SOAR Automation Engineer

Dragonfli Group

Washington (District of Columbia)

Remote

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, dental, and vision insurance
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match

Job summary

A cybersecurity and IT consulting firm seeks a Mid-Senior level SOAR Automation Engineer to design, implement, and scale security automation for a federal agency. This fully remote role involves using Splunk Phantom to enhance security operations and integrate AI services. The ideal candidate has extensive experience in SOAR automation, excellent problem-solving skills, and a strong background in cybersecurity. The position offers competitive benefits, including health insurance, PTO, and 401(k) matching.

Qualifications

  • 4+ years of experience building and supporting SOAR/security automation solutions in enterprise environments.
  • Hands-on experience with Splunk Phantom (Splunk SOAR).
  • Strong background in security workflow automation and playbook development.
  • Experience integrating cloud and on-premise systems via APIs.
  • Working familiarity with Azure AI services and applied AI use cases in cybersecurity.
  • Strong problem-solving and analytical skills.
  • Ability to collaborate across technical and non-technical teams.
  • Excellent written and verbal communication skills.

Responsibilities

  • Design, build, and maintain SOAR automation using Splunk Phantom.
  • Develop and enhance automated playbooks to support detection, response, and investigation workflows.
  • Integrate SOAR with SIEM, security tools, cloud platforms, and on-prem systems.
  • Apply AI-enabled enrichment and decision support using Azure AI services.
  • Lead automation design decisions and guide SOC teams on effective SOAR usage.
  • Improve dashboards, metrics, and operational visibility tied to automated workflows.
  • Collaborate with security analysts, engineers, and stakeholders to identify automation opportunities.
  • Operationalize and scale automation across the security lifecycle.
  • Ensure reliability, maintainability, and documentation of automation solutions.

Skills

SOAR and AI technologies
Technical and analytical skills
Ability to work collaboratively with security teams
Automated security workflows
Cloud and on-premise system integration
Communication and planning abilities
Problem-solving and critical thinking
Cybersecurity frameworks and standards

Education

Bachelor’s degree in a cyber-related field or equivalent

Tools

Splunk Phantom
Azure AI services
APIs

Job description

Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission‑critical systems across on‑site, hybrid, and fully remote environments.

This SOAR Automation Engineer role supports a large U.S. federal agency by designing, implementing, and scaling security automation capabilities across a complex enterprise environment. The role is centered on Splunk Phantom (Splunk SOAR) and focuses on automating security operations, improving response and investigation workflows, and integrating AI‑enabled enrichment using Azure AI services where appropriate.

This is a hands‑on technical role with strategic influence, combining deep engineering work with ownership of automation design and continuous improvement across SOC workflows.

This is a W2 contract, fully remote (CONUS only) role, supporting a large federal agency. Prior federal contracting experience is preferred.

U.S. Citizenship or Permanent Residency is required.

Responsibilities
  • Design, build, and maintain SOAR automation using Splunk Phantom
  • Develop and enhance automated playbooks to support detection, response, and investigation workflows
  • Integrate SOAR with SIEM, security tools, cloud platforms, and on‑prem systems
  • Apply AI‑enabled enrichment and decision support using Azure AI services
  • Lead automation design decisions and guide SOC teams on effective SOAR usage
  • Improve dashboards, metrics, and operational visibility tied to automated workflows
  • Collaborate with security analysts, engineers, and stakeholders to identify automation opportunities
  • Operationalize and scale automation across the security lifecycle
  • Ensure reliability, maintainability, and documentation of automation solutions
Requirements

Must-Have

  • 4+ years of experience building and supporting SOAR / security automation solutions in enterprise environments
  • Hands‑on experience with Splunk Phantom (Splunk SOAR)
  • Strong background in security workflow automation and playbook development
  • Experience integrating cloud and on‑premise systems via APIs
  • Working familiarity with Azure AI services and applied AI use cases in cybersecurity
  • Strong problem‑solving and analytical skills
  • Ability to collaborate across technical and non‑technical teams
  • Excellent written and verbal communication skills
  • Bachelor’s degree in a cyber‑related field or equivalent experience/certifications

Nice-To-Have

  • Federal cybersecurity environments
  • SOC operations and incident response workflows
  • Python or scripting for automation
  • SIEM integration (Splunk Enterprise / Splunk ES)
  • Familiarity with NIST cybersecurity frameworks
Skills
  • Expertise in SOAR and AI technologies
  • Strong technical and analytical skills
  • Ability to work collaboratively with security teams
  • Proficiency in developing automated security workflows
  • Experience with cloud and on‑premise system integration
  • Strong communication and planning abilities
  • Problem‑solving and critical thinking skills
  • Familiarity with cybersecurity frameworks and standards
Benefits
  • Insurance – health, dental, and vision
  • Paid Time Off (PTO) and 11 Federal Holidays
  • 401(k) employer match
Seniority Level

Mid‑Senior level

Employment Type

Full‑time

Job Function

Engineering and Information Technology

Industries

IT Services and IT Consulting

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote SOAR Automation Engineer - Splunk Phantom
Remote SOAR Automation Engineer - Splunk Phantom

Dragonfli Group • Washington

Remote
USD 120,000 - 160,000
Health, dental, and vision insurance
Paid Time Off (PTO) and 11 Federal Holidays
401(k) employer match
Senior Security Automation Engineer
Senior Security Automation Engineer

Piper Companies • United States

Remote
USD 130,000 - 145,000
Medical plan
Dental plan
Vision plan
+3
Senior Security Automation & SOAR Engineer
Senior Security Automation & SOAR Engineer

S&P Global, Inc. • New York (NY)

On-site
USD 140,000 - 155,000
Health & Wellness
Flexible Downtime
Continuous Learning
+3
SOAR Engineer
SOAR Engineer

MSM Technology, LLC • Scott Air Force Base (IL)

On-site
USD 90,000 - 130,000
Senior Security Automation, SOAR Engineer
Senior Security Automation, SOAR Engineer

Jobtailor • Colorado

On-site
USD 140,000 - 170,000
Security Incident Response Orchestration Lead
Security Incident Response Orchestration Lead

Bank of America • Washington

On-site
USD 170,000 - 250,000
Remote SOAR Developer/Engineer
Remote SOAR Developer/Engineer

WaveStrong, Inc. • Town of Texas (WI)

Remote
USD 80,000 - 100,000
SOAR Engineer [Job ID 20260707]
SOAR Engineer [Job ID 20260707]

Phoenix Cyber • Salt Lake City (UT)

Remote
USD 90,000 - 130,000
Senior SOAR Engineer - Remote Security Orchestration
Senior SOAR Engineer - Remote Security Orchestration

Phoenix Cyber • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Security Automation (SOAR) Engineer
Security Automation (SOAR) Engineer

AnaVation LLC • Reston (VA)

On-site
USD 140,000 - 200,000
Medical insurance
Dental insurance
Disability insurance
+6