18 xsoar jobs at 11 companies in Washington, DC

1mo
Save
Mark Applied
Hide
Security Operations Center Analyst (SOC)
Arlington, Virginia, United States
OnsiteFull Time
Chenega Corporation
Chenega Corporation: Provides professional government, defense, and facility support services.
2+ YOE2+ years relevant experience; DoD IAT Level II required; DoD Top Secret clearance with SCI eligibility required. Experience with SIEM and tools like FireEye, Wireshark, Splunk, Palo Alto, Nessus; NOSC/24-7 environment knowledge.
FireEye, Wireshark, Net Witness, Palo Alto, Cisco ASA, F5, tcpdump, Snort, Splunk, EMET, Bit9/Carbon Black, Stealth Watch, IronPort, McAfee ePO, Microsoft Defender, XSOAR, Nessus, Extra hop, OpenText NDR, SIEM
3w
Save
Mark Applied
Hide
Endpoint Security Engineer
Alexandria, Virginia, United States
$100k-$110k/yr OnsiteFull Time
Halvik
HalvikNASDAQ: TTEK: Provides technology, analytics, and management consulting to federal agencies.
3+ YOEBachelor's degree, 3+ years administering enterprise endpoint security (SentinelOne), experience with Windows, Microsoft Intune, PowerShell, SIEM/SOAR integrations, and eligibility for Public Trust.
SentinelOne, Microsoft Intune, PowerShell, Microsoft Sentinel, Splunk, IBM QRadar, Cortex XSOAR, Microsoft Entra ID (Azure AD)
1w
Save
Mark Applied
Hide
Specialist Director, Federal Cyber Security Solutions Architect
Washington or McLean
OnsiteFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
8+ YOE8+ years in cybersecurity engineering or solutions architecture, federal consulting preferred. Experience with Zero Trust, NIST/RMF/FedRAMP, cloud security (AWS/Azure/GCP), SIEM/SOAR, ICAM; ability to travel; U.S. Secret clearance required.
NIST SP 800-53, NIST SP 800-207, Risk Management Framework (RMF), Dod Cloud Computing Security Requirements Guide (SRG), Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Splunk, Sentinel, Cortex XSOAR, Okta, CyberArk, Microsoft Entra ID, AWS, Azure, GCP
1mo
Save
Mark Applied
Hide
NCO (National Cybersecurity Operations) Technical Lead
Washington or Leesburg
HybridFull Time
OCH Technologies
OCH Technologies: Provides IT and cybersecurity services for federal government agencies.
15+ YOE5+ MgmtBachelor's in a technical field, 15+ years cybersecurity experience with 5+ years supervisory experience, Public Trust eligibility, security cert (CISSP/CISM/CASP), SIEM/EDR experience, threat intelligence and incident response expertise.
MITRE ATT&CK, Diamond Model, Cyber Kill Chain, SIEM, threat intelligence platforms, EDR, MISP, OpenCTI, Cortex XSOAR, Splunk SOAR, Tines, CrowdStrike Falcon, SentinelOne, Carbon Black, US-CERT, CISA, AI/ML
2w
Save
Mark Applied
Hide
Senior Cyber Infrastructure Engineer & Architect (Security Platforms SME)
Arlington, Virginia, United States
$200k-$275k/yr OnsiteFull Time
VT-ARC
VT-ARC: Provides research, engineering, and analysis for national security.
Hands-on security platform engineering experience (SIEM, EDR/XDR, vulnerability scanning, log/telemetry pipelines), scripting with Python/PowerShell/Bash, ability to operate in TS/SCI environments; U.S. citizenship and active Top Secret/SCI required.
Python, PowerShell, Bash, Splunk Enterprise, Splunk ES, Elastic, Microsoft Sentinel, QRadar, ArcSight, Cribl, Logstash, Kafka, Fluent Bit, syslog-ng, Microsoft Defender, CrowdStrike, SentinelOne, Trellix, Tanium, Carbon Black, Tenable/ACAS, Nessus, SecurityCenter, Qualys, Rapid7, ServiceNow, Jira, Cortex XSOAR, Splunk SOAR, Phantom, Ansible, Terraform, Git, GitLab, Jenkins, PowerShell DSC, Active Directory/LDAP, Windows, Linux
1mo
Save
Mark Applied
Hide
Palo Alto Subject Matter Expert
Springfield or St. Louis
$75k-$158k/yr OnsiteFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
7+ YOEActive TS/SCI clearance, 7+ years administering Palo Alto NGFWs, PCNSE certification, DoD 8140/8570 IAT Level II compliance, Panorama/Prisma/VM experience, networking protocol expertise, bachelor’s degree or equivalent.
