1

Splunk Soar Jobs in Texas (NOW HIRING)

Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq ... XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM ...

Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response. * Strong analytical and investigative skills; knowledge ...

Experience with SOAR platforms (e.g., Splunk SOAR, Microsoft Sentinel automation, Swimlane) and building playbooks for enrichment and response. * Strong analytical and investigative skills; knowledge ...

Experience with SOAR orchestration tools such as Splunk SOAR, Palo Alto XSOAR, or equivalent (desired) * CISSP or CISM preferred; cloud professional certification such as CCSP, AWS Solutions ...

New

SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...

Splunk Engineer

Plano, TX · On-site

$63.68 - $71.68/hr

Genesis10 is currently seeking a Splunk Engineer for a contract position with a Global Financial ... ES) and SOAR (Phantom or equivalent) Exposure to cloud logging and security architectures (AWS ...

SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...

SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...

SOAR products such as Splunk SOAR, Cortex XSOAR, FortiSOAR, etc. SOAR playbook development experience is a plus. * Endpoint detection and response tools, e.g. CrowdStrike, SentinelOne, Microsoft ...

Experience with SOAR orchestration tools such as Splunk SOAR, Palo Alto XSOAR, or equivalent.CISSP or CISM preferred; cloud professional certification such as CCSP, AWS Solutions Architect ...

New

next page

Showing results 1-20

Splunk Soar information

What is the difference between Splunk Soar vs Splunk Security Analyst?

AspectSplunk SoarSplunk Security Analyst
CertificationsSplunk Certified SOAR User, Security certificationsCompTIA Security+, CISSP, Splunk certifications
Work EnvironmentSecurity operations centers, incident response teamsSecurity teams, SOCs, incident analysis
Primary FocusAutomating security workflows, incident response automationMonitoring security alerts, analyzing threats

Splunk Soar specializes in automating security incident response and streamlining workflows within security operations centers. In contrast, Splunk Security Analysts focus on monitoring security alerts, analyzing threats, and supporting incident investigations. While both roles require security knowledge and Splunk certifications, Splunk Soar emphasizes automation skills, whereas Security Analysts focus on threat analysis and monitoring.

What job categories do people searching Splunk Soar jobs in Texas look for? The top searched job categories for Splunk Soar jobs in Texas are:
What cities in Texas are hiring for Splunk Soar jobs? Cities in Texas with the most Splunk Soar job openings:
Infographic showing various Splunk Soar job openings in Texas as of August 2026, with employment types broken down into 81% Full Time, and 19% Contract. Highlights an 81% In-person, 6% Hybrid, and 13% Remote job distribution.

