1

Soar Automation Splunk Phantom Jobs (NOW HIRING)

Experience in technologies like GIT, JIRA, Automation Testing * Familiarity with Phantom, Cloud ... Splunk core admin experience is a plus Additional Information Nice to Have: * Experience in ...

Experience in technologies like GIT, JIRA, Automation Testing * Familiarity with Phantom, Cloud ... Splunk core admin experience is a plus Additional Information Nice to Have: * Experience in ...

Splunk Engineer/Administrator San Antonio, TX (Hybrid) Qualifications: * 8+ years of overall IT ... Experience in technologies like GIT, JIRA, and Automation Testing. * Familiarity with Phantom ...

Splunk Engineer

San Antonio, TX ยท Hybrid

$52/hr

Experience in technologies like GIT, JIRA, and Automation Testing. Familiarity with Phantom, Cloud ... Splunk Admin Certification is mandatory. Excellent communication and interpersonal skills. Splunk ...

Experience in technologies like GIT, JIRA, and Automation Testing. Familiarity with Phantom, Cloud ... Splunk Admin Certification is mandatory. Excellent communication and interpersonal skills. Splunk ...

Sr Splunk SIEM Engineer

Alexandria, VA

$122K - $167K/yr

... SOAR (Phantom) for automation Expertise with MITRE ATT&CK-aligned detection development Scripting/automation experience (Python, Bash, PowerShell) Experience in cloud security logging (AWS, Azure ...

The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and analytics across ... with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms) for improved ...

The Mid-Level Splunk Engineer supports enterprise-wide monitoring, alerting, and analytics ... with automation/orchestration tools (e.g., Ansible, ServiceNow, SOAR platforms) for improved ...

SOAR Engineers

Washington, DC ยท Hybrid

$120K - $150K/yr

The SOAR Engineer will design, implement, and optimize SOAR solutions to automate and enhance ... Proficiency in developing automation playbooks and integrating security platforms such as Splunk ES ...

next page

Showing results 1-20

Soar Automation Splunk Phantom information

See salary details

$51.5K

$121.9K

$168K

How much do soar automation splunk phantom jobs pay per year?

As of Jun 14, 2026, the average yearly pay for soar automation splunk phantom in the United States is $121,854.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals working with SOAR Automation in Splunk Phantom, and how can they be addressed?

Professionals in SOAR Automation using Splunk Phantom often encounter challenges such as integrating diverse security tools, managing complex playbooks, and ensuring seamless automation without disrupting existing workflows. To address these, it's important to maintain clear documentation, conduct thorough testing of playbooks, and collaborate closely with IT and security operations teams. Continual learning and staying updated on platform updates and best practices can also help mitigate these challenges and enhance overall automation effectiveness.

What are the key skills and qualifications needed to thrive as a SOAR Automation (Splunk Phantom) Engineer, and why are they important?

To thrive as a SOAR Automation (Splunk Phantom) Engineer, you need a solid background in cybersecurity, scripting/programming (such as Python), and experience with security operations, typically supported by a relevant degree or certifications like CISSP or Splunk certifications. Familiarity with SOAR platforms such as Splunk Phantom, SIEM systems, REST APIs, and automation frameworks is essential. Strong problem-solving, communication, and teamwork skills help you effectively design and implement automated workflows and collaborate with cross-functional teams. These skills are critical for enhancing incident response efficiency, reducing manual workloads, and improving overall security posture.

What is a SOAR Automation Engineer specializing in Splunk Phantom?

A SOAR Automation Engineer specializing in Splunk Phantom is a cybersecurity professional responsible for automating security operations and incident response workflows using Splunk Phantom, a Security Orchestration, Automation, and Response (SOAR) platform. They design, develop, and maintain playbooks that integrate various security tools to streamline threat detection and response processes. Their role helps organizations respond faster to threats, reduce manual workloads, and improve overall security posture.
Infographic showing various Soar Automation Splunk Phantom job openings in the United States as of June 2026, with employment types broken down into 55% Full Time, and 45% Contract. Highlights an 83% Physical, 8% Hybrid, and 9% Remote job distribution, with an average salary of $121,854 per year, or $58.6 per hour.
Automation / SOAR Engineer - Senior

Automation / SOAR Engineer - Senior

MKS2 Technologies

Washington, DC โ€ข On-site

$150K - $160K/yr

Full-time

Posted 8 days ago


Job description

MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our "Mission First" orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.


Automation / SOAR Engineer โ€“ Senior

Location: National Capital Region (Washington, DC) โ€“ Hybrid/Onsite
Clearance: Must be able to pass background check (US work authorization required)

Salary: $150,000-$160,000


Position Overview

We are seeking a Senior Automation / SOAR Engineer to support enterprise cybersecurity operations by designing, implementing, and optimizing security automation and orchestration capabilities. This role is focused on improving incident response speed, consistency, and operational efficiency through the development of automated workflows, integrations, and playbooks across security platforms.


Key Responsibilities
  • Design, develop, test, and maintain SOAR playbooks and automated security workflows
  • Integrate SOAR and SIEM platforms with:
    • Ticketing systems (ServiceNow, etc.)
    • Endpoint security tools
    • Identity and access systems
    • Vulnerability management platforms
    • Threat intelligence feeds
  • Automate incident response activities including:
    • Alert triage
    • Data enrichment
    • Case routing and escalation
    • Documentation and reporting
  • Develop automation scripts and integrations using Python, PowerShell, Bash, REST APIs, and similar technologies
  • Collaborate with SOC analysts, incident responders, and stakeholders to identify automation opportunities
  • Optimize workflows to reduce false positives and manual workload
  • Maintain documentation, SOPs, implementation plans, and training materials
  • Track and report automation performance, effectiveness, and operational improvements

Required Qualifications
  • 5โ€“8+ years of experience in:
    • Cybersecurity engineering
    • SOC operations or automation
    • SOAR/SIEM implementation
  • 3+ years of hands-on experience building:
    • Security automation workflows
    • Playbooks and orchestration capabilities
  • Experience integrating SOAR/SIEM with enterprise security tools and systems
  • Experience supporting automation in:
    • Incident response
    • Alert triage and enrichment
    • Case management

Technical Skills
  • Strong scripting and automation experience:
    • Python, PowerShell, Bash
    • REST APIs, JSON, webhooks
    • Git or version control
  • Experience with security tools such as:
    • Splunk, Microsoft Sentinel, Elastic
    • CrowdStrike, Microsoft Defender (MDE)
    • Tenable, Rapid7
    • ServiceNow, Tanium
  • Experience building automation for:
    • Phishing response
    • Endpoint alert enrichment
    • Vulnerability workflows
    • Incident routing and escalation

Education
  • Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field (or equivalent experience)

Certifications (Preferred)
  • SOAR / SIEM / Security certifications such as:
    • Cortex XSOAR, Splunk SOAR, Swimlane
    • Microsoft Sentinel
    • CISSP, CASP+, CySA+, Security+
    • Cloud security certifications

Additional Qualifications
  • Knowledge of:
    • MITRE ATT&CK framework
    • NIST 800-61 incident response lifecycle
    • SOC operational processes
  • Ability to document workflows and train SOC teams
  • Strong analytical and problem-solving skills

Nice to Have
  • Experience in federal or regulated environments
  • Familiarity with enterprise-scale cybersecurity operations
  • Experience optimizing SOC performance metrics

Ideal Candidate Profile
  • Hands-on builder (not just admin) of automation/playbooks
  • Strong integration/API background
  • Experienced in operational SOC environments
  • Comfortable working cross-functionally with engineering and operations


Diversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.