Prisma Access, Cortex XSOAR, Panorama, PAN-OS, Prisma SD-WAN, VM-Series, AWS, Azure, GCP, Python, Ansible, Terraform, Palo Alto XML/REST APIs, Cortex XDR, Palo Alto Networks Expedition, F5, Juniper SRX, Cisco FTD, ASA
1mo
Save
Mark Applied
Hide
Security Operations Center Analyst (SOC)
Arlington, Virginia, United States
OnsiteFull Time
Chenega Corporation
Chenega Corporation: Provides professional government, defense, and facility support services.
2+ YOE2+ years relevant experience, DoD IAT Level II required, DoD Top Secret clearance with SCI eligibility required. Bachelor's degree (or equivalent experience) and experience with SOC/SIEM tools.
FireEye, Wireshark, Net Witness, Palo Alto, Cisco ASA, F5, tcpdump, Snort, Splunk, EMET, Bit9/Carbon Black, Stealth Watch, IronPort, McAfee ePO, Microsoft Defender, XSOAR, Nessus, Extra hop, OpenText NDR, SIEM
1mo
Save
Mark Applied
Hide
Security Operations Center Analyst (SOC)
Arlington, Virginia, United States
OnsitePart Time
Chenega Corporation
Chenega Corporation: Provides professional government, defense, and facility support services.
2+ YOE2+ years relevant experience; DoD IAT Level II certification and DoD Top Secret clearance with SCI eligibility required; experience with security tools and NOSC/24/7 operations.
FireEye, Wireshark, Net Witness, Palo Alto, Cisco ASA, F5, tcpdump, Snort, Splunk, EMET, Bit9/Carbon Black, Stealth Watch, IronPort, McAfee ePO, Microsoft Defender, XSOAR, Nessus, ExtraHop, OpenText NDR, SIEM
1w
Save
Mark Applied
Hide
Sr. Principal Threat Intelligence Engineer- Remote or Hybrid in MN or DC
Washington or Minneapolis or United States
$135k-$231k/yr RemoteFull Time
UnitedHealth Group
UnitedHealth GroupNYSE: UNH: Provides health insurance and technology-enabled health care services.
5+ YOE5+ years in threat intelligence, security engineering, IR or malware analysis; strong software engineering for automation, API integration, data pipelines; proficiency with Python and security tooling integrations.
Python, Java, JavaScript/Node.js, Go, REST APIs, JSON, STIX/TAXII, Bash, PowerShell, Git, CI/CD, Linux (Ubuntu, CentOS, RHEL, Kali), AWS, Docker, Windows Server, Active Directory, Mac OS X, LLM, MISP, OpenCTI, ThreatConnect, Anomali, ThreatQuotient, Splunk, Microsoft Sentinel, IBM QRadar, Elastic, Cortex XSOAR, Splunk SOAR, Swimlane, Tines, Kafka, Spark, Elasticsearch, SIEM, SOAR, EDR, NDR
2mo
Save
Mark Applied
Hide
Automation / SOAR Engineer – Senior
Washington, District of Columbia, United States
$150k-$160k/yr HybridFull Time
MKS2 Technologies
MKS2 Technologies: Delivers cybersecurity and IT solutions to government agencies.
5+ YOE5+ years cybersecurity/SOC engineering; 3+ years building security automation/playbooks; experience with SOAR/SIEM integrations; proficiency with Python, PowerShell, Bash, REST APIs; strong analytical and SOC ops knowledge.
Python, PowerShell, Bash, REST APIs, JSON, webhooks, Git, Splunk, Microsoft Sentinel, Elastic, CrowdStrike, Microsoft Defender (MDE), Tenable, Rapid7, ServiceNow, Tanium, Cortex XSOAR, Splunk SOAR, Swimlane, SOAR, SIEM, MITRE ATT&CK, NIST 800-61
2w
Save
Mark Applied
Hide
Program Manager (Ops Center Manager for SOC & NOC)
Springfield, Virginia, United States
$180k-$250k/yr OnsiteFull Time
JFL Consulting
JFL Consulting: Provides cybersecurity and network defense solutions for government agencies.
10+ YOE4+ Mgmt10+ years SOC/NOC experience, 4+ years leadership, Secret clearance, required certs (e.g., CISSP/CISM/CISA/GCIH), bachelor's in CS/InfoSec or equivalent, experience with SIEM/SOAR and DoD/NIST compliance.
Splunk, Microsoft Sentinel, Palo Alto XSOAR, Splunk SOAR, Solarwinds, Nagios, WhatsupGold, SIEM, SOAR
3w
Save
Mark Applied
Hide
Security Engineer
Annapolis Junction, Maryland, United States
$113k-$257k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
6+ YOE6+ years administering Elastic Stack, experience with ES/EQL, log pipeline design, IAM, incident response, and federal cybersecurity environments; Secret clearance required; HS diploma/GED.
