Security Operations Engineer Jobs in Virginia
Security Operations Engineer jobs in Virginia are among the most active in the country, with steady demand concentrated in defense contracting, federal civilian agencies, financial services, and cloud infrastructure across seniority levels from entry-level analysts to principal engineers. Northern Virginia, particularly the Tysons Corner and Reston corridors, leads hiring volume, followed by Richmond and the Hampton Roads area, where employers like Leidos, Booz Allen Hamilton, and General Dynamics Information Technology maintain large security operations workforces. The most in-demand specialties are SIEM engineering, endpoint detection and response, and cloud security operations. Find a role that fits below and apply directly.
Find JobsOverview
Showing 5 of 53+ Security Operations Engineer jobs











TIAG is now hiring a Junior Network Security Operations Center (NSOC) Analyst to join our team in support of the Office of Naval Research (ONR) in Arlington, VA. Candidates must possess an active Secret Clearance or interim Secret Clearance and meet DoD IAWF IAT Level II qualifications to be considered.
This is a 100% onsite position in Arlington, VA.
The Junior NSOC Analyst will support ONR's Network Security Operations Center (NSOC) and work closely with senior NSOC personnel, the Information Assurance (IA)/Cybersecurity/Computer Network Defense (CND) Team, and IT Operations. The Analyst will assist with security monitoring, Security Information and Event Management (SIEM), incident identification and response, vulnerability management, network security operations, and cybersecurity compliance activities.
Responsibilities:
- Monitors security events, alerts, and network activity using SIEM and cybersecurity monitoring tools.
- Assists with analyzing and triaging security alerts to identify potential threats, vulnerabilities, and anomalous activity.
- Supports threat reconnaissance and threat monitoring activities using available cybersecurity tools and information sources.
- Uses security tools and technologies such as Trellix ESM/SIEM, Trellix ePO/HBSS, Splunk, Microsoft Defender for Endpoint (MDE), SolarWinds, and Tenable/ACAS/Nessus.
- Assists senior analysts with investigating SIEM events and executing established Incident Response and Incident Handling procedures.
- Generates, monitors, documents, and tracks cybersecurity incidents through resolution. Escalates significant or suspicious cybersecurity events to senior NSOC analysts and appropriate Government personnel.
- Assists with reviewing Indicators of Compromise (IOCs), threat intelligence, and MITRE ATT&CK information to identify potential threats within the ONR environment.
- Supports the collection, correlation, and analysis of security logs from network devices, endpoints, servers, and enterprise applications.
- Assists the IA team with validating system logging, log retention, and audit trail requirements in accordance with NIST and DoD requirements.
- Supports continual assessment of network device configurations and assists with identifying unauthorized or rogue devices.
- Assists with reviewing and validating implementation of applicable DISA Security Technical Implementation Guide (STIG) requirements.
- Supports vulnerability management activities, including reviewing vulnerability scan results and coordinating remediation with technical teams.
- Creates and maintains cybersecurity tickets and supporting documentation using ServiceNow, Azure Boards, and other ITSM tools.
- Assists with the development and maintenance of NSOC Standard Operating Procedures (SOPs), incident response documentation, and operational processes.
- Supports the development of security metrics, dashboards, reports, and trend analysis used to assess ONR's cybersecurity posture and NSOC performance.
- Participates in cybersecurity incident response exercises, vulnerability remediation efforts, and other NSOC operational activities.
- Coordinates with NSOC, IA, Network Operations, Systems Engineering, and other technical teams to resolve cybersecurity issues.
- Continues developing technical knowledge of SIEM, Endpoint Detection and Response (EDR), vulnerability management, threat intelligence, and security automation technologies.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related technical discipline.
- 1–3 years of experience in cybersecurity, information assurance, security operations, network operations, or a related technical field.
- Basic understanding of cybersecurity concepts, including security monitoring, incident response, vulnerability management, network security, and endpoint security.
- Experience or familiarity with SIEM technologies, such as Trellix ESM/SIEM or Splunk.
- Experience or familiarity with endpoint security and Endpoint Detection and Response (EDR) technologies such as Microsoft Defender for Endpoint (MDE) or Trellix ePO/HBSS.
- Familiarity with vulnerability scanning technologies such as Tenable, ACAS, or Nessus.
- Familiarity with NIST cybersecurity guidance, DISA STIGs, and DoD cybersecurity requirements.
- Experience or familiarity with ticketing and work management platforms such as ServiceNow or Azure Boards.
- Strong analytical, troubleshooting, documentation, and communication skills.
- Ability to work collaboratively with cybersecurity, infrastructure, network, and systems engineering teams. IAT Level II certification (Security+ CE or equivalent) and required Operating System (OS)/Computing Environment (CE) certification. Active Secret Clearance or interim Secret Clearance.
- Preferred Qualifications Experience supporting a Security Operations Center (SOC), Network Security Operations Center (NSOC), or DoD cybersecurity environment.
- Familiarity with MITRE ATT&CK, Indicators of Compromise (IOCs), threat intelligence, and security event correlation.
- Exposure to Security Orchestration, Automation, and Response (SOAR) technologies.
- Understanding of TCP/IP, firewalls, IDS/IPS, Access Control Lists (ACLs), endpoint security, and enterprise network architecture.
- Familiarity with DoD Risk Management Framework (RMF) and cybersecurity compliance activities.
- CompTIA Sec+, Computing Environment Certification
- Secret security clearance
TIAG is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a), and 41 CFR 60-741.5(a) and employment decisions shall be based solely on merit and without regard disability, or protected veteran status, or any other characteristic protected by local, state, or federal laws, rules, or regulations. TIAG takes proactive steps to employ and advance in employment qualified individuals without regard to disability or protected veteran status. The parties also agree that, as applicable, they will abide by the requirements and may be subject and required to take action pursuant to the following laws and accompanying regulations:
The Vietnam Era Veterans Readjustment Assistance Act of 1974, as amended (and its implementing regulations at 41 C.F.R. 60-300);
Section 503 of the Rehabilitation Act of 1973, as amended (and its implementing regulations at 41 C.F.R 60-741); and
Executive Order 13496 (and its implementing regulations at 29 C.F.R. part 471, Appendix A to Subpart A).
See All 53 Security Operations Engineer Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find JobsSecurity Operations Engineer Jobs by City in Virginia
Where Virginia roles are concentrated, by current openings.
Security Operations Engineer Job Market in Virginia
A snapshot from current Virginia openings, updated as new roles post.
Who's Hiring
- Allied Universal16

