Security Operations Engineer
Core
Support, maintain, and expand the Security Orchestration, Automation, and Response (SOAR) platform to streamline security operations and enhance incident response efficiency.
Role type
Security Operations Engineer (SOAR focus)
Builds
SOAR playbooks, automated workflows, and tool integrations
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOAR platform operations, API integrations, Python scripting, security concepts, incident response workflows, documentation
Preferred skills
SOC analyst experience, SIEM/EDR/threat intelligence exposure, Go/Bash/PowerShell/JavaScript, MITRE ATT&CK/NIST frameworks
Technologies
SOAR platforms (Palo Alto Networks Cortex XSOAR, Tines, Splunk SOAR), Python, APIs
Responsibilities
Develop, test, and maintain SOAR playbooks and workflows; Identify and automate repetitive manual tasks; Partner with security analysts to understand workflows; Create and maintain documentation for automation scripts and integrations; Assist with basic SOAR platform maintenance and logging system changes
Seniority
Junior to Mid-level, hands-on IC