Position Summary
The Splunk SOAR Engineer is the program's security automation developer and owns the Splunk SOAR workload end to end. The position's defining early commitment is automating the Cyber Defense Center's incident response playbooks during the first months of performance, followed by the documentation and decision tree diagrams that make the automation maintainable. In steady state, this individual keeps the SOAR platform, its integrations, and its playbook library healthy and expanding, and trains government analysts to get full value from the automation.
Key Responsibilities
· Design, develop, test, and document Splunk SOAR playbooks that automate the Cyber Defense Center's incident response scenarios, including the logic documentation and decision tree diagrams behind each playbook.
· Configure and maintain SOAR integrations with security tools including the SIEM, EDR, and ServiceNow, and restore integrations promptly when they break.
· Build and test custom apps and connectors for third-party platform connectivity.
· Manage API keys, credentials, and authentication for all integrated platforms.
· Configure case management and workflow templates for incident handling.
· Maintain SOAR platform health and apply updates in accordance with change management.
· Monitor playbook execution and case handling, and investigate and correct playbook failures.
· Create automation workflows for repetitive security tasks and containment actions, and review the automation library on a recurring cycle for efficiency gains.
· Validate playbooks in development and production environments before release.
· Provide training and support to government analysts on playbook usage and SOAR capabilities.
Demonstrated Hands-On Experience (Evaluation Emphasis)
The selected individual must demonstrate hands-on experience designing and developing playbooks in Splunk SOAR (or Phantom) within a production environment. The candidate shall clearly describe direct technical experience writing playbook logic in Python, integrating SOAR with SIEM, EDR, and ticketing platforms through REST APIs, and managing the connectors and credentials behind those integrations, including specific examples of the response scenarios automated, the environments supported, and the operational outcomes achieved. Experience limited primarily to running playbooks built by others, coordinating incident response, or administering ticketing workflows, without substantial playbook development responsibilities, will be viewed as less competitive.
Required Qualifications
· Minimum of five years in a security operations or security engineering role, including at least two years of hands-on Splunk SOAR playbook development. Demonstrated hands-on experience is mandatory and may not be substituted.
· Demonstrated proficiency in Python, REST API integration, and JSON, with working knowledge of SPL and of how SOAR consumes and acts on SIEM data.
· Experience integrating SOAR with EDR platforms and ServiceNow or comparable ITSM systems.
· Relevant industry certifications are preferred where practicable, such as Splunk SOAR Certified Automation Developer, Splunk Core Certified Power User, GIAC GCIH, or CompTIA Security+.
- Clearance and Work Conditions
- · Place of performance: Remote work, based within United States.
- · Schedule: standard business hours, Monday through Friday, excluding Federal holidays.
- · Successfully complete an Government background investigation
- Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 10229270
- Position Id: 9098456
- Posted 12 hours ago