Senior Security Automation & SOAR Engineer
Listed on 2026-07-26
-
IT/Tech
Cybersecurity
Our Mission
Advancing Essential Intelligence.
AboutThe Role
Grade Level (for internal use): 11
Job DescriptionThe Team:
The Cyber Fusion Center protects the business by fusing threat intelligence, monitoring, detection engineering, and response into one proactive, intelligence‑led defense capability that breaks down silos to reduce risk and strengthen security across the enterprise. The team prioritizes collaboration, continuous learning, and innovation, with shared ownership of outcomes and a supportive learning mindset during high‑pressure situations. You'll work in a hands‑on, build‑driven environment with strong team collaboration, rapid learning through real use cases, and clear opportunities to mature automation across the security program.
And Impact
- Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response
- Build and maintain secure integrations across a comprehensive ecosystem of security, IT, and business platforms including security tools, identity systems, cloud services, network infrastructure, ticketing systems, and communication platforms using APIs and custom code to support end‑to‑end incident response workflows
- Lead cross‑functional collaboration with SOC, Detection Engineering, and Incident Response teams to identify automation opportunities and translate operational needs into technical solutions
- Deploy cloud‑based security infrastructure using infrastructure‑as‑code practices, managing role‑based access controls and supporting disaster recovery initiatives
- Incorporate cutting‑edge AI technologies including Agentic AI and Large Language Models into security workflows to enhance decision‑making and contextual understanding
- Produce executive‑level reporting on automation performance metrics and ROI, presenting program effectiveness to leadership while supporting strategic security initiatives
Basic
Required Qualifications:
- 5+ years of proven experience designing and implementing security automation solutions in enterprise environments with hands‑on SOAR platform expertise and demonstrated leadership in automation initiatives.
- Strong hands‑on incident response experience with demonstrated ability to translate response procedures into scalable automated workflows.
- Strong proficiency in Python programming and experience with detection technologies such as YARA, along with REST API development and third‑party service integrations
- Deep technical expertise across security platforms including SIEM technologies (such as Splunk, Elastic, or Sentinel), SOAR platforms (such as Phantom, XSOAR, or Swimlane), and EDR solutions (such as Crowd Strike, Sentinel One, or Microsoft Defender)
- Hands‑on experience with cloud infrastructure deployment particularly in AWS environments, using infrastructure‑as‑code tools (such as Terraform, Cloud Formation, or Pulumi)
- Experience with data manipulation and analysis tools (such as Pandas, SQL, or Elasticsearch) for processing high‑volume security telemetry and creating sophisticated automation triggers
Preferred Qualifications
- Experience with Google Sec Ops platform and familiarity with integrating Agentic AI and Large Language Models into security workflows for enhanced automation and decision‑making
- Advanced knowledge of identity and access management platforms such as Okta, Microsoft Entra , or SailPoint, along with email security solutions like Proofpoint or Mimecast
- Proven experience in development lifecycle best practices including version control systems (such as Git, Git Lab, or Bitbucket), containerization technologies (such as Docker, Podman, or containerd), and CI/CD platforms (such as Jenkins, Git Lab CI, or Azure Dev Ops)
- Experience with threat intelligence platforms (such as Threat Connect, Anomali, or MISP) and integrating threat feeds into automated response workflows
- Strong presentation and communication skills with demonstrated ability to present metrics, operational insights, and program outcomes to executive leadership and cross‑functional stakeholders
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).