SOC Technical Writer
ECSAbout the role
Everforth ECS is seeking a Cyber Technical Writer to work in our Portland, OR office.
The Cyber Technical Writer develops, maintains, and improves cybersecurity documentation, operational procedures, technical guides, reports, briefings, and knowledge products that support security operations, engineering, assessment, training, and program management activities. This role translates complex cybersecurity concepts, processes, tools, and technical findings into clear, accurate, audience-appropriate documentation.
The ideal candidate combines strong writing and editing skills with a working understanding of cybersecurity operations, risk management, incident response, security tools, and compliance-driven environments. The role requires close collaboration with analysts, engineers, assessors, threat intelligence staff, training personnel, and program leadership to ensure documentation is complete, consistent, usable, and aligned with program requirements.
Key Responsibilities
Cybersecurity Documentation Development
- Develop, revise, and maintain cybersecurity documentation, including standard operating procedures, playbooks, runbooks, technical guides, process documents, user guides, and job aids.
- Translate technical input from cybersecurity subject matter experts into clear, structured, and actionable documentation for technical, operational, and management audiences.
- Document SOC workflows, incident response procedures, escalation paths, monitoring processes, reporting procedures, and security tool usage guidance.
- Ensure documentation accurately reflects current tools, processes, roles, responsibilities, and operational requirements.
Reports, Briefings & Deliverables
- Prepare, edit, and format cybersecurity reports, executive summaries, operational updates, assessment support materials, after-action reports, and program deliverables.
- Support development of recurring status reports, performance summaries, metrics narratives, findings summaries, and stakeholder briefings.
- Ensure written products are clear, accurate, consistent, properly formatted, and aligned with audience needs and program expectations.
- Coordinate with technical contributors to validate facts, terminology, findings, recommendations, and supporting evidence before publication or submission.
Process, Policy & Procedure Support
- Support documentation of cybersecurity policies, processes, procedures, standards, templates, and governance materials.
- Assist teams in converting informal practices, analyst notes, lessons learned, and technical workflows into repeatable, approved procedures.
- Maintain documentation that supports audit readiness, compliance activities, risk management, incident handling, training, and operational continuity.
- Identify gaps, inconsistencies, outdated content, or unclear procedures and recommend improvements to documentation owners.
Stakeholder Collaboration & Content Coordination
- Work with SOC analysts, engineers, assessors, threat hunters, threat intelligence analysts, forensics personnel, training staff, and program leadership to gather content and clarify requirements.
- Facilitate reviews, collect feedback, adjudicate comments, and incorporate approved changes into formal documentation.
- Support communication between technical teams and non-technical stakeholders by converting technical details into plain-language summaries when appropriate.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s