Senior SOAR Engineer

Sampoorna Consultants
Posted on
Sampoorna Consultants logo

Experience
5 - 8 yrs
Job Location
Mumbai, India
Vacancy
1
Designation
Senior Engineer
Job Type
Not specified

Job Description

Senior SOAR Engineer - J50695


Role & responsibilities

Job Location: Airoli, Navi Mumbai (Client Location)
5 days Work from Office - General Shift

About the Role
We are looking for an experienced and driven SOAR Engineer to join our growing SOC Services team. The candidate will be responsible for designing, building, and maintaining automated playbooks and integrations within the SOAR platform. The role focuses on automation engineering, API integrations, scripting, and the orchestration of security tools to streamline incident response processes.

Key Responsibilities
1. Design and build automated playbooks for incident types such as: Phishing
investigations, Malware alerts, Suspicious authentication, Privilege misuse enrichment workflows.
2. Implement conditional logic (if/else, loops), Parallel execution flows, Automated enrichment steps, Escalation and approval workflows.
3. Convert manual SOC runbooks into fully automated workflows.
4. Build dynamic playbooks driven by alert severity and risk score.
5. Develop integrations with- SIEM, EDR/XDR, Firewall, Email security platforms, IAM, threat Intelligence platforms, ticketing systems such as Service Now.
6. Build custom integrations with REST APIs, Web hooks, and Python-based connectors.
7. Conduct regression testing after playbook creation/updates using synthetic data.
8. Troubleshooting failed automation, runbooks, and integration errors.
9. Maintain end-to-end documentation from conceptual, requirement gathering, to playbook production- sign-offs.

Required technical skill sets
10. Hands-on experience with at least one SIEM platform.
11. Strong Python scripting skills (mandatory) with knowledge of PowerShell/bash.
12. Experience with rest APIs, JSON & XML parsing, API authentication mechanisms,
Webhooks.
13. Experience developing custom connectors.
14. Experience with SIEM architecture, SOC incident response lifecycle, MIRTE Framework.

Required Experience
15. 5-6 years of hands-on experience in managing an enterprise SIEM platform.
16. Strong playbook building knowledge.
17. Proven track record in SOAR management, playbook building, and new data sources and integration.





No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.