About the Role
The Senior Security Automation & SOAR Engineer is a highly technical role responsible for the architecture, deployment, and lifecycle management of automated incident response workflows. This role will develop cloud-native orchestration playbooks, integrate diverse API-driven detection technologies, tune data streams, and improve operational response efficiency.
Responsibilities
- Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes.
- Build and maintain secure integrations across security, IT, and business platforms using APIs and custom code.
- Lead cross-functional collaboration with SOC, Detection Engineering, and Incident Response teams to identify automation opportunities.
- Deploy cloud-based security infrastructure using infrastructure-as-code practices.
- Incorporate AI technologies including Agentic AI and Large Language Models into security workflows.
- Produce executive-level reporting on automation performance metrics and ROI.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent professional experience in security automation and orchestration.
- 5+ years of proven experience designing and implementing security automation solutions in enterprise environments.
- Hands-on SOAR platform expertise and demonstrated leadership in automation initiatives.
- Strong hands-on incident response experience with demonstrated ability to translate response procedures into scalable automated workflows.
- Strong proficiency in Python programming and experience with detection technologies such as YARA.
- Experience with REST API development and third-party service integrations.
- Deep technical expertise across SIEM technologies (such as Splunk, Elastic, or Sentinel), SOAR platforms (such as Phantom, XSOAR, or Swimlane), and EDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).
- Hands-on experience with cloud infrastructure deployment particularly in AWS environments, using infrastructure-as-code tools (such as Terraform, CloudFormation, or Pulumi).
- Experience with data manipulation and analysis tools (such as Pandas, SQL, or Elasticsearch).
- Experience with Google SecOps platform.
- Familiarity with integrating Agentic AI and Large Language Models into security workflows.
- Advanced knowledge of identity and access management platforms such as Okta, Microsoft Entra ID, or SailPoint.
- Experience with email security solutions like Proofpoint or Mimecast.
- Proven experience in development lifecycle best practices including version control systems (such as Git, GitLab, or Bitbucket).
- Experience with containerization technologies (such as Docker, Podman, or containerd).
- Experience with CI/CD platforms (such as Jenkins, GitLab CI, or Azure DevOps).
- Experience with threat intelligence platforms (such as ThreatConnect, Anomali, or MISP) and integrating threat feeds into automated response workflows.
- Strong presentation and communication skills.
Skills
- Security Automation
- SOAR
- Incident Response
- Cloud-native orchestration
- API Integration
- Python Programming
- SIEM technologies
- EDR solutions
- Infrastructure-as-code
- Data manipulation and analysis
- Agentic AI
- Large Language Models
- Identity and Access Management
- Email Security
- Version Control Systems
- Containerization
- CI/CD
- Threat Intelligence Platforms
Experience Level
- 5+ years of proven experience designing and implementing security automation solutions
- Senior
Education Level
- Bachelor's degree in Computer Science, Cybersecurity, or related field
- Equivalent professional experience in security automation and orchestration
Salary/Compensations
- $140,000 to $155,000
Benefits
- Additional compensation such as annual incentive bonus plan
- Health care coverage designed for the mind and body
- Generous time off
- Access to resources for career growth and learning
- Competitive pay
- Retirement planning
- Continuing education program with a company-matched student loan contribution
- Financial wellness programs
- Benefits for families
- Retail discounts
- Referral incentive awards
About the Company
- Advancing Essential Intelligence.
- We're more than 35,000 strong worldwide—so we're able to understand nuances while having a broad perspective.
- Our team is driven by curiosity and a shared belief that Essential Intelligence can help build a more prosperous future for us all.
- From finding new ways to measure sustainability to analyzing energy transition across the supply chain to building workflow solutions that make it easy to tap into insight and apply it.
- We are changing the way people see things and empowering them to make an impact on the world we live in.
- We’re committed to a more equitable future and to helping our customers find new, sustainable ways of doing business.
- Join us and help create the critical insights that truly make a difference.
- Integrity, Discovery, Partnership
- Throughout our history, the world's leading organizations have relied on us for the Essential Intelligence they need to make confident decisions about the road ahead.
- We start with a foundation of integrity in all we do, bring a spirit of discovery to our work, and collaborate in close partnership with each other and our customers to achieve shared goals.
Equal Opportunity
- S&P Global is an equal opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law.
- Only electronic job submissions will be considered for employment.
- If you need an accommodation during the application process due to a disability, please send an email to: EEO.Compliance@spglobal.com and your request will be forwarded to the appropriate person.
