SOC Engineer II
Morrisville, North Carolina
Job Id:
170751
Job Category:
Job Location:
Morrisville, North Carolina
Security Clearance:
Secret
Business Unit:
Zachary Piper
Division:
Not Defined
Position Owner:
Elizabeth Britt
Piper Companies is looking to fill the role of SOC Engineer II for a Cloud and Technology company located in Morrisville, NC. The SOC Engineer II will support the organization’s security monitoring and incident response capabilities by leveraging Splunk Enterprise Security (ES), Splunk SOAR, and integrated cloud/security platforms across AWS and Azure environments. The SOC Engineer II role is a contract position and requires time in-office 2 days per week in Morrisville, NC.
Responsibilities of the SOC Analyst II Include:
- Developed and optimized Splunk Enterprise Security (ES) detections, correlation searches, dashboards, and reporting to enhance threat visibility and detection coverage.
- Supported Splunk SOAR playbook development, security automation initiatives, and the onboarding, normalization, and enrichment of security data sources.
- Troubleshot data ingestion pipelines, forwarder connectivity, search performance, indexing issues, and configuration changes across distributed Splunk environments.
- Created and maintained Splunk knowledge objects, including field extractions, lookups, event types, tags, macros, and accelerated data models.
- Conducted incident response investigations, analyzing security alerts and coordinating with cross-functional teams to contain, remediate, and document security incidents.
- Collaborated with SOC analysts and engineering teams while participating in a 24/7 on-call rotation to improve operational efficiency and ensure timely response to security events.
Qualifications for the SOC Engineer II Include:
- 5+ years of experience in SIEM engineering, SOC operations, incident response, or cybersecurity engineering, with the ability to perform effectively in high-pressure environments and participate in an on-call rotation, and active secret clearance.
- Strong Splunk Enterprise and Splunk Enterprise Security (ES) expertise, including advanced SPL development, dashboard creation, analytics, detections, reporting, data normalization, and use case development.
- Experience onboarding, parsing, and integrating security data sources and tools into a centralized SIEM, including AWS Security Hub, AWS Config, and other enterprise security platforms.
- Solid understanding of Splunk knowledge objects, field extractions, lookups, CIM normalization, data models, and dashboard optimization in distributed Splunk environments.
- Experience supporting Tier 2 SOC operations, investigating security incidents, presenting technical findings to technical and non-technical stakeholders, and collaborating with cross-functional teams.
- Preferred qualifications include Splunk ES Certified Admin and/or Splunk Core Power User, Security+ or equivalent, GCIH/GCIA/AWS/Azure security certifications, and experience in AWS/Azure environments with Entra ID.
Compensation for the SOC Engineer II include:
- $110,000-$130,000
- Contract
- Benefits: Medical, Dental, Vision, 401k, PTO, Sick leave if required by law, and Holidays
This job opens for applications on 7/28/2026. Applications for this job will be accepted for at least 30 days from the posting date.
Keywords: SOC, SOC engineer II, Security, Secret clearance, Cloud Security, Tier II
#LI-EB1 #HYBRID