Senior SOAR Engineer responsible for designing, developing, implementing, and maintaining security orchestration, automation, and response solutions using Palo Alto XSOAR and Splunk SOAR. The role will work closely with SOC, engineering, and security teams to automate incident response processes, integrate security technologies, and improve SOC efficiency and response times.
How you'll make an impact:
Design, develop, and maintain SOAR playbooks, workflows, integrations, and automation using Palo Alto XSOAR and Splunk SOAR.
Develop and optimize automated incident response processes across common SOC use cases including phishing, malware, endpoint, identity, vulnerability, and threat intelligence investigations.
Build and maintain integrations with SIEM, EDR, email security, identity, network security, threat intelligence, and other security platforms.
Develop custom integrations, scripts, automation components, and APIs using Python, REST APIs, JSON, and webhooks.
Translate SOC processes and manual procedures into scalable and reliable SOAR automation.
Troubleshoot and optimize existing playbooks, integrations, automation failures, and platform performance issues.
Collaborate with SOC analysts, incident responders, threat intelligence, detection engineering, and security engineering teams to identify automation opportunities.
Participate in SOAR architecture, solution design, deployment, upgrades, and platform migration activities.
Establish development standards, documentation, testing procedures, and operational best practices for SOAR content.
Support production deployments and troubleshoot critical automation issues in a 24x7 security operations environment.
Review and improve automation effectiveness, reducing manual analyst effort and improving incident response SLAs.
Mentor junior SOAR engineers and contribute to technical standards and knowledge sharing.
Stay current with emerging SOAR capabilities, security technologies, APIs, and automation techniques.
What we're looking for:
5+ years of experience in Palo Alto XSOAR and/or Splunk SOAR.
Experience developing complex SOAR playbooks, workflows, integrations, and automation.
Experience with SOAR architecture, platform administration, upgrades, migrations, and enterprise deployments.
Strong programming and scripting skills, particularly Python.
Experience with REST APIs, JSON, webhooks, and API-based integrations.
Strong understanding of SOC operations, incident response, and security investigation processes.
Experience integrating SOAR with SIEM, EDR/XDR, IAM, email security, threat intelligence, vulnerability management, and other security platforms.
Experience with Splunk, Palo Alto Networks, CrowdStrike, Microsoft security technologies, ServiceNow, and threat intelligence platforms..
Experience troubleshooting and supporting SOAR solutions in production environments.
Ability to translate complex security processes into scalable and maintainable automation.
Strong analytical, problem-solving, communication, and documentation skills.
Relevant vendor/tool certifications, such as:
Palo Alto Networks Certified Security Automation Engineer (PCSAE) or equivalent XSOAR certification.
Splunk SOAR / Splunk Certified certifications.
Relevant CrowdStrike, Microsoft, Google SecOps, Elastic, or other security platform certifications.
Relevant SIEM, EDR/XDR, threat intelligence, or security automation certifications.
Excellent English fluency required
This role demands availability during US Working Hours specifically from 5:00 PM to 2:00 AM IST
This role is Work from Office (3 days a week).
What you can expect from Optiv
- A company committed to our inclusive value through our Employee Resource Groups
- Work/life balance
- Professional training resources
- Creative problem-solving and the ability to tackle unique, complex projects
- Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
- The ability and technology necessary to productively work remotely/from home (where applicable)
EEO Statement
Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.
Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities. For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.
Skills Required
- 5+ years of experience with Palo Alto XSOAR and/or Splunk SOAR
- Experience developing complex SOAR playbooks, workflows, integrations, and automation
- Experience with SOAR architecture, platform administration, upgrades, migrations, and enterprise deployments
- Strong Python programming and scripting skills
- Experience with REST APIs, JSON, webhooks, and API-based integrations
- Strong understanding of SOC operations, incident response, and security investigation processes
- Experience integrating SOAR with SIEM, EDR/XDR, IAM, email security, threat intelligence, and vulnerability management platforms
- Experience with Splunk, Palo Alto Networks, CrowdStrike, Microsoft security technologies, ServiceNow, and threat intelligence platforms
- Experience troubleshooting and supporting SOAR solutions in production environments
- Ability to translate complex security processes into scalable and maintainable automation
- Strong analytical, problem-solving, communication, and documentation skills
- Excellent English fluency
- Availability during US working hours from 5:00 PM to 2:00 AM IST
- Work from office three days per week
- Palo Alto Networks Certified Security Automation Engineer or equivalent XSOAR certification
- Splunk SOAR or Splunk Certified certification
- Relevant CrowdStrike, Microsoft, Google SecOps, Elastic, SIEM, EDR/XDR, threat intelligence, or security automation certifications
Optiv Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Optiv and has not been reviewed or approved by Optiv.
-
Retirement Support — Immediate vesting with a clear 401(k) match and a solid retirement setup are emphasized in official materials. This positions retirement benefits as a dependable part of the total package.
-
Leave & Time Off Breadth — A flexible, no‑accrual “Recharge” policy for eligible exempt roles and traditional PTO for non‑exempt roles are highlighted. Hybrid/remote flexibility also appears frequently across role descriptions.
-
Healthcare Strength — Comprehensive medical, dental, and vision options with FSA/HSA (including a company HSA contribution) are described. Company‑paid life, AD&D, and short‑/long‑term disability further strengthen core protections.
Optiv Insights
What We Do
Optiv is a security solutions integrator – “one-stop” trusted partner with a singular focus on cybersecurity. Our end-to-end cybersecurity capabilities span risk management and transformation, cyber digital transformation, threat management, security operations, identity and data management, and integration and innovation, helping organizations realize stronger, simpler and more cost-efficient cybersecurity programs that support business requirements and outcomes. At Optiv, we are modernizing cybersecurity to enable clients to innovate their consumption models, integrate infrastructure and technology to maximize value, achieve measurable outcomes, and realize complete solutions and business alignment.
.png)






