1

Siem Soar Developer Jobs (NOW HIRING)

... engineering or security operations, with hands-on expertise in SOAR platform administration ... Experience integrating security tools via RESTful APIs, including SIEM platforms, EDR solutions (e ...

Security Engineer

Aurora, CO · On-site

$95 - $115/hr

Skills SIEM, SOAR, Splunk, Scripting, Cissp, Cyber security, Rmf, ATO, SQL Top Skills Details SIEM ... engineer (ISSE) supporting high-level technical and practical expertise.  • This position ...

Skills SIEM, SOAR, Splunk, Scripting, Cissp, Cyber security, Rmf, ATO, SQL Top Skills Details SIEM ... engineer (ISSE) supporting high-level technical and practical expertise.  • This position ...

Skills SIEM, SOAR, Splunk, Scripting, Cissp, Cyber security, Rmf, ATO, SQL Top Skills Details SIEM ... engineer (ISSE) supporting high-level technical and practical expertise.  • This position ...

Splunk Engineer Location: Onsite - New Jersey (NJ), Tampa (FL), Tempe (AZ) Experience Required: 8 ... Implement and support SIEM/SOAR solutions using platforms such as Splunk, Elastic, Datadog, Cribl ...

next page

Showing results 1-20

Siem Soar Developer information

See salary details

$17

$52

$81

How much do siem soar developer jobs pay per hour?

As of Jun 17, 2026, the average hourly pay for siem soar developer in the United States is $52.84, according to ZipRecruiter salary data. Most workers in this role earn between $40.38 and $64.66 per hour, depending on experience, location, and employer.

What are SIEM SOAR Developers?

SIEM SOAR Developers are IT professionals who specialize in designing, implementing, and maintaining Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) systems. They build solutions that help organizations detect, analyze, and respond to cybersecurity threats by integrating automated workflows and advanced analytics. These developers often work closely with security teams to customize SIEM and SOAR platforms, automate incident response tasks, and ensure security tools work together efficiently. Their work is crucial for improving response times and reducing the impact of security incidents.

What are the key skills and qualifications needed to thrive as a SIEM SOAR Developer, and why are they important?

To thrive as a SIEM SOAR Developer, you need a strong background in cybersecurity, scripting/programming (such as Python or JavaScript), and experience with SIEM and SOAR platforms like Splunk, IBM QRadar, or Palo Alto Cortex XSOAR. Familiarity with security event monitoring tools, incident response processes, and relevant certifications (e.g., Splunk Certified, GIAC, or CompTIA Security+) is often required. Problem-solving, analytical thinking, and effective communication are crucial soft skills for designing automations and collaborating with security teams. These skills ensure the effective detection, analysis, and automated response to threats, helping organizations strengthen their security posture.

What are some common challenges faced by SIEM SOAR Developers when integrating new data sources or security tools?

SIEM SOAR Developers often encounter challenges when integrating new data sources or security tools, such as dealing with inconsistent log formats, ensuring data normalization, and maintaining compatibility across diverse systems. Additionally, developers must carefully manage access controls and automation scripts to avoid introducing security gaps. Successful integration typically requires strong collaboration with security analysts and IT teams to understand data flows and ensure that integrations align with organizational security policies.

What is the difference between Siem Soar Developer vs Siem Analyst?

AspectSiem Soar DeveloperSiem Analyst
Primary RoleDesigning, developing, and customizing SOAR playbooks and automation workflowsMonitoring, analyzing, and responding to security alerts within SIEM systems
Skills & CertificationsSIEM/SOAR platform expertise, scripting, security certifications (e.g., CISSP, CEH)SIEM platform knowledge, incident response, security certifications
Work EnvironmentSecurity operations centers, cybersecurity teams, development environmentsSecurity operations centers, incident response teams

While both roles work within cybersecurity and SIEM tools, Siem Soar Developers focus on creating automation and integrations using SOAR platforms, whereas Siem Analysts primarily monitor and analyze security alerts to respond to threats.

SOAR Engineer

1 point system

Plano, TX • Remote

Contractor

Posted 4 days ago


Job description

  • 5+ years of experience in cyber security engineering or security operations, with hands-on expertise in SOAR platform administration, playbook development, and security workflow automation.
  • Subject matter expertise in one or more SOAR platforms** (e.g., Palo Alto XSOAR/Cortex XSOAR, Splunk SOAR/Phantom, Swimlane, Tines, Crowdstrike Fusion, Google Chronicle SOAR, or similar).
  • Strong proficiency in Python and PowerShell, with demonstrated ability to build custom integrations, automation scripts, and API-driven workflows.
  • Experience integrating security tools via RESTful APIs, including SIEM platforms, EDR solutions (e.g., CrowdStrike), ticketing systems, threat intelligence feeds, IAM solutions, and cloud security services.
  • Solid understanding of security operations workflows, including alert triage, incident response, threat enrichment, and escalation processes.
  • Familiarity with SIEM platforms and data source ecosystems, with the ability to collaborate effectively with SIEM engineers on detection-to-response automation pipelines.