Dragonfli Group ยท 15 hours ago
SOAR Automation Engineer
Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. They are seeking a SOAR Automation Engineer to design, implement, and scale security automation capabilities for a large U.S. federal agency, focusing on automating security operations and enhancing investigation workflows.
Cyber SecurityInformation TechnologyRisk Management
Responsibilities
Design, build, and maintain SOAR automation using Splunk Phantom
Develop and enhance automated playbooks to support detection, response, and investigation workflows
Integrate SOAR with SIEM, security tools, cloud platforms, and on-prem systems
Apply AI-enabled enrichment and decision support using Azure AI services
Lead automation design decisions and guide SOC teams on effective SOAR usage
Improve dashboards, metrics, and operational visibility tied to automated workflows
Collaborate with security analysts, engineers, and stakeholders to identify automation opportunities
Operationalize and scale automation across the security lifecycle
Ensure reliability, maintainability, and documentation of automation solutions
Qualification
Required
4+ years of experience building and supporting SOAR / security automation solutions in enterprise environments
Hands-on experience with Splunk Phantom (Splunk SOAR)
Strong background in security workflow automation and playbook development
Experience integrating cloud and on-premise systems via APIs
Working familiarity with Azure AI services and applied AI use cases in cybersecurity
Strong problem-solving and analytical skills
Ability to collaborate across technical and non-technical teams
Excellent written and verbal communication skills
Bachelor's degree in a cyber-related field or equivalent experience/certifications
U.S. Citizenship or Permanent Residency
Preferred
Federal cybersecurity environments
SOC operations and incident response workflows
Python or scripting for automation
SIEM integration (Splunk Enterprise / Splunk ES)
Familiarity with NIST cybersecurity frameworks