SOAR Engineer (SPLUNK)

Posted 6 Hours Ago
Be an Early Applicant
Hiring Remotely in GBR
Remote
Senior level
Information Technology • Professional Services • Software • Cybersecurity
The Role
Design, build and maintain Splunk-based SOAR automations and playbooks to detect, investigate and respond to cyber threats. Partner with Incident Response to develop use cases, validate automation behaviour, produce analytics, document changes, perform QA, and mentor junior engineers.
Summary Generated by Built In
The Senior SOAR Engineer designs, builds and maintains security automations that detect, investigate and respond to cyber threats. The role works closely with Incident Response to identify improvements, create new playbooks and deliver scalable automation within the Splunk ecosystem. Responsibilities include advanced analytics, scripting, creating new use cases, validating automation behaviour, documenting changes and mentoring junior engineers. 

Key Responsibilities
  • Work in partnership with the incident response team to design, identify, and implement opportunities for improvement 
  • Develop, and implement automations for detection and response. 
  • Be the subject matter experts on big data analytics and automation 
  • Participate in special projects, as needed, and perform other duties as assigned 
  • Produce System Analytics to prove automation behaviour assumptions 
  • Document all system changes in line with Change Management good practices 
  • Recommend, Develop and Release new Use Cases to maximize the benefits and efficiencies from a SOAR platform. 
  • Mentor junior members of the SOAR team. 
  • Complete Quality Assurance on work completed by other members of the team before it is implemented in production. 

Skills, Knowledge and Expertise
  •  Experience with Splunk, Splunk Enterprise Security, Splunk SOAR (Formerly Splunk Phantom) and Splunk User Behaviour Analytics 
  •  Develop, and implement automations for detection and response. 
  •  Produce System Analytics to prove automation behaviour assumptions 
  • A passion for security automation and a solid understanding of security incident response 
  • Knowledge of security frameworks including MITRE ATT&CK, NIST, etc. 
  • Working experience and knowledge of operating systems (e.g.: Windows, UNIX/Linux) and databases 
  • Knowledge in various scripting and programming languages (Java, Perl, R, Python, C++) 
Desirable: 
  • Understanding of NIS regulations 
  • Understanding of CNI and ideally the Energy Sector. Ideally having worked on a CNI environment/client. 
  • Understanding of NCSC CAF and IT/OT controls such as NIST 
  • Integration of SOAR (Splunk) with OT specific IDS such as Nozomi, Claroty, Dragos, etc. 
  • Playbook development. 

Benefits
We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits: 
 
  • Flexible Working: Balance your work and personal life with our flexible working options. 
  • Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave. 
  • Medicash & Critical Illness Scheme 
  • Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme. 
  • Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities. 
  • Green Car Scheme: Drive green and save money with our eco-friendly car scheme. 
  • Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme. 
  • Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet. 
  • Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments. 

About
We assess, develop and manage cyber threats across our increasingly connected society. We advise global technology, manufacturers, financial institutions, critical national infrastructure providers, retailers and governments on the best way to keep businesses, software and personal data safe.With our knowledge, experience and global footprint, we are best placed to help businesses identify, assess, mitigate & respond to the risks they face.We are passionate about making the Internet safer and revolutionising the way in which organisations think about cyber security.Headquartered in Manchester, UK, with over 35 offices across the world, NCC Group employs more than 2,000 people and is a trusted advisor to 15,000 clients worldwide.

Skills Required

  • Experience with Splunk, Splunk Enterprise Security and Splunk SOAR (Phantom)
  • Experience with Splunk User Behaviour Analytics
  • Develop and implement automations for detection and response (SOAR/playbook development)
  • Produce system analytics to validate automation behaviour
  • Solid understanding of security incident response processes
  • Knowledge of security frameworks (MITRE ATT&CK, NIST)
  • Working experience with operating systems (Windows, UNIX/Linux) and databases
  • Knowledge of scripting/programming languages: Java, Perl, R, Python, C++
  • Documenting system changes and following Change Management practices
  • Perform quality assurance on team deliverables and mentor junior engineers
  • Understanding of NIS regulations
  • Experience with CNI/Energy sector or OT environments
  • Understanding of NCSC CAF and IT/OT controls
  • Integration of SOAR with OT-specific IDS (Nozomi, Claroty, Dragos)
  • Playbook development experience
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Manchester
2,140 Employees
Year Founded: 1999

What We Do

NCC Group is a global cyber security and resilience company that helps organizations manage risk, strengthen resilience, and build trust. They provide services in cyber security consulting, managed services, technical assurance, and software escrow.

Similar Jobs

Immersive Logo Immersive

Operations Specialist

Enterprise Web • HR Tech • Information Technology • Software • Cybersecurity
Remote or Hybrid
United Kingdom
330 Employees

Dynatrace Logo Dynatrace

Principal Telemetry Pipeline Specialist

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
Remote or Hybrid
London, Greater London, England, GBR
5600 Employees

Huntress Logo Huntress

Sales Development Representative

Information Technology • Cybersecurity
Easy Apply
Remote
United Kingdom
780 Employees
44K-57K Annually

CrowdStrike Logo CrowdStrike

Specialist, Cloud Security (Remote, GBR)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
United Kingdom
11000 Employees

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account