×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

SOAR and Security Automation Engineer

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Kirkland & Ellis
Full Time position
Listed on 2026-08-22
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 133000 - 166000 USD Yearly USD 133000.00 166000.00 YEAR
Job Description & How to Apply Below

At Kirkland & Ellis, we don’t just meet the standard for legal excellence — we set it. Our culture is built on teamwork, ingenuity and an unwavering commitment to continuous growth. We tackle the most sophisticated legal challenges with bold ideas and innovative solutions, powered by the exceptional experience and ambition of our 7,000+ people, including 4,000+ attorneys, across 24 offices worldwide.

Our dedicated professionals share our lawyers’ commitment to excellence and show up each day to do meaningful work that helps drive global business, investment and innovation forward.

What You’ll Do

Are you passionate about transforming security operations through automation and AI? As a SOAR & Security Automation Engineer, you’ll design and scale intelligent workflows that power faster, smarter cyber incident response. You’ll play a critical role within the Cybersecurity Investigations & Response function, helping protect the firm from evolving threats while driving efficiency through Security Orchestration, Automation, and Response (SOAR) and emerging AI technologies.
Working within the Security Governance organization led by the Chief Information Security Officer (CISO), you’ll operate at the intersection of security, automation, and innovation. This is a high-impact role where sound judgment, attention to detail, and professionalism are essential as you support enterprise-wide security and compliance efforts.

  • Design, build, and continuously improve automation playbooks for key incident types such as phishing, identity compromise, endpoint events, and threat intelligence.
  • Translate manual investigation and response processes into scalable, automated workflows that improve accuracy and response speed.
  • Administer and optimize SOAR platforms such as Palo Alto Cortex XSOAR and Google Security Operations (Sec Ops), ensuring reliability and performance.
  • Connect and streamline security technologies across the ecosystem—including Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), identity and access management (IAM), ticketing systems, and threat intelligence platforms.
  • Oversee end-to-end lifecycle activities including development, testing, deployment, and tuning of automation solutions.
  • Identify repetitive, high-volume tasks and implement automation to reduce mean time to respond (MTTR) and improve signal-to-noise ratio.
  • Develop and track performance metrics to measure the effectiveness, efficiency, and return on investment (ROI) of automation initiatives.
  • Build and deploy AI-assisted workflows for triage, enrichment, and response using large language models (LLMs) and related tools.
  • Collaborate with engineering and detection teams to evolve toward an agentic Security Operations Center (SOC) model.
  • Partner with SOC, incident response, detection engineering, IT teams, and managed security service providers (MSSPs) to translate operational gaps into automation opportunities and continuously improve response processes.
What You’ll Bring
  • Education &

    Certifications:

    Bachelor’s degree in Cybersecurity, Information Systems, or a related field (preferred); relevant certifications such as Palo Alto Networks Certified XSOAR Engineer, Google Cloud Professional Security Operations Engineer, or AI/automation credentials are a plus.
  • Experience:

    3–7+ years in cybersecurity, including hands-on work in SOAR, Security Operations Center (SOC), incident response, or security engineering.
  • SOAR & Automation Expertise:
    Proven experience designing and maintaining automation workflows and playbooks using platforms like Cortex XSOAR or Google Sec Ops.
  • Technical

    Skills:

    Strong scripting capabilities in Python, Power Shell, or similar languages to build scalable automation solutions.
  • Security Operations Knowledge:
    Solid understanding of incident response lifecycle, SIEM, EDR, and threat intelligence practices.
  • Framework Familiarity:
    Working knowledge of industry frameworks such as ISO 27001, National Institute of Standards and Technology (NIST) 800-53, Cybersecurity Framework (CSF), Center for Internet Security (CIS), and MITRE ATT&CK.
  • Analytical Mindset:
    Ability to identify inefficiencies, solve complex…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary