1

Soar Automation Splunk Phantom Jobs (NOW HIRING)

The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration ... Automation * Develop, customize, and maintain complex SOAR playbooks using Python and the Phantom ...

Design, develop, and maintain automated playbooks using Splunk SOAR (Phantom) to streamline SOC ... Collaborate with SOC and IT teams to align automation with detection and response strategies.

... security workflow automation. * Subject matter expertise in one or more SOAR platforms** (e.g., Palo Alto XSOAR/Cortex XSOAR, Splunk SOAR/Phantom, Swimlane, Tines, Crowdstrike Fusion, Google ...

Senior Cybersecurity Engineer

Charlotte, NC · Hybrid

$111K - $153K/yr

SOAR & Security Automation * Design and implement automation workflows using Splunk SOAR (Phantom). * Develop automation scripts using Python and REST APIs. * Integrate security orchestration ...

Experience with Security Orchestration, Automation, and Response (SOAR), particularly Cortex XSOAR ... Expertise in Splunk Search Processing Language (SPL). Proven experience in building custom ...

Design, develop, and maintain SOAR playbooks and automation workflows. * Automate incident response ... Experience with tools such as Splunk, Microsoft Sentinel, Microsoft Defender, Rapid7 InsightVM ...

Design, develop, and maintain SOAR playbooks and automation workflows. * Automate incident response ... Experience with tools such as Splunk, Microsoft Sentinel, Microsoft Defender, Rapid7 InsightVM ...

next page

Showing results 1-20

Soar Automation Splunk Phantom information

See salary details

$51.5K

$121.9K

$168K

How much do soar automation splunk phantom jobs pay per year?

As of Jun 14, 2026, the average yearly pay for soar automation splunk phantom in the United States is $121,854.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working with SOAR Automation in Splunk Phantom, and how can they be addressed?

Professionals in SOAR Automation using Splunk Phantom often encounter challenges such as integrating diverse security tools, managing complex playbooks, and ensuring seamless automation without disrupting existing workflows. To address these, it's important to maintain clear documentation, conduct thorough testing of playbooks, and collaborate closely with IT and security operations teams. Continual learning and staying updated on platform updates and best practices can also help mitigate these challenges and enhance overall automation effectiveness.

What are the key skills and qualifications needed to thrive as a SOAR Automation (Splunk Phantom) Engineer, and why are they important?

To thrive as a SOAR Automation (Splunk Phantom) Engineer, you need a solid background in cybersecurity, scripting/programming (such as Python), and experience with security operations, typically supported by a relevant degree or certifications like CISSP or Splunk certifications. Familiarity with SOAR platforms such as Splunk Phantom, SIEM systems, REST APIs, and automation frameworks is essential. Strong problem-solving, communication, and teamwork skills help you effectively design and implement automated workflows and collaborate with cross-functional teams. These skills are critical for enhancing incident response efficiency, reducing manual workloads, and improving overall security posture.

What is a SOAR Automation Engineer specializing in Splunk Phantom?

A SOAR Automation Engineer specializing in Splunk Phantom is a cybersecurity professional responsible for automating security operations and incident response workflows using Splunk Phantom, a Security Orchestration, Automation, and Response (SOAR) platform. They design, develop, and maintain playbooks that integrate various security tools to streamline threat detection and response processes. Their role helps organizations respond faster to threats, reduce manual workloads, and improve overall security posture.
Infographic showing various Soar Automation Splunk Phantom job openings in the United States as of June 2026, with employment types broken down into 55% Full Time, and 45% Contract. Highlights an 83% Physical, 8% Hybrid, and 9% Remote job distribution, with an average salary of $121,854 per year, or $58.6 per hour.
Splunk SOAR Engineer

Splunk SOAR Engineer

Venatore Llc

Tampa, FL • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 12 days ago


Job description

About Us
Venatore is a woman-owned small business headquartered in Tampa, Florida, providing mission-driven technology and professional services to federal defense and civilian agencies. We deliver expertise in information technology, engineering, logistics, and program support to help our clients achieve operational excellence and mission success.

About the Job
Venatore is seeking a Splunk SOAR Engineer to support U.S. Central Command (USCENTCOM) operations by designing, implementing, and optimizing enterprise-level Security Orchestration, Automation, and Response (SOAR) capabilities. This role is responsible for transforming manual incident response processes into scalable, automated workflows that accelerate threat detection, containment, and remediation. The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration, content development, and performance optimization while collaborating closely with SOC analysts, threat hunters, and incident response teams. An active TS/SCI clearance is required.

Responsibilities

Platform Architecture & Engineering

  • Design, deploy, document, and maintain distributed Splunk SOAR (Phantom) platform architecture to ensure high availability, scalability, and performance.

  • Support system upgrades, patching, and performance tuning across the SOAR infrastructure.

  • Provide advanced troubleshooting and resolution of platform issues and playbook execution errors.

  • Adhere to security best practices and compliance requirements within the operational environment.

Playbook Development & Automation

  • Develop, customize, and maintain complex SOAR playbooks using Python and the Phantom Playbook Editor for automated enrichment, triage, containment, and remediation of security incidents (e.g., phishing, malware, unauthorized access).

  • Translate manual security procedures into robust, automated workflows aligned with SecOps best practices.

  • Establish and track automation metrics, including utilization rates, automation coverage, and Mean Time to Respond (MTTR) improvements.

Integration & Interoperability

  • Integrate Splunk SOAR with Splunk Enterprise Security (ES) and other core security technologies, including EDR/XDR platforms, firewalls, vulnerability scanners, threat intelligence platforms, and ticketing systems.

  • Develop custom apps and integrations to connect proprietary or unsupported security tools using RESTful APIs and custom connectors.

  • Manage and optimize data flow between Splunk ES and Splunk SOAR to ensure effective event-triggered automation actions.

Collaboration & Documentation

  • Partner with SOC analysts, threat hunters, and incident response teams to gather requirements and document workflows.

  • Develop and maintain detailed technical documentation for platform configurations, integrations, and automation content.

  • Provide training and mentorship to SOC staff on SOAR usage, content development, and automation best practices.

  • Evaluate and integrate emerging security technologies and threat intelligence feeds into the automation ecosystem.

Required Qualifications

  • Active TS/SCI security clearance.

  • U.S. citizenship.

  • Applicable DoD 8140 or DoD 8570 certification.

  • 8+ years of related experience in security engineering or security operations.

  • Hands-on expertise with Splunk SOAR (Phantom) administration, configuration, and maintenance in a distributed enterprise environment.

  • Advanced proficiency in Python scripting for playbook development, custom apps, and integrations.

  • Proven experience integrating SOAR platforms with Splunk Enterprise Security (ES), SIEMs, EDR/XDR tools, and other security technologies.

  • Strong understanding of security operations principles, incident response lifecycles, and threat detection methodologies.

  • Experience working with RESTful APIs and developing tool connectors.

  • Proficiency in data manipulation, log parsing, and understanding of the Common Information Model (CIM) in a security context.

  • Strong verbal and written communication skills with the ability to convey complex automation concepts to technical and non-technical audiences.

Preferred Qualifications

  • Familiarity with cloud security logging, containerization (Docker/Kubernetes), and CI/CD pipelines for playbook deployment.

  • Knowledge of the MITRE ATT&CK framework and its application in automated detection and response use cases.

  • Experience using Git or other version control systems for SOAR content management.

  • Familiarity with network protocols, Windows and Linux operating systems, and enterprise security architecture components.

  • Splunk Enterprise Security Certified Admin or Architect certification.

  • Splunk SOAR (Phantom) Certified Content Developer or Administrator certification.

  • Experience with other SOAR platforms (e.g., Palo Alto Cortex XSOAR, IBM Resilient).

  • Experience supporting USCENTCOM or multi-domain defense security operations environments.

  • ITIL 4 Foundation certification.

Benefits
Venatore offers a competitive benefits package designed to support the well-being of our employees, including:

  • Paid Time Off (PTO)

  • 10 Federal Holidays

  • 401(k) with company matching

  • Medical, dental, and vision insurance

  • Paid parental leave

  • Paid military leave

Venatore is an equal opportunity employer and considers qualified applicants without regard to disability or protected veteran status.