Senior Security Automation & SOAR Engineer
Core
Architect, deploy, and manage end-to-end lifecycle of automated incident response workflows and cloud-native orchestration playbooks to improve SOC efficiency and reduce MTTR.
Role type
Senior Security Automation & SOAR Engineer
Builds
Cloud-native orchestration playbooks, secure integrations across security/IT/business platforms, and automated incident response workflows.
Domain
Cybersecurity, Security Operations Center (SOC), Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOAR platform expertise, Python programming, REST API development, incident response automation, SIEM technologies, EDR solutions, cloud infrastructure deployment, infrastructure-as-code, data manipulation and analysis
Preferred skills
Google SecOps platform, Agentic AI and Large Language Models integration, identity and access management platforms, email security solutions, development lifecycle best practices, containerization technologies, CI/CD platforms, threat intelligence platforms
Technologies
Google SecOps, Splunk, Elastic, Sentinel, Phantom, XSOAR, Swimlane, CrowdStrike, SentinelOne, Microsoft Defender, AWS, Terraform, CloudFormation, Pulumi, Pandas, SQL, Elasticsearch, Okta, Microsoft Entra ID, SailPoint, Proofpoint, Mimecast, ThreatConnect, Anomali, MISP, Git, GitLab, Bitbucket, Docker, Podman, containerd, Jenkins, GitLab CI, Azure DevOps
Responsibilities
Architect and develop SOAR playbooks and automated workflows; Build and maintain secure integrations across security, IT, and business platforms; Lead cross-functional collaboration to identify automation opportunities; Deploy cloud-based security infrastructure using infrastructure-as-code; Incorporate AI technologies into security workflows; Produce executive-level reporting on automation performance metrics and ROI.
Seniority
Senior, hands-on IC