Jobs · Engineering · Connecticut

Security Orchestration, Automation & Response Engineer 2/3

University of Connecticut · Storrs, CT · 1 mo ago
Engineering$85k–$115k/yrFull-time

About the Role

Under the direction of the Chief Information Security Officer, the Security Orchestration, Automation, and Response (SOAR) Engineer is responsible for the development, implementation, and administration of UConn’s security automation capabilities, including its infrastructure and systems, in support of the University’s Information Security Office. The engineer designs, builds, and maintains automated security workflows, integrations, and response playbooks that improve the efficiency and effectiveness of cybersecurity operations across the University’s academic, research, and administrative environments. Additionally, this role develops and supports technical solutions that strengthen threat detection, incident response, and operational resilience through the integration of security technologies, data sources, and industry best practices.

The SOAR Engineer investigates and resolves a diverse range of security operations, automation, and technical issues across multiple platforms, working with a broad range of University stakeholders whose technical skills range from minimal to extensive. The engineer collaborates within a team of skilled information security and IT professionals to address problems within a complex University environment and develop solutions tailored to that environment. The role is also responsible for processes and procedures to ensure the continuous improvement of monitoring, detection, and mitigation capabilities. The engineer plans, organizes, and establishes priorities related to assignments, works independently with minimal outside support, and handles sensitive information in a confidential manner.

Responsibilities

Security Orchestration, Automation, and Response Engineer 2

  • Administer and use security tools to identify, investigate, analyze, and mitigate threats to the environment.
  • Assist with the development and support of UConn’s security infrastructure, including but not limited to SIEM, SOAR, EDR/XDR, logging, identity and access management, forensic capabilities, and others.
  • Develop, maintain, and support automated workflows, integrations, scripts, and playbooks to improve security operations and incident response processes.
  • Participate in cybersecurity incident response activities including triage, analysis, containment, eradication, recovery, and post-incident review activities.
  • Produce and maintain detailed engineering plans, operating procedures, diagrams, workflows, standards, and documentation related to security operations and automation platforms.
  • Proactively analyze logs, alerts, telemetry, and security events to identify threats, intrusions, suspicious behavior, and/or compromises.
  • Assist other information security domain owners and IT teams with operational security activities, investigations, troubleshooting, and implementation efforts as needed.
  • Triage and respond to service requests, operational issues, and escalations.
  • Maintain awareness of current and emerging threats, vulnerabilities, attack techniques, and industry trends.
  • Maintain appropriate documentation and diagrams of infrastructure and security systems.
  • Promote security awareness and best practices to improve the overall security posture of the University.
  • Participate in on-call rotation, after-hours changes, and security escalations as needed.
  • Perform other related duties as assigned.

Security Orchestration, Automation, and Response Engineer 3 (additional responsibilities inclusive of Engineer 2)

  • Serve as domain and subject matter expert in one or more information security domains.
  • Lead the design, development, implementation, and maintenance of university security automation, monitoring, and/or incident response systems.
  • Design, implement, and maintain new security solutions.
  • Lead the development and support of UConn’s security infrastructure, including but not limited to SIEM, SOAR, EDR/XDR, logging, identity and access management, forensic capabilities, and others.
  • Lead major projects and initiatives related to cybersecurity operations, engineering, automation, and incident response capabilities.
  • Develop and maintain integrations between enterprise security systems, operational platforms, and data sources.
  • Identify enterprise-level security gaps, perform risk assessments, and recommend solutions to improve detection, response, visibility, and operational resilience.
  • Create custom code, API/REST integrations, automation workflows, and maintainable tooling to facilitate data collection, orchestration, and information sharing across systems and platforms.
  • Assist in the development of operational procedures, response standards, metrics, and security operations best practices.
  • Provide technical leadership and mentoring to junior staff and project teams as appropriate.
  • Operate autonomously within general guidance and with limited supervision.

Skills and Competencies

  • Problem Solving: Demonstrates sound analytic and diagnostic skills dealing with issues that are loosely defined and/or where information is available but must be further manipulated. Once decisions are made, follows and directs action to implement intended results. Breaks a problem down to manageable pieces and implements effective, timely solutions. Openly and directly confronts issues until resolved.
  • Team Orientation: Builds relationships with peers and other departments to achieve objectives. Balances team and individual responsibilities. Exhibits objectivity and openness to others’ views. Gives and welcomes feedback. Puts success of team above self. Responsibilities are assigned with some latitude for setting priorities and decision-making using established policies and procedures. Results are reviewed with next-level team lead/manager for clarification and direction before proceeding.
  • Planning and Project Management: Works with, or serves as, the project lead in identifying those project tasks that are most important, establishes clear priorities, and understands the larger picture. Executes project tasks and creates documentation as required.

