Senior SOAR Engineer - Onsite

BlackCube Labs

Chicago (IL)

On-site

USD 96,000 - 107,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health Savings Account
Medical, Dental, Vision
401K
Commuter Benefits

Job summary

Genesis10 is seeking a Senior SOAR Engineer for an onsite, 12+ month contract in Chicago area(s). The role focuses on migrating and optimizing SOAR capabilities, with heavy emphasis on Splunk SOAR playbooks, integrations, and Python-based automation.

Responsibilities include building and maintaining playbooks, integrations, and automation workflows, while ensuring security compliance and documentation. The ideal candidate has 5+ years in security automation and strong SPL, APIs, and scripting

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience preferred
  • 5+ years of experience in security engineering, security automation, or SOAR development
  • Hands-on experience with Splunk SOAR, including playbook development, custom app development, custom function development, and platform administration/troubleshooting
  • Strong Python programming skills
  • Experience writing and optimizing SPL queries
  • Experience integrating security technologies through APIs, webhooks, and automation frameworks
  • Strong documentation and technical writing skills
  • Experience managing and maintaining integration inventories and system dependencies
  • Strong analytical, troubleshooting, and problem-solving skills

Responsibilities

  • Migration, implementation, and optimization of SOAR platforms and automation capabilities
  • Design, develop, test, and maintain Splunk SOAR playbooks, custom applications, and custom functions
  • Create and manage integrations between security tools, IT systems, cloud platforms, and third-party technologies
  • Develop and maintain Python-based automation solutions to support security operations and incident response
  • Utilize SPL to support automation workflows, investigations, and reporting
  • Maintain ownership of the orchestration and integration inventory, ensuring accuracy and alignment with operational requirements
  • Identify opportunities to automate repetitive security processes and improve response efficiency
  • Collaborate with SOC, IR, Engineering, and Infrastructure teams to improve security workflows
  • Perform troubleshooting and root cause analysis of automation failures and integration issues
  • Develop and maintain technical documentation, architecture diagrams, operational procedures, and knowledge articles
  • Ensure solutions adhere to security, compliance, and governance requirements
  • Participate in platform upgrades, testing, and continuous improvement efforts

Skills

Splunk SOAR
Python
SPL
REST APIs
Webhooks
Automation
Documentation
Integration inventories
Splunk

Education

Bachelor's degree in Cybersecurity/CS/IT or related field

Tools

Splunk SOAR
Splunk Enterprise Security

Job description

Genesis10 is currently seeking a Senior SOAR Engineer - Onsite for a 12+ month contract opportunity with a Global Financial Institution located in Chicago, IL, Denver, CO, Washington, DC, or Jersey City, NJ.


This role is responsible for designing, developing, and supporting security orchestration, automation, and response (SOAR) capabilities, with a primary focus on SOAR migration initiatives. The ideal candidate has deep expertise in Splunk SOAR, Python development, and security automation, and will be responsible for the development and optimization of automated incident response workflows, integrations, and orchestration processes.


Responsibilities:


  • Migration, implementation, and optimization of SOAR platforms and automation capabilities

  • Design, develop, test, and maintain Splunk SOAR playbooks, custom applications, and custom functions

  • Create and manage integrations between security tools, IT systems, cloud platforms, and third-party technologies

  • Develop and maintain Python-based automation solutions to support security operations and incident response

  • Utilize Splunk Processing Language (SPL) to support automation workflows, investigations, and reporting

  • Maintain ownership of the organization's orchestration and integration inventory, ensuring accuracy and alignment with operational requirements

  • Identify opportunities to automate repetitive security processes and improve response efficiency

  • Collaborate with Security Operations Center (SOC), Incident Response, Engineering, and Infrastructure teams to improve security workflows

  • Perform troubleshooting and root cause analysis of automation failures and integration issues

  • Develop and maintain technical documentation, architecture diagrams, operational procedures, and knowledge articles