- Serco2

- Leidos2

- AMERICAN SYSTEMS2

- Acuity International2

Top Industries Hiring
- Technology & Software
What Virginia Employers Look For
The qualifications that appear most often in security operations engineer jobs across Virginia.
- Active or eligible federal security clearance, typically Secret or Top Secret with SCI eligibility
- Bachelor's degree in cybersecurity, computer science, information systems, or a related field
- Relevant certifications such as CompTIA Security+, CISSP, CEH, or GIAC credentials
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar
- Proficiency in incident response, threat hunting, and security event analysis workflows
- Familiarity with NIST cybersecurity frameworks, FedRAMP, or CMMC compliance requirements
Security Operations Engineer Jobs in Virginia: Frequently Asked Questions
How do you become a security operations engineer in Virginia?
Most security operations engineer roles in Virginia require a bachelor's degree in cybersecurity, information systems, or computer science, along with industry certifications such as CompTIA Security+, CISSP, or a GIAC credential. Virginia does not issue a state-specific license for this role, but federal contractor positions frequently require a security clearance obtained through a sponsoring employer. Building hands-on experience with SIEM tools, endpoint detection platforms, and incident response workflows is essential for competitive candidacy.
How much do security operations engineers make in Virginia?
Security operations engineers in Virginia earn a median of about $134,900 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $81,410 for the lowest 10% to over $205,750 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire security operations engineers in Virginia?
Employers hiring security operations engineers in Virginia right now include Allied Universal, Serco, and Leidos, based on current listings on Migrate Mate as of September 2026. Virginia's dense concentration of federal contractors and defense agencies means many openings require or prefer candidates who already hold or can obtain a federal security clearance.
Which Virginia cities have the most security operations engineer jobs?
Richmond, Arlington, and Reston have the most security operations engineer openings in Virginia. Northern Virginia dominates because of its proximity to federal agencies, the Pentagon, and the national intelligence community, while Richmond draws demand from financial services firms and state government technology offices, and Hampton Roads reflects the strong Navy and defense contractor presence along the coast.
Are there remote security operations engineer jobs in Virginia?
Yes, and more than most technical fields. About 40% of security operations engineer openings tied to Virginia are remote or hybrid as of September 2026, reflecting the desk-based and analytical nature of much of this work. The tasks most commonly performed remotely include SIEM monitoring, alert triage, and threat intelligence analysis, while roles requiring hands-on lab access or classified facility work tend to be on-site.
How can I get hired as a security operations engineer in Virginia with little or no experience?
The most realistic entry path is securing a junior SOC analyst or security analyst role at one of Virginia's large federal contractors, such as Leidos, Booz Allen Hamilton, or SAIC, which run structured early-career programs and new-graduate hiring pipelines. Completing CompTIA Security+ and Network+ certifications and building a home lab portfolio demonstrating SIEM configuration and incident response gives candidates a concrete edge. Adjacent roles in IT helpdesk, network administration, or systems administration at Virginia government agencies also serve as practical on-ramps.
Where can I find and apply to security operations engineer jobs in Virginia?
You can find and apply to security operations engineer jobs in Virginia on Migrate Mate, which lists current Virginia openings. Find a role that fits and apply directly.
See All 53 Security Operations Engineer Jobs in Virginia
Find roles in Virginia that match your experience and apply in just a few clicks.
Find Jobs