Senior Security Automation & SOAR Engineer
About The Role
Grade Level (for internal use): 10
Job Description Summary: The Senior Security Automation & SOAR Engineer is a highly technical role within the Cyber Fusion Center responsible for the architecture, deployment, and end-to-end lifecycle management of automated incident response workflows.
Responsibilities And Impact
- Arcitect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response
- Build and maintain secure integrations across a comprehensive ecosystem of security, IT, and business platforms including security tools, identity systems, cloud services, network infrastructure, ticketing systems, and communication platforms using APIs and custom code to support end-to-end incident response workflows
- Lead cross-functional collaboration with SOC, Detection Engineering, and Incident Response teams to identify automation opportunities and translate operational needs into technical solutions
- Deploy cloud-based security infrastructure using infrastructure-as-code practices, managing role-based access controls and supporting disaster recovery initiatives
- Incorporate cutting-edge AI technologies including Agentic AI and Large Language Models into security workflows to enhance decision-making and contextual understanding
- Produce executive-level reporting on automation performance metrics and ROI, presenting program effectiveness to leadership while supporting strategic security initiatives
Basic Required Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent professional experience in security automation and orchestration
- 5+ years of proven experience designing and implementing security automation solutions in enterprise environments with hands-on SOAR platform expertise and demonstrated leadership in automation initiatives
- Strong hands-on incident response experience with demonstrated ability to translate response procedures into scalable automated workflows
- Strong proficiency in Python programming and experience with detection technologies such as YARA, along with REST API development and third-party service integrations
- Deep technical expertise across security platforms including SIEM technologies (such as Splunk, Elastic, or Sentinel), SOAR platforms (such as Phantom, XSOAR, or Swimlane), and EDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender)
- Hands-on experience with cloud infrastructure deployment particularly in AWS environments, using infrastructure-as-code tools (such as Terraform, CloudFormation, or Pulumi)
- Experience with data manipulation and analysis tools (such as Pandas, SQL, or Elasticsearch) for processing high-volume security telemetry and creating sophisticated automation triggers
Additional Preferred Qualifications
- Experience with Google SecOps platform and familiarity with integrating Agentic AI and Large Language Models into security workflows for enhanced automation and decision-making
- Advanced knowledge of identity and access management platforms such as Okta, Microsoft Entra ID, or SailPoint, along with email security solutions like Proofpoint or Mimecast
- Prominent experience in development lifecycle best practices including version control systems (such as Git, GitLab, or Bitbucket), containerization technologies (such as Docker, Podman, or containerd), and CI/CD platforms (such as Jenkins, GitLab CI, or Azure DevOps)
- Proven experience in threat intelligence platforms (such as ThreatConnect, Anomali, or MISP) and integrating threat feeds into automated response workflows
- Strong presentation and communication skills with demonstrated ability to present metrics, operational insights, and program outcomes to executive leadership and cross-functional stakeholders
Compensation/Benefits Information (US Applicants Only)
S&P Global states that the anticipated base salary range for this position is $140,000 to $155,000. Base salary ranges may vary by geographic location. In addition to base compensation, this role is eligible for additional compensation such as annual incentive bonus plan. This role is eligible to receive additional S&P Global benefits.
What’s In It For You?
Our Mission: Advancing Essential Intelligence.
Our People: More than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective. Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all.
Our Values
- Integrity
- Discovery
- Partnership
Benefits
- Health & Wellness
- Flexible Downtime
- Continuous Learning
- Invest in Your Future
- Family Friendly Perks
- Beyond the Basics
Recruitment Fraud Alert
If you receive an email from a spglobalind.com domain or any other regionally based domains, it is a scam and should be reported to reportfraud@spglobal.com.
Equal Opportunity Employer
S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. Only electronic job submissions will be considered for employment.