Cyber Automation Engineer

Neos Consulting

Austin, TX • On-site

Other

Posted 22 days ago


Job description

City : Austin
State : Texas
Neos is Seeking a Cyber Automation Engineer for a long-term contract role for with our client in Austin, TX.
Experience in security automation, detection engineering, and CrowdStrike. The ideal candidate is passionate about improving Security Operations Center (SOC) processes through automation and has experience working in highly regulated or government environments.
*** REMOTE - CANDIDATES CURRENTLY RESIDING IN THE AUSTIN, TEXAS AREA OR IN U.S. NEED APPLY***
This position is Remote
No calls, no emails, please respond directly to the "apply" link with your resume and contact details.
DESCRIPTION OF SERVICES
Seeking a senior-level Security Operations Analyst to strengthen detection, response, and orchestration capabilities across the agency's security operations. This role blends deep SOC (Security Operations Center) investigative expertise with hands-on security automation engineering, focusing on CrowdStrike Falcon and Torq to build scalable, AI-assisted detection and response workflows. The ideal candidate has practical experience integrating large language model (LLM) tools such as Claude into security operations - for triage acceleration, playbook generation, and analyst augmentation - while operating within a strict Zero Trust, defense-in-depth security posture appropriate to a state Attorney General's office.
Key Responsibilities
Serve as a SOC analysis & Tier 3 escalation point for complex security incidents, performing deep-dive investigation, root cause analysis, and threat hunting across endpoint, network, cloud, and identity telemetry.
Design, build, and maintain detection analytics, dashboards, and hunting queries (Falcon Query Language / FQL) within CrowdStrike Falcon, tuning correlation rules and detection logic to reduce false positives and improve mean-time-to-detect (MTTD).
Architect and maintain security orchestration, automation, and response (SOAR) playbooks in Torq, integrating CrowdStrike Falcon, identity providers, ticketing, and communication platforms into automated response workflows.
Design AI-assisted analyst workflows (e.g., automated triage summarization, alert enrichment, playbook drafting) using approved generative AI tooling, ensuring all inputs are sanitized and free of regulated or case-specific data.
Lead incident response efforts for high-severity events, coordinating with IT, legal, and divisional stakeholders while strictly adhering to FTI/CJI handling restrictions.
Develop and maintain detection engineering documentation, runbooks, and standard operating procedures (SOPs) for Tier 1/Tier 2 analyst use.
Mentor and provide technical guidance to Tier 1 and Tier 2 SOC analysts; review and validate their investigative work and escalation quality.
Continuously evaluate and integrate emerging SOC automation and AI capabilities, presenting proposals for tooling changes with documented risk and compliance analysis.
Participate in an on-call rotation for critical incident escalations.
The above job description and requirements are general in nature and may be subject to change based on the specific needs and requirements of the organization and project.
CANDIDATE SKILLS AND QUALIFICATIONS
Requirements
8 years Required - Progressive SOC / security operations experience, including 2+ years functioning at a Tier 3 / senior analyst or detection engineering level.
8 years Required - Hands-on production experience with CrowdStrike Falcon (Insight XDR, Discover, and/or Fusion SOAR), including custom detection/IOA authoring, Falcon Query Language (FQL) use, and dashboard development.
8 years Required - Demonstrated experience building or maintaining SOAR automation (Torq strongly preferred).
8 years Required - Practical, hands-on experience using AI/LLM tools (e.g., Claude, GPT-based tools) to support security operations, with clear understanding of data sanitization and safe-use boundaries in a regulated environment.
8 years Required - Working knowledge of Zero Trust architecture principles (NIST 800-207) and general familiarity with regulatory frameworks such as IRS Pub. 1075, FBI CJIS Policy, and HIPAA.
8 years Required - Strong scripting/automation ability (PowerShell, Python, or Falcon Query Language-based automation) for building custom detections and integrations.
8 years Required - Excellent written communication skills for incident reporting, runbook authorship, and cross-divisional coordination.
8 years Required - Experience documenting investigations, creating hunt reports, and communicating technical findings to diverse audiences.
8 years Required - Strong analytical, problem-solving, and critical-thinking skills.
8 years Required - Ability to work independently while collaborating effectively within cross-functional cybersecurity teams.
8 years Required - Ability to resolve complex security issues in diverse and decentralized environments; learn, communicate, teach new security technologies; and communicate effectively.
8 years Required - Conduct forensic investigations on cyberattacks to determine how they occurred and can be prevented in the future.
8 years Required - Experience creating/reviewing/updating security policies and standards for the public/private/hybrid cloud contexts.
4 years Required - Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
Preferred Qualifications
1 year Preferred - GIAC certifications (GCIH, GCIA, GCFA) or equivalent.
1 year Preferred - CrowdStrike Certified Falcon Responder (CCFR) or CrowdStrike Certified Falcon Administrator (CCFA), or equivalent CrowdStrike security certification.
1 year Preferred - Torq certification or demonstrated portfolio of built automation workflows.
1 year Preferred - Experience designing AI-assisted playbooks or analyst copilots for SOC use cases while maintaining strict data-handling guardrails.
1 year Preferred - Familiarity with Microsoft Defender XDR, Splunk, Entra ID Protection, and Tenable One / cloud security posture management (CSPM) tooling.
1 year Preferred - Experience in government, legal, or law-enforcement-adjacent security environments.
#DICE
#LI-I