Senior Security Automation & SOAR Engineer
Core
Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response.
Role type
Senior Security Automation & SOAR Engineer
Builds
Automated incident response workflows, secure integrations across security/IT/business platforms, and cloud-based security infrastructure.
Domain
Cybersecurity / Security Operations Center (SOC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOAR platform expertise, Python programming, REST API development, SIEM technologies, EDR solutions, AWS infrastructure-as-code, data manipulation (Pandas/SQL), incident response procedures
Preferred skills
Agentic AI and Large Language Models integration, Identity and Access Management platforms, CI/CD platforms, containerization technologies, threat intelligence platforms
Technologies
Splunk, Elastic, Sentinel, Phantom, XSOAR, Swimlane, CrowdStrike, SentinelOne, Microsoft Defender, AWS, Terraform, CloudFormation, Pulumi, Pandas, SQL, Git, GitLab, Bitbucket, Podman, containerd, Jenkins, GitLab CI, Azure DevOps, ThreatConnect, Anomali, MISP, Okta, Microsoft Entra ID, SailPoint, Proofpoint, Mimecast, Google SecOps
Responsibilities
Architect and develop SOAR playbooks and automated workflows; Build and maintain secure integrations across security, IT, and business platforms; Lead cross-functional collaboration to identify automation opportunities; Deploy cloud-based security infrastructure using infrastructure-as-code; Incorporate AI technologies into security workflows; Produce executive-level reporting on automation performance metrics and ROI.
Seniority
Senior, hands-on IC