Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
EY

Cyber Security Orchestration, Automation and Response Engineer – Manager

EY

. Lead end-to-end SOAR and security automation engagements from discovery and strategy through architecture, implementation, testing, deployment, and operational transition .

Posted 9/15/2026full-timeNew York City • New York • United StatesMid-LevelSenior💰 $144,900 - $302,100 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading security automation and SOAR implementations, with a strong focus on solution architecture, integration of security technologies, and development of automation workflows. Proficient in managing multidisciplinary teams and delivering client-facing engagements while ensuring adherence to engineering standards and governance controls.

Highest-signal resume keywords
Security AutomationSOAR EngineeringPython ScriptingEnterprise SOAR PlatformsSOC Processes

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security AutomationSOAR EngineeringPythonPowerShellJavaScriptREST APIsCloud SecurityIncident ResponseVulnerability ManagementAutomation Workflows
Soft Skills
Team LeadershipClient EngagementCommunicationRisk ManagementStakeholder Management
Tools & Technologies
Palo Alto Cortex XSOARMicrosoft Sentinel AutomationSplunk SOARGoogle Security OperationsTinesD3 SecuritySwimlaneSIEMEDR/XDRIAM
Certifications & Qualifications
Relevant Industry Certifications
Industry Keywords
CybersecurityAutomation TechnologiesCloud-Native SecurityAI-Assisted Security OperationsGovernance Controls

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityD3.jsGoogle Cloud PlatformJavaScriptPythonSplunkTerraform

About the role

Key responsibilities & impact
  • Lead end-to-end SOAR and security automation engagements from discovery and strategy through architecture, implementation, testing, deployment, and operational transition
  • Advise clients on automation strategy, operating models, governance, platform selection, capability roadmaps, and SOC effectiveness
  • Own solution architecture and delivery quality for enterprise SOAR implementations
  • Direct the design and development of playbooks for incident triage, enrichment, investigation, containment, remediation, case management, and reporting
  • Oversee integrations across SIEM, EDR/XDR, IAM, cloud security, threat intelligence, vulnerability management, email security, network security, ticketing, and collaboration platforms
  • Provide technical oversight for custom integrations, APIs, connectors, reusable frameworks, and cloud-native automation capabilities
  • Facilitate executive briefings, architecture reviews, technical workshops, stakeholder interviews, and requirements sessions
  • Manage engagement scope, workplans, risks, dependencies, staffing, financial performance, and delivery milestones
  • Establish engineering standards, governance controls, testing practices, documentation expectations, and production support models
  • Lead, coach, and develop multidisciplinary teams
  • Identify follow-on opportunities, contribute to proposals and statements of work, support solution development, and help grow the security automation practice
  • Maintain awareness of emerging threats, AI-assisted security operations, automation technologies, cloud-native security capabilities, and evolving SOAR platforms

Requirements

What you’ll need
  • Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Information Technology, Management Information Systems, or a related field
  • 6–10 years of relevant experience in security automation, SOAR engineering, security operations, cybersecurity engineering, or a related discipline
  • Experience leading teams or workstreams responsible for designing and delivering enterprise security automation or SOAR solutions
  • Hands-on experience with enterprise SOAR platforms such as Palo Alto Cortex XSOAR, Microsoft Sentinel Automation, Splunk SOAR, Google Security Operations, Tines, D3 Security, Swimlane, or comparable technologies
  • Strong software development and scripting experience using Python, PowerShell, JavaScript, or other automation-focused languages
  • Experience designing and consuming REST APIs, web services, SDKs, and custom integrations
  • Strong knowledge of SOC processes, including alert triage, incident response, threat detection, threat intelligence, vulnerability management, and case management
  • Experience integrating security technologies across SIEM, EDR/XDR, IAM, email, network, cloud, vulnerability management, threat intelligence, ticketing, and collaboration platforms
  • Understanding of infrastructure, networking, operating systems, and major cloud platforms, including Microsoft Azure, Amazon Web Services, and Google Cloud Platform
  • Experience designing, testing, troubleshooting, operationalizing, and governing automation workflows in production environments
  • Knowledge of secure development practices, version control, testing methodologies, CI/CD concepts, and software engineering standards
  • Ability to lead client-facing engagements, manage delivery risks, and communicate recommendations to senior stakeholders
  • Relevant industry or platform certifications, or the ability to obtain an applicable certification after employment
  • Ideally: experience architecting enterprise-scale SOAR implementations and establishing security automation programs or centers of enablement
  • Ideally: experience developing reusable automation frameworks, advanced orchestration solutions, and platform governance standards
  • Ideally: familiarity with Infrastructure as Code technologies such as Terraform, ARM templates, Bicep, or CloudFormation
  • Ideally: experience with DevSecOps, CI/CD pipelines, cloud-native automation, containers, and serverless technologies
  • Ideally: experience defining automation use-case portfolios, prioritization criteria, value metrics, and adoption roadmaps
  • Ideally: ability to translate operational requirements into target-state architectures, implementation roadmaps, estimates, and business cases
  • Ideally: experience with consulting engagement methodologies, proposal development, statements of work, and executive-level presentations
  • Ideally: familiarity with AI-assisted security operations, generative AI use cases, and responsible automation controls

Benefits

Comp & perks
  • Medical and dental coverage
  • Pension plan
  • 401(k) plan
  • Wide range of paid time off options
  • Professional growth
  • Inclusive culture
  • Reasonable accommodation for qualified individuals with disabilities, including veterans with disabilities