SOAR Engineer, Senior

Reposted 3 Hours Ago
Be an Early Applicant
Bethesda, MD, USA
In-Office
87K-198K Annually
Senior level
Information Technology
We use the most advanced technologies to build what nobody else can. Making America stronger, safer, faster. Learn more!
The Role
Designs, implements, and maintains SOAR systems, Splunk SOAR playbooks, and phishing automation pipelines using Cofense Triage. Automates incident response, triage, enrichment, containment, and remediation workflows. Provides security architecture support across Zero Trust, TIC 3.0, EDR, and SASE initiatives. Collaborates with SOC, incident response, and architecture teams to improve enterprise detection and response capabilities, while documenting procedures and mentoring team members.
Summary Generated by Built In
SOAR Engineer, Senior

The Opportunity:

Design, implement, integrate, and maintain systems and tools to automate complex cyber activities. Apply advanced consulting skills, extensive technical expertise, and full industry knowledge. Develop innovative solutions to complex problems. Work without considerable direction. Mentor and may supervise team members. Support a mature Security Operations Center by engineering, automating, and optimizing incident response capabilities across the enterprise. Design, implement, and maintain Splunk SOAR playbooks to streamline analyst workflows, reduce manual effort, and improve response consistency. Develop and maintain phishing automation pipelines using Cofense Triage and Splunk SOAR, ensuring rapid triage, enrichment, and disposition of email‑based threats. Provide cybersecurity architecture and engineering support across initiatives such as Zero‑Trust, TIC 3.0, endpoint detection and response (EDR), and secure access service edge (SASE), contributing to the design and enhancement of enterprise security controls. Collaborate closely with SOC analysts, IR teams, and security architects to strengthen detection, response, and automation capabilities while advancing the organization’s overall security posture.

You Have:

  • 6+ years of experience in cybersecurity engineering, including performing orchestration, automation, and remediation

  • Experience implementing and maintaining Splunk SOAR playbooks, modern coding languages including Python, and writing Splunk Processing Language (SPL) queries

  • Experience with enterprise security technologies such as EDR, SIEM, firewalls, or identity security platforms

  • Knowledge of incident response processes, including triage, enrichment, containment, and documentation

  • Knowledge of Zero Trust principles, TIC 3.0 concepts, or modern security architecture frameworks

  • Ability to write clear technical documentation, playbooks, and engineering procedures for SOC and IR teams

  • Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements

  • Bachelor’s degree

Nice If You Have:

  • Experience with Splunk Enterprise, including data onboarding, correlation searches, and dashboard development

  • Experience with SASE architecture, secure remote access, or cloud-based security controls

  • Experience with automation scripting, including Python, PowerShell, or Bash, to support SOAR or IR workflows

  • Knowledge of threat intelligence enrichment, indicator management, and automated response logic

  • Knowledge of NIST 800 61, MITRE ATT&CK, or other IR frameworks

  • Possession of excellent communication skills for collaborating with analysts, engineers, and leadership

  • Splunk SOAR Certified Automation Developer, Splunk Core Certified Power User or Admin, CySA+, GIAC Certified Incident Handler (GCIH), CISSP, or other equivalent industry Certifications

Vetting:

Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client. 

Compensation

At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.

Salary at Booz Allen is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $86,800.00 to $198,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen’s total compensation package for employees. This posting will close within 90 days from the Posting Date.

Identity Statement

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Candidate AI Usage Policy

AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.

Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.

  • Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.

  • Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.

  • Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.

Skills Required

  • 6+ years of experience in cybersecurity engineering, including orchestration, automation, and remediation via Splunk SOAR
  • Experience implementing and maintaining Splunk SOAR playbooks
  • Experience with Python and Splunk Processing Language queries
  • Experience with enterprise security technologies such as EDR, SIEM, firewalls, or identity security platforms
  • Knowledge of incident response processes, including triage, enrichment, containment, and documentation
  • Knowledge of Zero Trust principles, TIC 3.0 concepts, or modern security architecture frameworks
  • Ability to write technical documentation, playbooks, and engineering procedures
  • Public Trust determination
  • Bachelor's degree
  • Experience with Splunk Enterprise, including data onboarding, correlation searches, and dashboard development
  • Experience with SASE architecture, secure remote access, or cloud-based security controls
  • Experience with Python, PowerShell, or Bash automation scripting
  • Knowledge of threat intelligence enrichment, indicator management, and automated response logic
  • Knowledge of NIST 800-61, MITRE ATT&CK, or other incident response frameworks
  • Excellent communication skills
  • Splunk SOAR Certified Automation Developer, Splunk Core Certified Power User or Admin, CySA+, GCIH, CISSP, or equivalent certification

Booz Allen Hamilton Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Booz Allen Hamilton and has not been reviewed or approved by Booz Allen Hamilton.

  • Retirement Support Retirement benefits are anchored by a dollar‑for‑dollar 401(k) match with immediate vesting and complemented by an employee stock purchase plan. Feedback suggests these features strengthen long‑term financial security beyond base pay.
  • Healthcare Strength Health coverage spans medical, dental, vision, life, disability, mental health, and wellness incentives, with multiple plan options. Tax‑advantaged accounts and wellness contributions further enhance the breadth of coverage.
  • Leave & Time Off Breadth Time‑off benefits include paid holidays, PTO that grows with tenure, and paid parental leave with additional unpaid time available. Flexible scheduling and remote options support work‑life balance alongside formal leave.

Booz Allen Hamilton Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: McLean, VA
Year Founded: 1914

What We Do

Booz Allen is an advanced technology company delivering outcomes with speed for America’s most critical defense, civil, and national security priorities. We build technology solutions using AI, cyber, and other cutting-edge technologies to advance and protect the nation and its citizens. By focusing on outcomes, we enable our people, clients, and their missions to succeed—accelerating the nation to realize our purpose: Empower People to Change the World®.

Why Work With Us

At Booz Allen, our culture of heart and performance will fuel your growth and empower you to succeed, both inside and outside of the workplace. Discover your future career and join us. The world can't wait.

Similar Jobs

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Support Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Hanover, MD, USA
16000 Employees
15-22 Hourly

Samsara Logo Samsara

Sales Operations Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
95K-144K Annually

Apryse Logo Apryse

Technical Writer

Productivity • Software • App development • Automation
In-Office or Remote
12 Locations
665 Employees
90K-130K Annually

Bestow Logo Bestow

Senior Data Analyst

Big Data • Fintech • Information Technology • Insurance • Software
Remote or Hybrid
US
160 Employees
115K-135K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account