Elastic Stack, Elasticsearch, Kibana, Logstash, Beats, Fleet, Elastic Security, ES|QL, EQL, SOAR, n8n, XSOAR, Python, scikit-learn, PyTorch, Elastic AI Assistant
3w
Save
Mark Applied
Hide
Security Engineer
Annapolis Junction, Maryland, United States
$113k-$257k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
6+ YOE6+ years administering Elastic Stack, experience with Elasticsearch/Kibana/Logstash/Beats, EQL/ES|QL, SOC/SIEM operations, DoD or federal cyber experience, Secret clearance required; TS/SCI preferred.
Elastic Stack, Elasticsearch, Kibana, Logstash, Beats, Fleet, Elastic Security, ES|QL, EQL, n8n, XSOAR, Python, scikit-learn, PyTorch, Elastic AI Assistant
3w
Save
Mark Applied
Hide
Cyber Data Platform Architect
Arlington or McLean or Reston or Washington
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
8+ YOE8+ years defensive cyber experience, 5+ years designing security data pipelines, 3+ years with SIEMs, experience with stream processing, orchestration (Kubernetes/OpenShift), TS/SCI clearance required.
Splunk Enterprise Security, Elastic Security, Microsoft Sentinel, Google Chronicle, Cribl, Apache Kafka, Logstash, Fluentd, Kubernetes, RedHat OpenShift, Databricks, Apache Iceberg, Snowflake, CrowdStrike, Corelight, Trellix, Swimlane, XSOAR, Phantom, STIX/TAXII, Python
3w
Save
Mark Applied
Hide
Cyber Data Platform Architect
Arlington, Virginia, United States
$87k-$198k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
8+ YOE8+ years in defensive cyber operations or security architecture, 5+ years designing security data pipelines, experience with SIEMs and stream tools, TS/SCI clearance required.
Splunk Enterprise Security, Elastic Security, Microsoft Sentinel, Google Chronicle, Cribl, Apache Kafka, Logstash, Fluentd, Kubernetes, RedHat OpenShift, Databricks, Apache Iceberg, Snowflake, CrowdStrike, Corelight, Trellix, Swimlane, XSOAR, Phantom, Python
1mo
Save
Mark Applied
Hide
Palo Alto Subject Matter Expert
Springfield or St. Louis
$75k-$158k/yr OnsiteFull Time
CACI International
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
7+ YOEActive TS/SCI clearance with polygraph, 7+ years administering Palo Alto NGFWs, PCNSE and DoD IAT Level II (e.g., Security+ CE), CSSP Infrastructure Support within 120 days, experience with Panorama, PAN-OS, cloud (AWS/Azure/GCP) and core routing protocols.
PAN-OS, Panorama, Prisma Access (SASE), Prisma SD-WAN, VM-Series, AWS, Azure, GCP, Cortex XSOAR, Cortex XDR, Python, Ansible, Terraform, Palo Alto Expedition, Palo Alto XML/REST API, F5, Juniper SRX, Cisco FTD, Cisco ASA
1mo
Save
Mark Applied
Hide
Senior Systems Architect
Virginia, United States
$175k-$195k/yr RemoteFull Time
ECS
ECSNYSE: ASGN: Provides advanced technology and engineering services to government agencies.
12+ YOEU.S. citizen with 12+ years in cybersecurity IT, Bachelor\u0002s (or equivalent), Public Trust clearance eligibility, AWS Solution Architect cert, 3+ years cloud experience, strong SIEM/EDR/CDM and container expertise.
SIEM, EDR, CDM, AWS GovCloud, Amazon EKS, Amazon ECS, Splunk, Microsoft Sentinel, Palo Alto XSOAR, Terraform, AWS CloudFormation, Ansible, AWS App Mesh, Istio, CyberArk, Okta, AWS IAM Identity Center, AWS
1w
Save
Mark Applied
Hide
Principle Cybersecurity Analyst - Remote
Washington or Minneapolis or United States
$113k-$193k/yr RemoteFull Time
UnitedHealth Group
UnitedHealth GroupNYSE: UNH: Provides health insurance and technology-enabled health care services.
3+ YOE3+ years in threat intelligence, security engineering, IR or malware analysis; strong software engineering and cybersecurity integration experience; experience with TIPs, SIEM, SOAR, and automation.
Splunk, Microsoft Sentinel, IBM QRadar, Elastic, Python, Java, JavaScript/Node.js, Go, REST APIs, JSON, STIX/TAXII, Bash, PowerShell, Git, CI/CD, Linux, Ubuntu, CentOS, RHEL, Kali, AWS, Docker, Windows Server, Active Directory, Mac OS X, LLM, MCP, RAG, SIEM, SOAR, EDR, NDR, MISP, OpenCTI, ThreatConnect, Anomali, ThreatQuotient, Cortex XSOAR, Splunk SOAR, Swimlane, Tines, Kafka, Spark, Elasticsearch