  • Ensure solutions adhere to security, compliance, and governance requirements

  • Participate in platform upgrades, testing, and continuous improvement efforts


Requirements:


  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent experience preferred

  • 5+ years of experience in security engineering, security automation, or SOAR development

  • Hands-on experience with Splunk SOAR, including playbook development, custom app development, custom function development, and platform administration/troubleshooting

  • Strong Python programming skills

  • Experience writing and optimizing SPL queries

  • Experience integrating security technologies through APIs, webhooks, and automation frameworks

  • Strong documentation and technical writing skills

  • Experience managing and maintaining integration inventories and system dependencies

  • Strong analytical, troubleshooting, and problem-solving skills


Desired skills:


  • Experience with enterprise SOAR migration projects

  • Knowledge of security operations, incident response, and threat detection workflows

  • Experience with SIEM platforms, particularly Splunk Enterprise Security

  • Familiarity with cloud environments (AWS, Azure, or GCP)

  • Knowledge of REST APIs, JSON, and modern integration patterns

  • Relevant cybersecurity certifications (e.g., Splunk, Security+, CISSP, GSEC, GIAC certifications)


Pay range:

$70.25 - $78.25 per hour


Only candidates available and ready to work directly as Genesis10 employees will be considered for this position.


Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals.


For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10:



  • Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years.

  • The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years.

  • Access to an experienced, caring recruiting team (more than 7 years of experience, on average.)

  • Behavioral Health Platform

  • Medical, Dental, Vision

  • Health Savings Account

  • Voluntary Hospital Indemnity (Critical Illness & Accident)

  • Voluntary Term Life Insurance

  • 401K

  • Sick Pay (for applicable states/municipalities)

  • Commuter Benefits (Dallas, NYC, SF, and Illinois)


For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website.


Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOAR Engineer/Developer - Onsite
SOAR Engineer/Developer - Onsite

BlackCube Labs • Chicago (IL)

On-site
USD 96,000 - 107,000
Medical, Dental, Vision
401K
Sick Pay
+2
SOAR Engineer - ITSM Integrations - Onsite
SOAR Engineer - ITSM Integrations - Onsite

BlackCube Labs • Chicago (IL)

On-site
USD 96,000 - 107,000
Medical, Dental, Vision
401K
Commuter Benefits
Senior SOAR Engineer - ServiceNow Integrations - Onsite
Senior SOAR Engineer - ServiceNow Integrations - Onsite

BlackCube Labs • Chicago (IL)

On-site
USD 97,000 - 108,000
Medical
Dental
Vision
+3
Senior SOAR Engineer - Splunk Automation & Migration
Senior SOAR Engineer - Splunk Automation & Migration

BlackCube Labs • Chicago (IL)

On-site
USD 96,000 - 107,000
Health Savings Account
Medical, Dental, Vision
401K
+1
SOAR Engineer & Developer: REST-Python Integrations
SOAR Engineer & Developer: REST-Python Integrations

BlackCube Labs • Chicago (IL)

On-site
USD 96,000 - 107,000
Medical, Dental, Vision
401K
Sick Pay
+2
SOAR Engineer [Job ID 20260918]
SOAR Engineer [Job ID 20260918]

Socket.dev • Washington

On-site
USD 110,000 - 170,000
SOAR Engineer [Job ID 20260918]
SOAR Engineer [Job ID 20260918]

phoenixcybersecurity • Washington

On-site
USD 90,000 - 130,000
SOAR Engineer [Job ID 20260918]
SOAR Engineer [Job ID 20260918]

Phoenix Cyber • Arlington (VA)

On-site
USD 110,000 - 150,000
SOAR Engineer [Job ID 20260918]
SOAR Engineer [Job ID 20260918]

Phoenix Cyber • Columbia (MD)

On-site
USD 110,000 - 170,000
SOAR Engineer [Job ID 20260918]
SOAR Engineer [Job ID 20260918]

Phoenix Cyber • Washington

On-site
USD 110,000 - 150,000