Senior Security Automation & SOAR Engineer
Core
Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response.
Role type
Senior Security Automation & SOAR Engineer
Builds
Automated incident response workflows, secure integrations across security/IT/business platforms, cloud-based security infrastructure
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOAR platform expertise, Python programming, incident response, REST API development, SIEM technologies, EDR solutions, cloud infrastructure (AWS), infrastructure-as-code, data manipulation (SQL/Pandas)
Preferred skills
Agentic AI and LLM integration, identity and access management platforms, containerization technologies, CI/CD platforms, threat intelligence platforms
Technologies
Splunk, Elastic, Sentinel, Phantom, XSOAR, Swimlane, CrowdStrike, SentinelOne, Microsoft Defender, AWS, Terraform, CloudFormation, Pulumi, Pandas, SQL, Elasticsearch, Okta, Microsoft Entra ID, SailPoint, Proofpoint, Mimecast, Git, Docker, Podman, containerd, Jenkins, GitLab CI, Azure DevOps, ThreatConnect, Anomali, MISP
Responsibilities
Architect and develop SOAR playbooks and automated workflows; Build and maintain secure integrations across security, IT, and business platforms; Lead cross-functional collaboration with SOC, Detection Engineering, and Incident Response teams; Deploy cloud-based security infrastructure using infrastructure-as-code practices; Incorporate cutting-edge AI technologies including Agentic AI and Large Language Models into security workflows; Produce executive-level reporting on automation performance metrics and ROI
Seniority
Senior, hands-on IC