SOAR Engineer

San Antonio, TX, US • Posted 3 days ago • Updated 1 hour ago
Full Time
On-site
USD $75,000.00 - 150,000.00 per year
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Event Management
  • SIPRNet
  • Build Automation
  • Program Management Office
  • Content Creation
  • Reporting
  • Continuous Improvement
  • Dashboard
  • Workflow
  • Testing
  • Palo Alto
  • Microsoft
  • Orchestration
  • Management
  • Collaboration
  • Content Development
  • Communication
  • Computer Science
  • Information Systems
  • SIEM
  • Cyber Security
  • DoD
  • Security Operations
  • Adobe AIR
  • Cloud Computing
  • Security Clearance

Summary

SOAR Engineer

Location:

On-Site - Port San Antonio, TX

Clearance Required:

TS/SCI

Position Summary

The Digital Modernization Sector has an exciting career opportunity for an experienced SOAR Engineer to support the government customer's Security Orchestration, Automation, and Response (SOAR) platform and its integration with the Global Security Information and Event Management (SIEM) environment. This position is responsible for the sustainment, monitoring, and content development of the Global SOAR platform-Currently Palo Alto XSOAR and its connection to the Global SIEM - Currently Elastic SIEM. This application is hosted on AF Cloud one on both NIPRNET and SIPRNET. The SOAR Engineer works closely with government stakeholders, the 33rd Content Developers, and mission partners to build automation, integrations, and playbooks that improve analyst efficiency and reduce response time.

The position requires on-site presence at Joint Base San Antonio supporting the USAF Defensive Cyber Systems Program Management Office's Product Section. This position is regularly in a cleared facility to maintain classified applications.

3. Government-Directed Responsibilities

Key Responsibilities
  • Support further integration of the Global SIEM with the Global SOAR platform so that SOAR can receive and triage SIEM-generated alerts.
  • Establish new integrations with United States Air Force (USAF) systems such as Tanium, Defender, Patriot, and other mission-relevant platforms as directed.
  • Work with the SIEM team toidentifyvendor system data sources being ingested andestablishconnectivity using similar connectors where operationally relevant.
  • Content Creation - Partner with the 33rd Content Developers to design and build playbooks that reduce analyst workload and save analyst time.
  • Monitor SOAR cluster health and detection rule performance, identifying and remediating issues that affect orchestration, automation, or alerting.
  • Validate dashboards to ensure accuracy, availability, and relevance of reporting to end users.
  • Collect and incorporate analyst feedback to drive continuous improvement of SOAR playbooks, dashboards, and workflows.

Required Qualifications
  • Active Top Secret (TS) clearance.
  • Working knowledge of SOAR platforms (e.g., XSOAR/Cortex XSOAR) and their integration with SIEM platforms (e.g.,Elastic SIEM).
  • Experience developing, testing, andmaintainingautomation playbooks in a SOAR environmentusing Palo Alto XSOAR.
  • Familiarity with cybersecurity tools and data sources such as Tanium, Microsoft Defender, and Patriot, or comparable enterprise security platforms.
  • Ability tobuild andtroubleshoot connectors/integrations between SOAR and third-party vendor systems.
  • Ability to analyze detectionruleand cluster health data and troubleshoot orchestration or performance issues.
  • Ability to manage applications hosted on a Cloud.
  • Strong collaboration skills to work across content development,analyst, and government stakeholder teams.
  • Effective written and verbal communication skills, including the ability to translate analyst feedback into actionable engineering improvements.

Preferred Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or related field, or equivalent experience]
  • Familiarity withSOAR/SIEM or cybersecurity operations experience
  • Prior experience supporting government or DoD security operations environments.'
  • Familiarity with running applications on Air Force Cloud one

Work Environment

This position requires an active Top Secret clearance and may involve work in a cleared facility environment. Specific location and on-site requirements will be confirmed during the interview process.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91136213
  • Position Id: 6293d18a7ab1dbc579bebbda1b658c91
  • Posted 3 days ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

San Antonio, Texas

•

Today

Full-time

USD 145,000.00 per year

San Antonio, Texas

•

Today

Full-time

USD 120,000.00 per year

San Antonio, Texas

•

Today

Full-time

USD 90,000.00 per year

San Antonio, Texas

•

Today

Full-time

USD 190,000.00 per year

Search all similar jobs