Physical Demands: This position involves extended periods of sitting and the extensive use of computers and office equipment.

Requirements

Security Orchestration, Automation, and Response Engineer 2

  • Must meet and maintain eligibility requirements associated with working on CUI/CTI data, such as but not limited to holding U.S. citizenship or permanent residency, at the level required and as determined by the Facility Security Officer and the Office of Export Control.
  • Bachelor’s degree and two (2) years of related experience (IT/Security), OR Associate’s degree and four (4) years of related experience (IT/Security), OR six (6) years of related experience (IT/Security).
  • One (1) or more years of experience working in an information security role in the security automation domain.
  • Experience applying knowledge of SIEM concepts including log collection, event correlation, alerting, parsing/normalization, data ingestion, monitoring, and security analytics.
  • Experience applying knowledge of SOAR platforms, security automation workflows, incident response processes, API integrations, and orchestration concepts.
  • Experience with security monitoring, incident analysis, threat detection, or operational security investigations.
  • Experience administering enterprise SIEM and/or SOAR platforms such as Microsoft Sentinel, Splunk Enterprise Security/SOAR, Cortex XSOAR, QRadar, or similar technologies.
  • Experience developing searches, alerts, and reports using knowledge of SIEM query languages such as Splunk Query Language (SPL), Kusto Query Language (KQL), CrowdStrike Query Language (CQL), or similar query languages.
  • Experience programming or scripting using Python, PowerShell, Bash, or similar scripting languages.
  • Experience with security analysis, operational procedures, policies, standards, and incident response practices.
  • Demonstrated technical, analytical, interpersonal, and organizational skills.

Security Orchestration, Automation, and Response Engineer 3 (inclusive of Engineer 2 requirements)

  • Bachelor’s degree and four (4) years of related experience (IT/Security), OR Associate’s degree and six (6) years of related experience (IT/Security), OR eight (8) years of related experience (IT/Security).
  • Three (3) or more years of experience working in an information security role in the security operations/monitoring domain as an engineer.
  • Experience designing, deploying, and administering complex alerts, searches, APIs, orchestration, automation, and security management systems in an enterprise environment.
  • Demonstrated familiarity with IT Security frameworks and relevant regulatory obligations and audit requirements (GDPR, SOX, NIST, ISO, PCI, FERPA, HIPAA, and/or AICPA/SOC2).
  • Senior-level Security Engineer experience.

Preferred Qualifications

Security Orchestration, Automation, and Response Engineer 2

  • Bachelor’s degree or higher in a Science, Technology, Engineering, Math (STEM) field.
  • Demonstrated ability to stay informed in securing evolving technologies.
  • Demonstrated understanding of a wide array of enterprise applications/services including DNS, SMTP, SSL/TLS, IIS, Apache, LDAP, CAS, Entra, Azure/AWS, SQL, Splunk, KQL, etc.
  • Experience using forensics and deception technologies.
  • Experience working in and applying related security domain concepts including Identity & Access Management, Security Operations, Application Security, Risk Management, and Incident Management.
  • Experience working in a higher education environment.

Security Orchestration, Automation, and Response Engineer 3 (inclusive of Engineer 2 preferred qualifications)

  • Experience securing and supporting both on-premises and cloud-based enterprise environments.
  • Experience developing, configuring, and troubleshooting automated incident response workflows and security orchestration playbooks.
  • Senior-level experience with SIEM and/or SOAR platforms such as Microsoft Sentinel, Splunk Enterprise Security/SOAR, Cortex XSOAR, QRadar, or similar technologies.
  • Experience integrating EDR/XDR, vulnerability management, identity management, email security, cloud security, and ticketing systems into SIEM/SOAR platforms.
  • Experience developing automation and orchestration with iPaaS tools such as Boomi or similar technologies.
  • Experience deploying, administering, operating, and troubleshooting enterprise security monitoring and case management systems.
  • Experience deploying, administering, and operating forensics and deception technologies.
  • Experience developing and maintaining integrations using REST APIs, webhooks, or related automation technologies.
  • Experience with threat detection, incident response, digital forensics, or threat intelligence operations.
  • Experience with monitoring and observability platforms used to support cybersecurity operations.
  • Experience evaluating cybersecurity technologies, vendors, licensing, pricing, terms, and conditions.
  • CISSP, GSEC, GCIH, GCIA, CASP+, Splunk Enterprise Certified.

Pay

Security Orchestration, Automation & Response Engineer 2 (Information Security Analyst 2 – UCP 6): $84,880 to $115,427

Security Orchestration, Automation & Response Engineer 3 (Information Security Analyst 3 – UCP 7): $95,066 to $129,289

Salary will be commensurate with experience within the established range.

Similar jobs