Design, develop, implement, and maintain automation workflows within the enterprise SOAR platform
Build and optimize security orchestration playbooks for incident detection, triage, investigation, and response
Continuously improve existing automations to enhance efficiency, scalability, and response times
Administer and maintain SOAR platform configurations, workflows, and integrations
Develop automated response workflows for security alerts and incidents
Create logic-driven playbooks to reduce manual intervention and accelerate remediation
Identify opportunities to automate repetitive security operations tasks
Optimize existing automation processes for performance, reliability, and operational effectiveness
Build and maintain integrations between the SOAR platform and enterprise security tools, including: SIEM platforms, Endpoint Detection and Response (EDR) solutions, Firewalls, Threat intelligence platforms, Ticketing and case management systems
Develop and maintain API-based integrations with internal and external systems
Develop custom scripts and connectors when out-of-the-box integrations do not meet business requirements
Collaborate with Security Operations Center (SOC), Incident Response (IR), and Engineering teams
Support incident investigation, response, and remediation activities through automation
Develop and maintain comprehensive documentation for: Playbooks, Runbooks, Integration configurations, Troubleshooting procedures, Standard operating procedures
Engage directly with internal teams and external stakeholders to understand requirements
Design and maintain operational dashboards and reporting metrics
Requirements
5+ years of experience with SOAR platforms or security automation solutions
8+ years of experience in security architecture may be substituted in lieu of education
5+ years of experience supporting large enterprise IT environments or system deployments
Strong hands-on experience with automation platform design, implementation, and administration
Experience with Rest API's, JSON, and YAML
Experience with scripting and automation (Python, Bash, PowerShell, or similar)
Familiarity with MITRE ATT & CK framework
Experience working in multi-tenancy environment; multi-agency or enterprise service projects