2

Remote Soar Engineer Jobs in Austin, TX (NOW HIRING)

Principal Security Engineer

Austin, TX · Remote

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This is a remote position Key Responsibilities Detection, Response & Visibility * Own strategy and ... Build and maintain Security Orchestration, Automation, and Response (SOAR) tooling to reduce ...

Principal Security Engineer

Austin, TX · On-site +1

$175K - $200K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This is a remote position Key Responsibilities Detection, Response & Visibility * Own strategy and ... Build and maintain Security Orchestration, Automation, and Response (SOAR) tooling to reduce ...

Principal Security Engineer

Austin, TX · Remote

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

This is a remote position Key Responsibilities Detection, Response & Visibility * Own strategy and ... Build and maintain Security Orchestration, Automation, and Response (SOAR) tooling to reduce ...

Remote Soar Engineer information

See Austin, TX salary details

$37.7K

$114.8K

$189.8K

How much do remote soar engineer jobs pay per year?

As of Aug 13, 2026, the average yearly pay for remote soar engineer in Austin, TX is $114,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $82,300.00 and $150,200.00 per year, depending on experience, location, and employer.

What does a typical workday look like for a remote SOAR engineer, and how do they collaborate with security teams?

A typical workday for a Remote SOAR Engineer involves designing, building, and maintaining automated security workflows, analyzing security alerts, and quickly responding to incidents using SOAR tools. You’ll work closely with Security Operations Center (SOC) analysts, incident responders, and IT teams, often coordinating via virtual meetings, chat platforms, and collaborative documentation tools. Tasks may also include troubleshooting automation scripts, updating playbooks based on emerging threats, and participating in team reviews to improve security processes. Despite being remote, effective communication and regular check-ins are key to ensuring alignment and smooth collaboration across global security teams.

What are the key skills and qualifications needed to thrive as a remote SOAR engineer?

To thrive as a Remote SOAR Engineer, you need expertise in cybersecurity operations, automation scripting (such as Python), and familiarity with Security Orchestration, Automation, and Response (SOAR) platforms, often supported by a degree in computer science or a related field. Proficiency with tools like Splunk, Palo Alto Cortex XSOAR, and relevant certifications (e.g., CISSP, GIAC) are highly valued. Strong problem-solving skills, effective communication, and the ability to work independently in a distributed environment are key soft skills. These qualifications ensure effective incident response automation and seamless integration with security operations while collaborating remotely with global teams.

What is a remote SOAR engineer?

A Remote SOAR (Security Orchestration, Automation, and Response) Engineer is responsible for designing, implementing, and maintaining SOAR solutions to enhance an organization's cybersecurity operations. They work remotely to automate security workflows, integrate various security tools, and improve incident response efficiency. This role requires expertise in scripting, API integrations, and security operations to optimize threat detection and response.

What are the most commonly searched types of Soar Engineer jobs in Austin, TX? The most popular types of Soar Engineer jobs in Austin, TX are:
What job categories do people searching Remote Soar Engineer jobs in Austin, TX look for? The top searched job categories for Remote Soar Engineer jobs in Austin, TX are:
What cities near Austin, TX are hiring for Remote Soar Engineer jobs? Cities near Austin, TX with the most Remote Soar Engineer job openings:

Network Security Analyst 3 (Remote)

Serigor, Inc.

Austin, TX • On-site, Remote

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Job Title: Network Security Analyst 3 (Remote)
Location: Austin, TX
Duration: 12 Months with possible extension
Job Description:
The client is seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations - for triage acceleration, playbook generation, and analyst augmentation - while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office.
Key Responsibilities
  • Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
  • Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
  • Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
  • Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
  • Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
  • Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
  • Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
  • Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
  • Participate in an on-call rotation for critical incident escalations.

The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.
CANDIDATE SKILLS AND QUALIFICATIONS
Minimum Requirements:
Candidates that do not meet or exceed the minimum stated requirements (skills/experience) will be displayed to customers but may not be chosen for this opportunity.
Years
Required/Preferred
Experience
8
Required
Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8
Required
Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8
Required
Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred)
8
Required
Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8
Required
Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8
Required
Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8
Required
Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8
Required
Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8
Required
Strong analytical, problem-solving, and critical-thinking skills
8
Required
Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8
Required
Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8
Required
Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8
Required
Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4
Required
Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
1
Preferred
GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1
Preferred
CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1
Preferred
Torq certification or demonstrated portfolio of built automation workflows
1
Preferred
Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1
Preferred
Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1
Preferred
Experience in government, legal, or law-enforcement-adjacent security environments