About The Position

In a rapidly evolving cybersecurity landscape, organizations are facing increasingly sophisticated threats while simultaneously managing growing security operations workloads. Clients across industries look to us for innovative solutions that improve efficiency, enhance visibility, and strengthen cyber resilience through automation and orchestration. Join our dynamic team as a Senior SOAR Engineer, where you'll play a key role in designing, implementing, and optimizing security automation solutions that enable organizations to respond to threats faster and more effectively. You will work closely with security operations, incident response, threat detection, and engineering teams to automate repetitive tasks, orchestrate complex workflows, and integrate a wide range of security technologies. Your expertise in security automation, scripting, and platform engineering will help clients mature their security operations, reduce response times, and maximize the value of their cybersecurity investments.

Requirements

  • A Bachelor’s degree (4-year degree) in Computer Science, Computer Engineering, Cybersecurity, Information Technology, Management Information Systems, or a related field, along with 2-4 years of relevant experience in security automation, SOAR engineering, security operations, cybersecurity engineering, or a related discipline.
  • Hands-on experience implementing, administering, or developing solutions within enterprise SOAR platforms such as Palo Alto Cortex XSOAR, Microsoft Sentinel Automation, Splunk SOAR (Phantom), Google Security Operations (Chronicle SOAR), Tines, D3 Security, Swimlane, or similar technologies.
  • Strong software development and scripting experience using languages such as Python, PowerShell, JavaScript, or other automation-focused programming languages.
  • Experience developing and consuming REST APIs, web services, SDKs, and custom integrations.
  • Knowledge of security operations processes including alert triage, incident response, threat detection, vulnerability management, and case management workflows.
  • Experience integrating cybersecurity technologies such as SIEM, EDR/XDR, IAM, email security, network security, cloud security, vulnerability management, threat intelligence, and ticketing platforms.
  • Understanding of infrastructure, networking, operating systems, and cloud environments including Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
  • Experience designing, testing, troubleshooting, and maintaining automation workflows in production environments.
  • Knowledge of secure development principles and software engineering best practices including version control, testing methodologies, and CI/CD concepts.
  • Relevant industry certifications such as Microsoft Certified: Cybersecurity Architect Expert, Microsoft SC-200, Splunk Core Certified Power User, Security+, CySA+, GSEC, GCIH, Cortex XSOAR Engineer, or similar certifications, or the ability to acquire certification after employment.

Nice To Haves

  • Experience architecting enterprise-scale SOAR implementations and security automation programs.
  • Experience developing custom integrations, reusable automation frameworks, and advanced workflow orchestration solutions.
  • Familiarity with Infrastructure as Code (IaC) technologies such as Terraform, ARM templates, Bicep, or CloudFormation.
  • Experience working with DevSecOps, CI/CD pipelines, and cloud-native automation technologies.
  • The ability to communicate effectively during technical workshops, architecture reviews, client interviews, and executive briefings.
  • Exemplary writing skills and the ability to communicate complex technical concepts to both technical and non-technical audiences.
  • The ability to translate operational requirements into automation strategies, technical designs, and implementation roadmaps.
  • The ability to break down complex engineering challenges into manageable components, estimate level-of-effort, and deliver solutions within tight timelines.
  • Proficiency with consulting engagement methodologies and approaches, understanding how to align technical solutions with client business objectives.
  • Familiarity with emerging security automation trends, AI-assisted security operations, and modern cybersecurity technologies.

Responsibilities

  • Designing, developing, and maintaining automated security workflows that enhance the effectiveness and efficiency of security operations.
  • Implementing and optimizing SOAR platforms by integrating security tools, data sources, and operational processes across the cybersecurity ecosystem.
  • Collaborating with Security Operations Center (SOC), Incident Response, Threat Intelligence, Detection Engineering, and Vulnerability Management teams to identify automation opportunities and translate operational requirements into scalable technical solutions.
  • Designing and developing playbooks that automate incident triage, enrichment, containment, remediation, and reporting activities while ensuring reliability, maintainability, and security of automation workflows.
  • Leveraging programming and scripting languages to develop custom integrations, APIs, connectors, and automation capabilities across cloud environments, security platforms, and enterprise applications.
  • Integrating SIEM, EDR, IAM, cloud security, threat intelligence, ticketing, and collaboration platforms to facilitate seamless orchestration across complex security architectures.
  • Contributing to the development of automation standards, reusable frameworks, and engineering best practices.
  • Assisting clients with SOAR platform deployments, upgrades, and operational enhancements.
  • Mentoring junior team members, providing technical leadership on security automation initiatives, and contributing to the continued growth of the cybersecurity engineering practice.
  • Staying current on emerging cybersecurity threats, automation technologies, cloud-native security capabilities, and evolving SOAR solutions.
  • Actively participating in professional development opportunities, industry forums, technical communities, and relevant training to maintain expertise in modern security operations and automation engineering.

Benefits

  • medical and dental coverage
  • pension and 401(k) plans
  • a wide range of paid time off options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service