Senior SOAR Engineer responsible for designing, developing, implementing, and maintaining security orchestration, automation, and response solutions using Palo Alto XSOAR and Splunk SOAR. The role will work closely with SOC, engineering, and security teams to automate incident response processes, integrate security technologies, and improve SOC efficiency and response times.
How you'll make an impact:
Design, develop, and maintain SOAR playbooks, workflows, integrations, and automation using Palo Alto XSOAR and Splunk SOAR.
Develop and optimize automated incident response processes across common SOC use cases including phishing, malware, endpoint, identity, vulnerability, and threat intelligence investigations.
Build and maintain integrations with SIEM, EDR, email security, identity, network security, threat intelligence, and other security platforms.
Develop custom integrations, scripts, automation components, and APIs using Python, REST APIs, JSON, and webhooks.
Translate SOC processes and manual procedures into scalable and reliable SOAR automation.
Troubleshoot and optimize existing playbooks, integrations, automation failures, and platform performance issues.
Collaborate with SOC analysts, incident responders, threat intelligence, detection engineering, and security engineering teams to identify automation opportunities.
Participate in SOAR architecture, solution design, deployment, upgrades, and platform migration activities.
Establish development standards, documentation, testing procedures, and operational best practices for SOAR content.
Support production deployments and troubleshoot critical automation issues in a 24x7 security operations environment.
Review and improve automation effectiveness, reducing manual analyst effort and improving incident response SLAs.
Mentor junior SOAR engineers and contribute to technical standards and knowledge sharing.
Stay current with emerging SOAR capabilities, security technologies, APIs, and automation techniques.
What we're looking for:
5+ years of experience in Palo Alto XSOAR and/or Splunk SOAR.
Experience developing complex SOAR playbooks, workflows, integrations, and automation.
Experience with SOAR architecture, platform administration, upgrades, migrations, and enterprise deployments.
Strong programming and scripting skills, particularly Python.
Experience with REST APIs, JSON, webhooks, and API-based integrations.
Strong understanding of SOC operations, incident response, and security investigation processes.
Experience integrating SOAR with SIEM, EDR/XDR, IAM, email security, threat intelligence, vulnerability management, and other security platforms.
Experience with Splunk, Palo Alto Networks, CrowdStrike, Microsoft security technologies, ServiceNow, and threat intelligence platforms..
Experience troubleshooting and supporting SOAR solutions in production environments.
Ability to translate complex security processes into scalable and maintainable automation.
Strong analytical, problem-solving, communication, and documentation skills.
Relevant vendor/tool certifications, such as:
Palo Alto Networks Certified Security Automation Engineer (PCSAE)or equivalent XSOAR certification.
Splunk SOAR / Splunk Certifiedcertifications.
Relevant CrowdStrike, Microsoft, Google SecOps, Elastic, or other security platform certifications.
Relevant SIEM, EDR/XDR, threat intelligence, or security automation certifications.
Excellent English fluency required
This role demands availability during US Working Hours specifically from 5:00 PM to 2:00 AM IST
This role is Work from Office (3 days a week).
What you can expect from Optiv
- A company committed to our inclusive value through our Employee Resource Groups
- Work/life balance
- Professional training resources
- Creative problem-solving and the ability to tackle unique, complex projects
- Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
- The ability and technology necessary to productively work remotely/from home (where applicable)
EEO Statement
Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.
Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.

