Security Orchestration, Automation & Response
University of Connecticut · Storrs, CT · 5 days ago
Management$85k–$115k/yrFull-time
About the role
The Security Orchestration, Automation, and Response (SOAR) Engineer is responsible for the development, implementation, and administration of UConn’s security automation capabilities, including its infrastructure and systems, in support of the University’s Information Security Office. The engineer designs, builds, and maintains automated security workflows, integrations, and response playbooks that improve the efficiency and effectiveness of cybersecurity operations across the University’s academic, research, and administrative environments.
Responsibilities
- Administer and use security tools to identify, investigate, analyze, and mitigate threats to the environment.
- Assists with the development and support of UConn’s security infrastructure, including but not limited to SIEM, SOAR, EDR/XDR, logging, identity and access management, forensic capabilities, and others.
- Develops, maintains, and supports automated workflows, integrations, scripts, and playbooks to improve security operations and incident response processes.
- Participates in cybersecurity incident response activities including triage, analysis, containment, eradication, recovery, and post-incident review activities.
- Produces and maintains detailed engineering plans, operating procedures, diagrams, workflows, standards, and documentation related to security operations and automation platforms.
- Proactively analyzes logs, alerts, telemetry, and security events to identify threats, intrusions, suspicious behavior, and/or compromises.
- Assists other information security domain owners and IT teams with operational security activities, investigations, troubleshooting, and implementation efforts as needed.
- Trades and responds to service requests, operational issues, and escalations.
- Maintains awareness of current and emerging threats, vulnerabilities, attack techniques, and industry trends.
- Maintains appropriate documentation and diagrams of infrastructure and security systems.
- Promote security awareness and best practices to improve the overall security posture of the University.
- Participates in on-call rotation, after-hours changes, and security escalations as needed.
- Performs other related duties as assigned.
Qualifications
- Must meet and maintain eligibility requirements associated with working on CUI/CTI data, such as but not limited to holding U.S. citizenship or permanent residency, at the level required and as determined by the Facility Security Officer and the Office of Export Control.
- Bachelor’s degree and two (2) years of related experience (IT/Security), OR Associate’s degree and four (4) years of related experience (IT/Security), OR Six (6) years of related experience (IT/Security).
- One (1) or more years of experience working in an information security role in the security automation domain.
- Experience applying knowledge of SIEM concepts including log collection, event correlation, alerting, parsing/normalization, data ingestion, monitoring, and security analytics.
- Experience applying knowledge of SOAR platforms, security automation workflows, incident response processes, API integrations, and orchestration concepts.
- Experience with security monitoring, incident analysis, threat detection, or operational security investigations.
- Experience administering enterprise SIEM and/or SOAR platforms such as Microsoft Sentinel, Splunk Enterprise Security/SOAR, Cortex XSOAR, QRadar, or similar technologies.
- Experience developing searches, alerts and reports using knowledge of SIEM query languages such as Splunk Query Language (SPL), Kusto Query Language (KQL), CrowdStrike Query Language (CQL), or similar query languages.
- Experience programming or scripting using Python, PowerShell, Bash, or similar scripting languages.
- Experience with security analysis, operational procedures, policies, standards, and incident response practices.
- Demonstrated technical, analytical, interpersonal, and organizational skills.
Skills
- Problem Solving: Demonstrates sound analytic and diagnostic skills dealing with issues that are loosely defined and/or where information is available but must be further manipulated. Once decisions are made, you can follow and direct action to implement intended results. Breaks a problem down to manageable pieces and implements effective, timely solutions.
- Team Orientation: Builds relationships with peers and other departments to achieve objectives. Balances team and individual responsibilities. Exhibits objectivity and openness to others’ views. Gives and welcomes feedback. Puts success of team above self.
- Planning and Project Management: Works with, or serves as, the project lead in identifying those project tasks that are most important, establishes clear priorities and understands the larger picture. Executes project tasks and creates documentation as required.