Senior Security Automation & SOAR Engineer

S&P Global, Inc.

New York (NY)

On-site

USD 140,000 - 155,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health & Wellness
Flexible Downtime
Continuous Learning
Invest in Your Future
Family Friendly Perks
Beyond the Basics

Job summary

S&P Global, Inc. is seeking an experienced security automation engineer in New York to design and implement SOAR playbooks and automated workflows. You will collaborate with SOC, Detection Engineering, and Incident Response teams to translate operational needs into scalable solutions.

The role emphasizes Python development, API integrations, and cloud infrastructure deployment with a focus on AI-enhanced security workflows. Competitive salary and benefits accompany this opportunity.

Qualifications

  • 5+ years of proven experience designing and implementing security automation solutions in enterprise environments with hands‑on SOAR platform expertise and demonstrated leadership in automation initiatives.
  • Strong hands‑on incident response experience with demonstrated ability to translate response procedures into scalable automated workflows.
  • Strong proficiency in Python programming and experience with detection technologies such as YARA, along with REST API development and third‑party service integrations.

Responsibilities

  • Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response
  • Build and maintain secure integrations across a comprehensive ecosystem of security, IT, and business platforms including security tools, identity systems, cloud services, network infrastructure, ticketing systems, and communication platforms using APIs and custom code to support end‑to‑end incident response workflows
  • Lead cross‑functional collaboration with SOC, Detection Engineering, and Incident Response teams to identify automation opportunities and translate operational needs into technical solutions
  • Deploy cloud‑based security infrastructure using infrastructure‑as‑code practices, managing role‑based access controls and supporting disaster recovery initiatives
  • Incorporate cutting‑edge AI technologies including Agentic AI and Large Language Models into security workflows to enhance decision‑making and contextual understanding
  • Produce executive‑level reporting on automation performance metrics and ROI, presenting program effectiveness to leadership while supporting strategic security initiatives

Skills

Python programming
SOAR automation
Incident response
API integration
Security platforms

Tools

Terraform
CloudFormation
Pulumi
Git
Docker

Job description

About the Role

Grade Level (for internal use): 11

The Team

The Cyber Fusion Center protects the business by fusing threat intelligence, monitoring, detection engineering, and response into one proactive, intelligence‑led defense capability that breaks down silos to reduce risk and strengthen security across the enterprise. The team prioritizes collaboration, continuous learning, and innovation, with shared ownership of outcomes and a supportive learning mindset during high‑pressure situations. You'll work in a hands‑on, build‑driven environment with strong team collaboration, rapid learning through real use cases, and clear opportunities to mature automation across the security program.

Responsibilities and Impact
  • Architect and develop SOAR playbooks and automated workflows to streamline incident triage, containment, and remediation processes, directly improving SOC efficiency and reducing mean time to response
  • Build and maintain secure integrations across a comprehensive ecosystem of security, IT, and business platforms including security tools, identity systems, cloud services, network infrastructure, ticketing systems, and communication platforms using APIs and custom code to support end‑to‑end incident response workflows
  • Lead cross‑functional collaboration with SOC, Detection Engineering, and Incident Response teams to identify automation opportunities and translate operational needs into technical solutions
  • Deploy cloud‑based security infrastructure using infrastructure‑as‑code practices, managing role‑based access controls and supporting disaster recovery initiatives
  • Incorporate cutting‑edge AI technologies including Agentic AI and Large Language Models into security workflows to enhance decision‑making and contextual understanding
  • Produce executive‑level reporting on automation performance metrics and ROI, presenting program effectiveness to leadership while supporting strategic security initiatives
What We're Looking For
Basic Required Qualifications
  • 5+ years of proven experience designing and implementing security automation solutions in enterprise environments with hands‑on SOAR platform expertise and demonstrated leadership in automation initiatives.
  • Strong hands‑on incident response experience with demonstrated ability to translate response procedures into scalable automated workflows.
  • Strong proficiency in Python programming and experience with detection technologies such as YARA, along with REST API development and third‑party service integrations.
  • Deep technical expertise across security platforms including SIEM technologies (such as Splunk, Elastic, or Sentinel), SOAR platforms (such as Phantom, XSOAR, or Swimlane), and EDR solutions (such as CrowdStrike, SentinelOne, or Microsoft Defender).
  • Hands‑on experience with cloud infrastructure deployment particularly in AWS environments, using infrastructure‑as‑code tools (such as Terraform, CloudFormation, or Pulumi).
  • Experience with data manipulation and analysis tools (such as Pandas, SQL, or Elasticsearch) for processing high‑volume security telemetry and creating sophisticated automation triggers.
Additional Preferred Qualifications
  • Experience with Google SecOps platform and familiarity with integrating Agentic AI and Large Language Models into security workflows for enhanced automation and decision‑making.
  • Advanced knowledge of identity and access management platforms such as Okta, Microsoft Entra ID, or SailPoint, and email security solutions like Proofpoint or Mimecast.
  • Proven experience in development lifecycle best practices including version control systems (such as Git, GitLab, or Bitbucket), containerization technologies (such as Docker, Podman, or containerd), and CI/CD platforms (such as Jenkins, GitLab CI, or Azure DevOps).
  • Experience with threat intelligence platforms (such as ThreatConnect, Anomali, or MISP) and integrating threat feeds into automated response workflows.
  • Strong presentation and communication skills with demonstrated ability to present metrics, operational insights, and program outcomes to executive leadership and cross‑functional stakeholders.
Compensation and Benefits Information (US Applicants Only)

