Senior SOAR Engineer
Senior SOAR Engineer - Cyber Security Engineering
We are seeking an experienced Senior SOAR Engineer to lead the engineering, administration, and strategic enhancement of the Security Orchestration, Automation, and Response (SOAR) platform within a global investment banking environment. This role will serve as the technical owner of the SOAR ecosystem, ensuring platform resilience, operational efficiency, and alignment with enterprise cyber security frameworks.
The successful candidate will act as the primary technical authority for SOAR engineering, driving architecture, integrations, platform governance, and automation maturity across security operations.
Core Responsibilities
- Serve as the lead technical expert for SOAR engineering and security automation initiatives.
- Own end-to-end design, deployment, configuration, maintenance, and optimization of the Chronicle SOAR platform.
- Develop, maintain, and enhance SOAR architecture documentation, including:
- High-Level Design (HLD)
- Low-Level Design (LLD)
- Operational procedures
- Governance standards
- Design and implement integrations between SOAR and enterprise security technologies such as SIEM, EDR, IAM, threat intelligence, and cloud-native tools.
- Build, manage, and improve playbooks, automation workflows, and response capabilities.
- Establish and oversee platform life cycle management, including:
- Version control
- Patch management
- Change control
- Platform resilience
- Compliance adherence
- Partner closely with SOC, DevOps, Cloud, and Security Engineering teams to improve scalability, automation, and service reliability.
- Ensure platform security aligns with industry frameworks and regulatory standards.
Required Experience & Skills
- Extensive hands-on experience with Chronicle SOAR deployment, engineering, administration, and support
- Strong Scripting and automation expertise in:
- Python
- PowerShell
- JavaScript
- Proven experience with cloud platforms:
- Google Cloud Platform (GCP)
- Microsoft Azure
- Deep understanding of cyber security frameworks and methodologies:
- MITRE ATT&CK
- NIST Cybersecurity Framework
- Strong knowledge of SOAR integrations, API development, and enterprise security operations
Preferred Qualifications
- Experience within Banking, Financial Services, or highly regulated enterprise environments
- Relevant cloud certifications (especially GCP)
- Linux systems administration experience
- Familiarity with DevOps and Infrastructure-as-Code tools:
- Terraform
- CI/CD pipelines
- Exposure to machine learning, AI, or advanced data tooling within GCP security environments
- Experience working in Agile, Scrum, or iterative engineering frameworks