The Senior SOAR Engineer designs, builds and maintains security automations that detect, investigate and respond to cyber threats. The role works closely with Incident Response to identify improvements, create new playbooks and deliver scalable automation within the Splunk ecosystem. Responsibilities include advanced analytics, scripting, creating new use cases, validating automation behaviour, documenting changes and mentoring junior engineers.
Key Responsibilities
- Work in partnership with the incident response team to design, identify, and implement opportunities for improvement
- Develop, and implement automations for detection and response.
- Be the subject matter experts on big data analytics and automation
- Participate in special projects, as needed, and perform other duties as assigned
- Produce System Analytics to prove automation behaviour assumptions
- Document all system changes in line with Change Management good practices
- Recommend, Develop and Release new Use Cases to maximize the benefits and efficiencies from a SOAR platform.
- Mentor junior members of the SOAR team.
- Complete Quality Assurance on work completed by other members of the team before it is implemented in production.
Skills, Knowledge and Expertise
- Experience with Splunk, Splunk Enterprise Security, Splunk SOAR (Formerly Splunk Phantom) and Splunk User Behaviour Analytics
- Develop, and implement automations for detection and response.
- Produce System Analytics to prove automation behaviour assumptions
- A passion for security automation and a solid understanding of security incident response
- Knowledge of security frameworks including MITRE ATT&CK, NIST, etc.
- Working experience and knowledge of operating systems (e.g.: Windows, UNIX/Linux) and databases
- Knowledge in various scripting and programming languages (Java, Perl, R, Python, C++)
Desirable:
- Understanding of NIS regulations
- Understanding of CNI and ideally the Energy Sector. Ideally having worked on a CNI environment/client.
- Understanding of NCSC CAF and IT/OT controls such as NIST
- Integration of SOAR (Splunk) with OT specific IDS such as Nozomi, Claroty, Dragos, etc.
- Playbook development.
Benefits
We have a high-performance culture which is balanced evenly with world-class well-being initiatives and benefits:
- Flexible Working: Balance your work and personal life with our flexible working options.
- Generous Holiday Allowance: Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
- Financial & Investment Benefits: Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
- Community & Volunteering Programmes: Make a difference in your community with our volunteering opportunities.
- Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
- Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
- Special Time Off: Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
- Family Planning: Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.
SOAR Engineer (SPLUNK) employer: NCC Group
NCC is an exceptional employer, offering a dynamic work culture that prioritises flexibility and employee well-being in the heart of Cheltenham. With generous holiday allowances, comprehensive financial benefits, and a strong commitment to community engagement, employees are empowered to grow both personally and professionally while contributing to cutting-edge cyber threat intelligence initiatives.