1

Siem Soar Developer Jobs (NOW HIRING)

SIEM & SOAR Engineering • Support administration, engineering, optimization, and reliability of SIEM/SOAR platforms. • Develop and maintain SIEM queries, correlation rules, dashboards, alerts ...

We are seeking a SOAR Engineer for an opportunity that is 100% onsite in Washington, DC. All ... Integrate security tools such as SIEM, EDR, threat intelligence, ticketing, and IAM solutions with ...

We are seeking a SOAR Engineer for an opportunity that is 100% onsite in Washington, DC. All ... Integrate security tools such as SIEM, EDR, threat intelligence, ticketing, and IAM solutions with ...

... engineering or security operations, with hands-on expertise in SOAR platform administration ... Experience integrating security tools via RESTful APIs, including SIEM platforms, EDR solutions (e ...

Showing results 21-40

Siem Soar Developer information

See salary details

$17

$52

$81

How much do siem soar developer jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for siem soar developer in the United States is $52.84, according to ZipRecruiter salary data. Most workers in this role earn between $40.38 and $64.66 per hour, depending on experience, location, and employer.

What is a SIEM SOAR developer?

SIEM SOAR Developers are IT professionals who specialize in designing, implementing, and maintaining Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) systems. They build solutions that help organizations detect, analyze, and respond to cybersecurity threats by integrating automated workflows and advanced analytics. These developers often work closely with security teams to customize SIEM and SOAR platforms, automate incident response tasks, and ensure security tools work together efficiently. Their work is crucial for improving response times and reducing the impact of security incidents.

What are the key skills and qualifications needed to thrive as a SIEM SOAR developer?

To thrive as a SIEM SOAR Developer, you need a strong background in cybersecurity, scripting/programming (such as Python or JavaScript), and experience with SIEM and SOAR platforms like Splunk, IBM QRadar, or Palo Alto Cortex XSOAR. Familiarity with security event monitoring tools, incident response processes, and relevant certifications (e.g., Splunk Certified, GIAC, or CompTIA Security+) is often required. Problem-solving, analytical thinking, and effective communication are crucial soft skills for designing automations and collaborating with security teams. These skills ensure the effective detection, analysis, and automated response to threats, helping organizations strengthen their security posture.

What are some common challenges faced by SIEM SOAR developers when integrating new data sources or security tools?

SIEM SOAR Developers often encounter challenges when integrating new data sources or security tools, such as dealing with inconsistent log formats, ensuring data normalization, and maintaining compatibility across diverse systems. Additionally, developers must carefully manage access controls and automation scripts to avoid introducing security gaps. Successful integration typically requires strong collaboration with security analysts and IT teams to understand data flows and ensure that integrations align with organizational security policies.

What is the difference between Siem Soar Developer vs Siem Analyst?

AspectSiem Soar DeveloperSiem Analyst
Primary RoleDesigning, developing, and customizing SOAR playbooks and automation workflowsMonitoring, analyzing, and responding to security alerts within SIEM systems
Skills & CertificationsSIEM/SOAR platform expertise, scripting, security certifications (e.g., CISSP, CEH)SIEM platform knowledge, incident response, security certifications
Work EnvironmentSecurity operations centers, cybersecurity teams, development environmentsSecurity operations centers, incident response teams

While both roles work within cybersecurity and SIEM tools, Siem Soar Developers focus on creating automation and integrations using SOAR platforms, whereas Siem Analysts primarily monitor and analyze security alerts to respond to threats.

Infographic showing various Siem Soar Developer job openings in the United States as of August 2026, with employment types broken down into 85% Full Time, 3% Part Time, and 12% Contract. Highlights an 80% Physical, 5% Hybrid, and 15% Remote job distribution, with an average salary of $109,905 per year, or $52.8 per hour.

Microsoft Sentinel Subject Matter Expert

2T Consulting

Powder Springs, GA • On-site

Full-time

Posted 20 days ago


Job description

We are seeking an experienced Microsoft Sentinel Subject Matter Expert (SME) to design, implement, optimize, and manage Microsoft Sentinel and Azure security solutions. The role will focus on SIEM/SOAR engineering, threat detection, incident response, security automation, cloud security, and compliance across enterprise Azure environments.

Roles and Responsibilities
  • Design, implement, configure, and manage Microsoft Sentinel SIEM/SOAR solutions.
  • Integrate security data sources into Azure Log Analytics, including Syslog, CEF, APIs, and threat intelligence feeds.
  • Develop, optimize, and maintain KQL queries, analytics rules, detection rules, alerts, workbooks, and dashboards.
  • Develop automated security response workflows using Azure Logic Apps and Microsoft Copilot for Security.
  • Perform threat hunting, incident investigation, detection engineering, and response activities in collaboration with SOC teams.
  • Implement and manage Azure security controls aligned with Zero Trust principles.
  • Configure and secure enterprise Azure environments, including identity, access, monitoring, and security services.
  • Assess vulnerabilities, analyze attacker TTPs, and support remediation and security improvement initiatives.
  • Integrate and manage Microsoft Defender XDR, including Defender for Endpoint, Office 365, Identity, and Cloud Apps.
  • Support cloud security governance, compliance, risk assessments, and audit activities.
  • Provide technical guidance on security architecture, SIEM/SOAR strategy, detection engineering, and cloud security initiatives.
  • Develop security standards, operational procedures, and best practices for Sentinel and Azure security services.
  • Collaborate with Security Operations, Cloud Engineering, Identity, Application Security, and Governance teams.
Required Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • 5+ years of cybersecurity experience, including strong hands-on experience with Microsoft Sentinel engineering and administration.
  • Strong expertise in:
    • Microsoft Sentinel
    • Azure Log Analytics
    • Kusto Query Language (KQL)
    • Azure Logic Apps
    • Microsoft Defender XDR
    • Azure Security and Identity Services
    • Microsoft Entra ID
    • Privileged Identity Management (PIM)
    • Conditional Access
    • Security monitoring and incident response
    • CI/CD security and application security scanning
  • Strong understanding of SIEM/SOAR, threat detection, threat hunting, incident response, and security automation.
  • Experience implementing security controls in enterprise Azure environments.
  • Strong knowledge of Zero Trust architecture and cloud security best practices.
Preferred Qualifications
  • Experience with Azure Government / Government Cloud environments.
  • Experience with FISMA, FedRAMP, and NIST security and compliance frameworks.
  • Relevant certifications such as CISSP, CCSP, Microsoft Certified: Azure Security Engineer Associate, or Microsoft Certified: Cybersecurity Architect Expert.
  • Experience working with security auditors, compliance teams, and executive stakeholders.