization's security posture ...
Splunk Engineer
Herndon, VA · On-site
$112K - $179K/yr
Collaborate with NOC and SOC analysts to define KPIs and ensure accurate visibility into network ... Integrate Splunk with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms ...
Splunk Engineer
Herndon, VA · On-site
$112K - $179K/yr
Collaborate with NOC and SOC analysts to define KPIs and ensure accurate visibility into network ... Integrate Splunk with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms ...
... automation. The SOC Engineer III will collaborate with cybersecurity teams, system administrators, network engineers, and organizational leadership to strengthen the organization's security posture ...
... automation. The SOC Engineer III will collaborate with cybersecurity teams, system administrators, network engineers, and organizational leadership to strengthen the organization's security posture ...
Soc Automation Engineer information
What are the key skills and qualifications needed to thrive as a SoC automation engineer, and why are they important?
What is the difference between Soc Automation Engineer vs Security Analyst?
| Aspect | Soc Automation Engineer | Security Analyst |
|---|---|---|
| Credentials | Certifications like CISSP, CISA, or vendor-specific automation tools | Certifications like CompTIA Security+, CISSP, or GIAC certifications |
| Work Environment | Focus on developing and maintaining security automation tools within security operations centers | Monitoring, analyzing, and responding to security incidents and threats |
| Employer & Industry | Typically employed by large enterprises, security service providers, or cybersecurity firms | Commonly employed across various industries including finance, healthcare, and government |
While both roles are vital in cybersecurity, Soc Automation Engineers focus on automating security processes to improve efficiency, whereas Security Analysts primarily analyze and respond to security threats. Understanding these differences helps organizations assign the right skills to each role.
What is a SoC automation engineer?
What are some common challenges faced by SoC automation engineers during silicon validation and how can they be addressed?
Other
Medical, Life, Retirement, PTO
Re-posted 8 days ago
Booz Allen Hamilton rating
8.9
Based on 49 frontline employees who took The Breakroom Quiz
9th of 72 rated business consultants
Job description
* Engineer scalable batch and streaming data and feature pipelines over security telemetry including logs, EDR, network, identity, cloud, and threat intel with online and offline parity, feature stores, schema and contract management, and reproducible datasets that power detection, triage, and hunting use cases.
* Build, harden, and operate ML platforms and inference services, including low-latency real-time scoring, batch inference, model packaging and containerization, autoscaling, canary and shadow deployments, observability, and rollback, to meet SOC throughput, latency, and reliability SLOs.
* Apply secure-AI and MLSecOps engineering practices throughout the AI/ML lifecycle, including model and data protection, prompt and inference risk mitigation, evaluation against adversarial inputs such as evasion, poisoning, and prompt injection, model and dataset supply chain security, and responsible AI controls.
* Integrate ML services and analytics into security tools and workflows such as SIEM, SOAR, EDR, IAM, or CSPM via APIs and event-driven architectures extending detection logic, enrichment, and response playbooks with custom ML/LLM capabilities where commercial tooling falls short.
* Develop automation, scripting, and infrastructure-as-code (IaC) to enable repeatable, testable, and version-controlled ML pipelines, model deployments, and security data integrations across cloud and on-prem environments.
* Collaborate across data science, platform, data, threat intelligence, and SOC operations teams to deliver end-to-end solutions, embed ML practices into DevSecOps and MLSecOps pipelines, and drive implementation through measurable operational outcomes. Join us. The world can't wait. You Have: * 3+ years of experience in machine learning engineering, software engineering for ML, or applied AI platform development
* Experience building and operating production ML systems including cybersecurity or security operations
* Experience developing, testing, and integrating ML services across security tools and platforms using APIs, automation, and workflow orchestration and applying AI and machine learning to cybersecurity use cases such as threat and anomaly detection, behavioral analytics, alert triage and prioritization, threat hunting support, analyst copilots, and response automation with measurable impact on SOC outcomes
* Experience software engineering in Python for ML and security use cases, including production-quality code, design patterns, unit and integration testing, packaging, version control, CI/CD, Docker containerization, and container orchestration including Kubernetes
* Experience working with the modern AI/ML stack, including PyTorch or TensorFlow, scikit-learn, Hugging Face, LangChain/LlamaIndex, agent frameworks, model serving frameworks, KServe, BentoML, Triton, Ray Serve, embedding-based retrieval, and vector databases such as pgvector, OpenSearch, Pinecone, and Milvus
* Experience operationalizing AI/ML systems or MLOps, model versioning, experiment tracking, feature stores, evaluation harnesses, drift and quality monitoring, and CI/CD for models such as MLflow, Weights & Biases, SageMaker, Vertex AI, Azure ML, and Kubeflow
* Knowledge of secure AI implementation practices and frameworks including model and data protection, prompt and inference risk, agent guardrails, evaluation against adversarial inputs, ML supply chain security, and governance controls aligned to NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
* Knowledge of modern cybersecurity threats and attack patterns, including ransomware, insider threats, credential abuse, data exfiltration, and AI-enabled attack techniques such as prompt injection, model evasion, data poisoning, and model theft
* Ability to obtain a Secret clearance
* Bachelor's degree Nice If You Have: * Experience with programming or scripting languages used in ML, security, and automation environments such as Python, Go, Rust, SQL, PowerShell, and Bash
* Experience designing, deploying, and maintaining enterprise-scale ML and security systems for sensitive or regulated environments including FedRAMP, IL4, IL5, HIPAA, and PCI
* Experience designing and building agentic AI systems for security operations, multi-step reasoning, tool and function calling, retrieval pipelines, and human-in-the-loop workflows
* Experience fine-tuning, distilling, quantizing, or serving LLMs and other models for domain-specific security tasks, including automated eval harnesses and red-teaming AI systems
* Experience evaluating and integrating AI-enabled cybersecurity tooling such as AI-assisted SIEM, SOAR, UEBA, behavioral analytics, model-driven detection workflows into enterprise security operations via APIs and event-driven architectures
* Experience designing and implementing AI/ML services and pipelines over enterprise security telemetry spanning network, endpoint, application, identity, and cloud environments
* Knowledge of AI governance, model risk management, and policy controls aligned to enterprise and regulatory expectations for responsible AI use
* Knowledge of data governance frameworks, data classification standards, and privacy regulations such as GDPR and CCPA
* Knowledge of distributed data and streaming platforms, including Kafka, Kinesis, Spark, and Flink, database structures, data modeling fundamentals, and query optimization, including SQL and NoSQL
* IT Engineering, ML, or Security Certifications such as AWS, GCP, Azure ML Engineer, CKAD, CKA, CISSP, CCSP, CDPSE, cloud security Certifications, or AI security Certifications such as ISC2 CAISS or IAPP AIGP Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information . Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $77,600.00 to $176,000.00 (annualized USD). The estimate displayed represents the typical salary range for this posi
What Booz Allen Hamilton employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Booz Allen Hamilton
Sourced by ZipRecruiter
Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.
Industry
It services
Company size
10,000+ Employees
Headquarters location
McLean, VA, US
Year founded
1914