Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
EY

Senior Cyber – SOAR Engineer, Security Orchestration, Automation and Response

EY

. Design, develop, and maintain automated security workflows .

Posted 9/15/2026full-timeNew York City • New York • United StatesSenior💰 $104,800 - $192,200 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing and developing automated security workflows, integrating SOAR platforms, and implementing security operations processes. Proficient in scripting and programming for automation, with a strong understanding of cloud environments and security technologies.

Highest-signal resume keywords
SOAR Platform ImplementationPython ScriptingREST API DevelopmentSecurity Operations ProcessesCloud Security Integration

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security AutomationSOAR EngineeringIncident ResponseThreat DetectionVulnerability ManagementAutomation WorkflowsCustom IntegrationsCI/CD ConceptsVersion ControlTesting Methodologies
Soft Skills
Problem-SolvingAnalytical SkillsCollaborationTechnical LeadershipCommunication
Tools & Technologies
Palo Alto Cortex XSOARMicrosoft Sentinel AutomationSplunk SOARGoogle Security OperationsTinesD3 SecuritySwimlaneSIEMEDR/XDRIAM
Certifications & Qualifications
Microsoft Certified: Cybersecurity Architect ExpertMicrosoft SC-200Splunk Core Certified Power UserSecurity+CySA+GSECGCIHCortex XSOAR Engineer
Industry Keywords
CybersecurityCloud EnvironmentsOperational ProcessesTechnical DocumentationIncident Triage

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityD3.jsGoogle Cloud PlatformJavaScriptPythonSplunk

About the role

Key responsibilities & impact
  • Design, develop, and maintain automated security workflows
  • Implement and optimize SOAR platforms by integrating security tools, data sources, and operational processes
  • Collaborate with SOC, Incident Response, Threat Intelligence, Detection Engineering, and Vulnerability Management teams
  • Identify automation opportunities and translate operational requirements into scalable technical solutions
  • Design and develop playbooks for incident triage, enrichment, containment, remediation, and reporting
  • Develop custom integrations, APIs, connectors, and automation capabilities across cloud environments, security platforms, and enterprise applications
  • Integrate SIEM, EDR, IAM, cloud security, threat intelligence, ticketing, and collaboration platforms
  • Contribute to automation standards, reusable frameworks, and engineering best practices
  • Assist clients with SOAR platform deployments, upgrades, and operational enhancements
  • Mentor junior team members and provide technical leadership on security automation initiatives
  • Stay current on cybersecurity threats, automation technologies, cloud-native security capabilities, and SOAR solutions
  • Participate in professional development opportunities, industry forums, technical communities, and relevant training

Requirements

What you’ll need
  • Bachelor’s degree (4-year degree) in Computer Science, Computer Engineering, Cybersecurity, Information Technology, Management Information Systems, or a related field
  • 2–4 years of relevant experience in security automation, SOAR engineering, security operations, cybersecurity engineering, or a related discipline
  • Hands-on experience implementing, administering, or developing enterprise SOAR platforms such as Palo Alto Cortex XSOAR, Microsoft Sentinel Automation, Splunk SOAR (Phantom), Google Security Operations (Chronicle SOAR), Tines, D3 Security, or Swimlane
  • Strong software development and scripting experience using Python, PowerShell, JavaScript, or other automation-focused programming languages
  • Experience developing and consuming REST APIs, web services, SDKs, and custom integrations
  • Knowledge of security operations processes including alert triage, incident response, threat detection, vulnerability management, and case management workflows
  • Experience integrating SIEM, EDR/XDR, IAM, email security, network security, cloud security, vulnerability management, threat intelligence, and ticketing platforms
  • Understanding of infrastructure, networking, operating systems, and cloud environments including Microsoft Azure, AWS, and GCP
  • Experience designing, testing, troubleshooting, and maintaining automation workflows in production environments
  • Knowledge of secure development principles, version control, testing methodologies, and CI/CD concepts
  • Relevant industry certifications such as Microsoft Certified: Cybersecurity Architect Expert, Microsoft SC-200, Splunk Core Certified Power User, Security+, CySA+, GSEC, GCIH, Cortex XSOAR Engineer, or similar, or ability to acquire certification after employment
  • Advanced problem-solving and critical thinking skills
  • Strong analytical and troubleshooting skills
  • Ability to create high-quality work products, technical documentation, client reports, and presentations
  • Ability to work collaboratively in a culturally diverse and geographically dispersed cross-functional team
  • Ability to balance security, operational efficiency, and engineering best practices

Benefits

Comp & perks
  • Medical and dental coverage
  • Pension plan
  • 401(k) plan
  • Wide range of paid time off options
  • Professional growth opportunities
  • Inclusive culture
  • Reasonable accommodation for qualified individuals with disabilities