1

Soar Engineer Jobs (NOW HIRING)

Hybrid 2 Days Onsite/3 Days Remote in Washington, DC Our client seeks an Automation / SOAR Engineer to design, develop, and implement automation solutions within a federal cybersecurity operations ...

SIEM/SOAR Security Engineer Visa: USC, GC, GC-EAD, H4-EAD Interview: Video Mode: Onsite Work Location: Jersey City, NJ / Tampa, FL / Tempe, AZ Work location : Must work onsite for 4 days and 1 day ...

The Security Automation (SOAR) Engineer will build, optimize, and scale our automated incident response workflows. You will bridge security operations and software engineering, using modern low-code ...

$140K - $155K/yr

... engineering, and response into one proactive, intelligence-led defense capability that breaks down ... Architect and develop SOAR playbooks and automated workflows to streamline incident triage ...

Showing results 21-40

Soar Engineer information

See salary details

$38K

$115.9K

$191.5K

How much do soar engineer jobs pay per year?

As of Aug 9, 2026, the average yearly pay for soar engineer in the United States is $115,864.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,000.00 and $151,500.00 per year, depending on experience, location, and employer.

What is a Soar engineer?

A SOAR (Security Orchestration, Automation, and Response) Engineer is responsible for designing, implementing, and managing security automation solutions within an organization's cybersecurity operations. They work with SOAR platforms to automate repetitive tasks, integrate security tools, and streamline incident response workflows. Their role involves scripting, playbook development, and optimizing security operations to improve efficiency and threat mitigation. SOAR Engineers typically collaborate with SOC teams, threat analysts, and other cybersecurity professionals to enhance an organization's defense mechanisms.

What are some common challenges faced by Soar engineers in their daily work?

SOAR Engineers often face the challenge of integrating diverse security tools and processes to create seamless automated workflows. Ensuring that playbooks accurately address real-world threats while minimizing false positives requires careful tuning and ongoing collaboration with security analysts. Additionally, keeping up with evolving cyber threats and updating automation scripts to handle new scenarios is a regular part of the role. Working as a SOAR Engineer typically involves close teamwork with SOC members and IT staff to ensure incident response efforts are aligned and effective, making adaptability and strong problem-solving skills vital.

What are the key skills and qualifications needed to thrive as a Soar engineer?

To thrive as a SOAR Engineer, you need strong knowledge of cybersecurity, incident response processes, and experience with Security Orchestration, Automation, and Response (SOAR) platforms. Familiarity with tools like Splunk Phantom, Palo Alto Cortex XSOAR, and relevant certifications such as CISSP or CompTIA Security+ are highly valued. Analytical thinking, attention to detail, and effective communication are important soft skills for collaborating across IT and security teams. These skills are crucial for automating threat detection and response, improving security operations efficiency, and minimizing organizational risk.

What cities are hiring for Soar Engineer jobs? Cities with the most Soar Engineer job openings:
What are the most commonly searched types of Soar Engineer jobs? The most popular types of Soar Engineer jobs are:
What states have the most Soar Engineer jobs? States with the most job openings for Soar Engineer jobs include:
What job categories do people searching Soar Engineer jobs look for? The top searched job categories for Soar Engineer jobs are:
Infographic showing various Soar Engineer job openings in the United States as of August 2026, with employment types broken down into 77% Full Time, and 23% Contract. Highlights an 73% In-person, and 27% Remote job distribution, with an average salary of $115,864 per year, or $55.7 per hour.

Automation / SOAR Engineer - Senior

MKS2 Technologies

Washington, DC

$150K - $160K/yr

Full-time

Re-posted 4 days ago


Job description

MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our "Mission First" orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.


Automation / SOAR Engineer – Senior

Location: National Capital Region (Washington, DC) – Hybrid/Onsite
Clearance: Must be able to pass background check (US work authorization required)

Salary: $150,000-$160,000


Position Overview

We are seeking a Senior Automation / SOAR Engineer to support enterprise cybersecurity operations by designing, implementing, and optimizing security automation and orchestration capabilities. This role is focused on improving incident response speed, consistency, and operational efficiency through the development of automated workflows, integrations, and playbooks across security platforms.


Key Responsibilities
  • Design, develop, test, and maintain SOAR playbooks and automated security workflows
  • Integrate SOAR and SIEM platforms with:
    • Ticketing systems (ServiceNow, etc.)
    • Endpoint security tools
    • Identity and access systems
    • Vulnerability management platforms
    • Threat intelligence feeds
  • Automate incident response activities including:
    • Alert triage
    • Data enrichment
    • Case routing and escalation
    • Documentation and reporting
  • Develop automation scripts and integrations using Python, PowerShell, Bash, REST APIs, and similar technologies
  • Collaborate with SOC analysts, incident responders, and stakeholders to identify automation opportunities
  • Optimize workflows to reduce false positives and manual workload
  • Maintain documentation, SOPs, implementation plans, and training materials
  • Track and report automation performance, effectiveness, and operational improvements

Required Qualifications
  • 5–8+ years of experience in:
    • Cybersecurity engineering
    • SOC operations or automation
    • SOAR/SIEM implementation
  • 3+ years of hands-on experience building:
    • Security automation workflows
    • Playbooks and orchestration capabilities
  • Experience integrating SOAR/SIEM with enterprise security tools and systems
  • Experience supporting automation in:
    • Incident response
    • Alert triage and enrichment
    • Case management

Technical Skills
  • Strong scripting and automation experience:
    • Python, PowerShell, Bash
    • REST APIs, JSON, webhooks
    • Git or version control
  • Experience with security tools such as:
    • Splunk, Microsoft Sentinel, Elastic
    • CrowdStrike, Microsoft Defender (MDE)
    • Tenable, Rapid7
    • ServiceNow, Tanium
  • Experience building automation for:
    • Phishing response
    • Endpoint alert enrichment
    • Vulnerability workflows
    • Incident routing and escalation

Education
  • Bachelor's degree in Cybersecurity, IT, Computer Science, Engineering, or related field (or equivalent experience)

Certifications (Preferred)
  • SOAR / SIEM / Security certifications such as:
    • Cortex XSOAR, Splunk SOAR, Swimlane
    • Microsoft Sentinel
    • CISSP, CASP+, CySA+, Security+
    • Cloud security certifications

Additional Qualifications
  • Knowledge of:
    • MITRE ATT&CK framework
    • NIST 800-61 incident response lifecycle
    • SOC operational processes
  • Ability to document workflows and train SOC teams
  • Strong analytical and problem-solving skills

Nice to Have
  • Experience in federal or regulated environments
  • Familiarity with enterprise-scale cybersecurity operations
  • Experience optimizing SOC performance metrics

Ideal Candidate Profile
  • Hands-on builder (not just admin) of automation/playbooks
  • Strong integration/API background
  • Experienced in operational SOC environments
  • Comfortable working cross-functionally with engineering and operations


Diversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.