Security Operations Center Engineer
Unisys
📍 Rockville, Maryland, US0💼 Full-time🕐 5/29/2026
Apply now →Start your Pro trial in 30 seconds (3 days free): you also get the AI match score with your resume.
Role overview
Unisys is hiring for the Security Operations Center Engineer role in Rockville, Maryland, US. It is full-time, Mid-level level, in the Tech sector. It was posted 5/29/2026.
On TalentyGo you can review this job and apply more effectively: Charlie prepares an ATS-optimized resume and a cover letter tailored to "Security Operations Center Engineer" at Unisys in about a minute. Before you apply, you can also check how well your profile fits, with a match score based on skills, experience, location and seniority.
- Role
- Security Operations Center Engineer
- Company
- Unisys
- Location
- Rockville, Maryland, US
- Work mode
- On-site
- Employment
- Full-time
- Seniority
- Mid-level
- Sector
- Tech
- Posted
- 5/29/2026
Description
About the Role
Our Security Operations Center is evolving from foundational capabilities into a mature, comprehensive security operations program. We need an experienced SOC engineer who has been part of a top-tier SOC and can provide technical vision and leadership to guide our detection engineering and automation efforts.
This role focuses on building robust detection capabilities, automating security responses, and creating the frameworks that enable our SOC analysts to effectively identify and respond to threats. You will work closely with our threat intelligence and hunting teams to translate security research into actionable detections and automated responses.
Key Responsibilities
Detection Engineering:
Design and implement comprehensive detection use cases aligned with the MITRE ATT&CK framework
Conduct gap analysis of current detection coverage and develop roadmap to address gaps
Build and tune correlation searches, alerts, and detection logic in Splunk Enterprise Security
Implement Risk-Based Alerting (RBA) methodologies to improve signal-to-noise ratio
Develop detection strategies for multi-cloud environments (AWS, GCP, Azure)
Continuously evaluate and improve detection effectiveness based on SOC feedback
Security Automation & Orchestration
Design and implement automated response playbooks using Splunk SOAR
Build integrations between security tools to enable automated investigation and response workflows
Develop scripts and automation (Python, Bash, PowerShell) to streamline SOC operations
Create reusable automation frameworks that scale across multiple use cases
Collaborate with platform engineering to ensure reliable automation infrastructure
SOC Architecture & Vision:
Define what a mature SOC capability looks like using Splunk ES, SOAR, and supporting tools
Identify gaps and shortcomings in current SOC implementation and provide clear remediation guidance
Establish best practices, standards, and frameworks for detection engineering and response
Mentor platform engineering team on SOC-specific requirements and approaches
Contribute to long-term SOC strategy and capability development
Cross-Functional Collaboration:
Partner with threat intelligence and threat hunting teams to operationalize research into detections
Work with SOC analysts to understand investigation workflows and improve detection quality
Collaborate with platform engineering teams to implement and maintain SOC infrastructure
Participate in incident response activities to validate and refine detection and automation capabilities
Document detection logic, playbooks, and technical architectures
Required Qualifications:
SOC Experience: 5+ years in a Security Operations Center environment with exposure to mature SOC operations and best practices
SIEM Expertise: Hands-on experience with Splunk Enterprise Security or comparable enterprise SIEM platforms (building correlation searches, alerts, dashboards, and ES-specific frameworks)
Detection Engineering: Proven experience developing security detections, use cases, and alert tuning methodologies
MITRE ATT&CK Framework: Practical application of MITRE ATT&CK for detection coverage mapping and gap analysis
Security Automation: Experience building automated response workflows and playbooks (SOAR platforms preferred)
Scripting: Strong proficiency in Python, PowerShell, or Bash for automation and integration development
Cloud Security: Understanding of cloud security monitoring and detection across AWS, GCP, and Azure environments
Analytical Mindset: Ability to identify gaps, define clear vision for improvement, and guide teams toward maturity
Preferred Qualifications:
Splunk SOAR (Phantom) hands-on experience
Splunk UEBA or behavioral analytics platform experience
Risk-Based Alerting (RBA) implementation experience
Threat hunting background with detection engineering application
Infrastructure automation and CI/CD pipeline knowledge
Experience mentoring or leading detection engineering teams
Relevant certifications (GIAC, CISSP, or similar)
# LI-CGTS
# TS-2505
The market for this role in Rockville
TalentyGo lists 6864 similar roles (26 in Rockville), 21% remote. Charlie ranks them against your CV, each with a clear score.
Similar jobs
Manager, Engineering
📍 United States · tech
ANALYST
📍 New York · finance
Senior Security Analyst
📍 Dallas · finance
Design Control Engineer
📍 Warsaw · tech
Director, Operations
📍 Peterborough · consulting
Business Operations & Finance Administrator
📍 Kemah · finance
TalentyGo is an aggregator of job postings from public sources. Always verify information directly with the company. Applications go through the original company website; TalentyGo does not manage hiring processes.