Cyber - SOAR (Security Orchestration, Automation and Response) Engineer - Senior - Consulting
Job description
Location: Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
The Opportunity
In a rapidly evolving cybersecurity landscape, organizations are facing increasingly sophisticated threats while simultaneously managing growing security operations workloads. Clients across industries look to us for innovative solutions that improve efficiency, enhance visibility, and strengthen cyber resilience through automation and orchestration.
Join our dynamic team as a Senior SOAR Engineer, where you'll play a key role in designing, implementing, and optimizing security automation solutions that enable organizations to respond to threats faster and more effectively. You will work closely with security operations, incident response, threat detection, and engineering teams to automate repetitive tasks, orchestrate complex workflows, and integrate a wide range of security technologies. Your expertise in security automation, scripting, and platform engineering will help clients mature their security operations, reduce response times, and maximize the value of their cybersecurity investments.
Your Key Responsibilities
As a Senior on the Security Orchestration, Automation and Response (SOAR) team, your key responsibilities would include designing, developing, and maintaining automated security workflows that enhance the effectiveness and efficiency of security operations. You will be responsible for implementing and optimizing SOAR platforms by integrating security tools, data sources, and operational processes across the cybersecurity ecosystem. Your role will involve collaborating with Security Operations Center (SOC), Incident Response, Threat Intelligence, Detection Engineering, and Vulnerability Management teams to identify automation opportunities and translate operational requirements into scalable technical solutions. You will design and develop playbooks that automate incident triage, enrichment, containment, remediation, and reporting activities while ensuring reliability, maintainability, and security of automation workflows. You will leverage programming and scripting languages to develop custom integrations, APIs, connectors, and automation capabilities across cloud environments, security platforms, and enterprise applications. This may include integrating SIEM, EDR, IAM, cloud security, threat intelligence, ticketing, and collaboration platforms to facilitate seamless orchestration across complex security architectures. You will also contribute to the development of automation standards, reusable frameworks, and engineering best practices while assisting clients with SOAR platform deployments, upgrades, and operational enhancements. Additionally, as a senior engineer, you will mentor junior team members, provide technical leadership on security automation initiatives, and contribute to the continued growth of the cybersecurity engineering practice. In addition to these responsibilities, you will be expected to stay current on emerging cybersecurity threats, automation technologies, cloud-native security capabilities, and evolving SOAR solutions. You will actively participate in professional development opportunities, industry forums, technical communities, and relevant training to maintain expertise in modern security operations and automation engineering.
Skills and Attributes for Success
To thrive in this role, you'll need a combination of advanced technical engineering expertise, security operations knowledge, and strong consulting skills. Your professional knowledge and experience will guide you in designing scalable solutions, solving complex technical challenges, and delivering high-quality outcomes for clients.
- Demonstrate advanced problem-solving and critical thinking skills.
- Exhibit strong software engineering and automation development capabilities.
- Foster a collaborative learning environment and mentor junior team members.
- Possess the ability to identify and communicate opportunities to improve security operations through automation and orchestration.
- Demonstrate experience designing scalable and maintainable integrations across complex technology environments.
- The ability to create and deliver high-quality work products, technical documentation, client reports, and presentations.
- Adherence to service quality standards and program management requirements.
- The ability to work collaboratively in a cross-functional team environment that is culturally diverse and geographically dispersed.
- Strong analytical and troubleshooting skills, with the ability to diagnose and resolve complex integration and workflow issues.
- The ability to balance security, operational efficiency, and engineering best practices when developing automation solutions.
To Qualify for the Role, You Must Have:
- A Bachelor’s degree (4-year degree) in Computer Science, Computer Engineering, Cybersecurity, Information Technology, Management Information Systems, or a related field, along with 2-4 years of relevant experience in security automation, SOAR engineering, security operations, cybersecurity engineering, or a related discipline.
- Hands-on experience implementing, administering, or developing solutions within enterprise SOAR platforms such as Palo Alto Cortex XSOAR, Microsoft Sentinel Automation, Splunk SOAR (Phantom), Google Security Operations (Chronicle SOAR), Tines, D3 Security, Swimlane, or similar technologies.
- Strong software development and scripting experience using languages such as Python, PowerShell, JavaScript, or other automation-focused programming languages.
- Experience developing and consuming REST APIs, web services, SDKs, and custom integrations.
- Knowledge of security operations processes including alert triage, incident response, threat detection, vulnerability management, and case management workflows.
- Experience integrating cybersecurity technologies such as SIEM, EDR/XDR, IAM, email security, network security, cloud security, vulnerability management, threat intelligence, and ticketing platforms.
- Understanding of infrastructure, networking, operating systems, and cloud environments including Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
- Experience designing, testing, troubleshooting, and maintaining automation workflows in production environments.
- Knowledge of secure development principles and software engineering best practices including version control, testing methodologies, and CI/CD concepts.
- Relevant industry certifications such as Microsoft Certified: Cybersecurity Architect Expert, Microsoft SC-200, Splunk Core Certified Power User, Security+, CySA+, GSEC, GCIH, Cortex XSOAR Engineer, or similar certifications, or the ability to acquire certification after employment.
Ideally, You'll Also Have
- Experience architecting enterprise-scale SOAR implementations and security automation programs.
- Experience developing custom integrations, reusable automation frameworks, and advanced workflow orchestration solutions.
- Familiarity with Infrastructure as Code (IaC) technologies such as Terraform, ARM templates, Bicep, or CloudFormation.
- Experience working with DevSecOps, CI/CD pipelines, and cloud-native automation technologies.
- The ability to communicate effectively during technical workshops, architecture reviews, client interviews, and executive briefings.
- Exemplary writing skills and the ability to communicate complex technical concepts to both technical and non-technical audiences.
- The ability to translate operational requirements into automation strategies, technical designs, and implementation roadmaps.
- The ability to break down complex engineering challenges into manageable components, estimate level-of-effort, and deliver solutions within tight timelines.
- Proficiency with consulting engagement methodologies and approaches, understanding how to align technical solutions with client business objectives.
- Familiarity with emerging security automation trends, AI-assisted security operations, and modern cybersecurity technologies.
What We Look For
We seek top performers with a passion for cybersecurity engineering and automation, combined with a proven track record of delivering innovative technical solutions. Ideal candidates are individuals who demonstrate strong engineering expertise, learning agility, critical thinking, and the ability to work collaboratively in a fast-paced environment. We value professionals who are motivated by solving complex challenges, improving security operations through automation, and helping clients strengthen their cyber defenses through modern engineering practices.
What we offer you
At EY, we harness our collective strength to empower you to shape your future with confidence through professional growth, personal fulfillment and an inclusive culture. Learn more at ey.com/us/careers.
- The salary range for this job is:
- New York City, Boston, and Washington DC Metro Areas, Washington State, and Southern California offices – $125,800 to $209,700
- Bay Area California offices – $131,100 to $218,500
- All other offices locations in the US, including Sacramento – $104,800 to $192,200
- Individual salaries within these ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
Are you ready to shape your future with confidence? Apply today.
- To make the most of your application experience, please limit yourself to two applications within a six-month period.
- EY accepts applications for this position on an on-going basis.
- For those living in California, please click here for additional information.
- At EY, our values set the foundation for how we work and the behaviors we expect of our people. Any misrepresentation or falsification of information or lack of integrity at any point in the recruiting process may result in withdrawal of your candidacy, revocation of an offer or immediate termination of employment.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
All in to shape the future with confidence.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY’s Talent Shared Services Team (TSS) or email the TSS at ssc.customersupport@ey.com.