S&P Global states that the anticipated base salary range for this position is $140,000 to $155,000. Base salary ranges may vary by geographic location.

In addition to base compensation, this role is eligible for additional compensation such as an annual incentive bonus plan.

This role is eligible to receive additional S&P Global benefits.

Benefits

We take care of you, so you can take care of business. We care about our people. That’s why we provide everything you—and your career—need to thrive at S&P Global.

  • Health & Wellness: Health care coverage designed for the mind and body.
  • Flexible Downtime: Generous time off helps keep you energized for your time on.
  • Continuous Learning: Access a wealth of resources to grow your career and learn valuable new skills.
  • Invest in Your Future: Secure your financial future through competitive pay, retirement planning, a continuing education program with a company‑matched student loan contribution, and financial wellness programs.
  • Family Friendly Perks: It’s not just about you. S&P Global has perks for your partners and little ones, too, with some best‑in‑class benefits for families.
  • Beyond the Basics: From retail discounts to referral incentive awards—small perks can make a big difference.
Equal Opportunity Employer

S&P Global is an equal‑opportunity employer and all qualified candidates will receive consideration for employment without regard to race/ethnicity, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, marital status, military veteran status, unemployment status, or any other status protected by law. Only electronic job submissions will be considered for employment.

US Candidates Only: Know Your Rights: Workplace discrimination is illegal.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Automation & SOAR Engineer
Senior Security Automation & SOAR Engineer

S&P Global • Boulder (CO)

On-site
USD 140,000 - 155,000
Health & Wellness
Flexible Downtime
Continuous Learning
+3
Senior Security Automation, SOAR Engineer
Senior Security Automation, SOAR Engineer

Jobtailor • Colorado

On-site
USD 140,000 - 170,000
Senior Security Automation Engineer
Senior Security Automation Engineer

Piper Companies • United States

Remote
USD 130,000 - 145,000
Medical plan
Dental plan
Vision plan
+3
Cybersecurity Automation Engineer – SOAR & SOC Engineering 3643283
Cybersecurity Automation Engineer – SOAR & SOC Engineering 3643283

Axiom Path • Charlotte (NC)

Hybrid
USD 110,000 - 140,000
Security Automation (SOAR) Engineer
Security Automation (SOAR) Engineer

Nava • Reston (VA)

On-site
USD 140,000 - 180,000
Generous medical insurance
Dental insurance paid 100%
Vision insurance paid 100%
+4
Security Automation (SOAR) Engineer
Security Automation (SOAR) Engineer

AnaVation LLC • Reston (VA)

On-site
USD 140,000 - 200,000
Medical insurance
Dental insurance
Disability insurance
+6
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Koitecc Solutions • Denver (CO), Northern (KY)

Hybrid
USD 180,000 - 240,000
SOAR and AI Engineer - Managed Security
SOAR and AI Engineer - Managed Security

Thinkahead • United States

On-site
USD 110,000 - 165,000
Medical, Dental, Vision Insurance
401(k) matching
Paid holidays and PTO
+1
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Washington

On-site
USD 170,000 - 250,000
Senior SOAR & Security Automation Architect
Senior SOAR & Security Automation Architect

S&P Global, Inc. • New York (NY)

On-site
USD 140,000 - 155,000
Health & Wellness
Flexible Downtime
Continuous Learning
+3