Sr. Engineer - SOAR | Onsite, Bangalore.
optiv · Bangalore, Karnataka · India · On-site
Posted Sep 16, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Senior SOAR Engineer responsible for designing, developing, implementing, and maintaining security orchestration, automation, and response solutions using Palo Alto XSOAR and Splunk SOAR. The role will work closely with SOC, engineering, and security teams to automate incident response processes, integrate security technologies, and improve SOC efficiency and response times.
How you'll make an impact:
Design, develop, and maintain SOAR playbooks, workflows, integrations, and automation using Palo Alto XSOAR and Splunk SOAR.
Develop and optimize automated incident response processes across common SOC use cases including phishing, malware, endpoint, identity, vulnerability, and threat intelligence investigations.
Build and maintain integrations with SIEM, EDR, email security, identity, network security, threat intelligence, and other security platforms.
Develop custom integrations, scripts, automation components, and APIs using Python, REST APIs, JSON, and webhooks.
Translate SOC processes and manual procedures into scalable and reliable SOAR automation.
Troubleshoot and optimize existing playbooks, integrations, automation failures, and platform performance issues.
Collaborate with SOC analysts, incident responders, threat intelligence, detection engineering, and security engineering teams to identify automation opportunities.
Participate in SOAR architecture, solution design, deployment, upgrades, and platform migration activities.
Establish development standards, documentation, testing procedures, and operational best practices for SOAR content.
Support production deployments and troubleshoot critical automation issues in a 24x7 security operations environment.
Review and improve automation effectiveness, reducing manual analyst effort and improving incident response SLAs.
Mentor junior SOAR engineers and contribute to technical standards and knowledge sharing.
Stay current with emerging SOAR capabilities, security technologies, APIs, and automation techniques.
What we're looking for:
5+ years of experience in Palo Alto XSOAR and/or Splunk SOAR.
Experience developing complex SOAR playbooks, workflows, integrations, and automation.
Experience with SOAR architecture, platform administration, upgrades, migrations, and enterprise deployments.
Strong programming and scripting skills, particularly Python.
Experience with REST APIs, JSON, webhooks, and API-based integrations.
Strong understanding of SOC operations, incident response, and security investigation processes.
Experience integrating SOAR with SIEM, EDR/XDR, IAM, email security, threat intelligence, vulnerability management, and other security platforms.
Experience with Splunk, Palo Alto Networks, CrowdStrike, Microsoft security technologies, ServiceNow, and threat intelligence platforms..
Experience troubleshooting and supporting SOAR solutions in production environments.
Ability to translate complex security processes…