Splunk SOAR Engineer

Venatore Llc
Tampa, FL, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Computing Platforms Cloud Computing Security Cyber Security Linux Issue Tracking Systems Information Model Interoperability Intrusion Detection and Prevention Python (Programming Language) Log Analysis Network Protocols
+20 more
Performance Tuning Phishing Data Streaming Systems Integration Data Logging Data Processing Power Platform Integration System Availability Mitre Att&ck Mttr Git Containerization Kubernetes Cortex XSOAR Platform Restful APIs Splunk Software Version Control Docker Security Orchestration, Automation & Response Vulnerability Analysis

Job description

Venatore is seeking a Splunk SOAR Engineer to support U.S. Central Command (USCENTCOM) operations by designing, implementing, and optimizing enterprise-level Security Orchestration, Automation, and Response (SOAR) capabilities. This role is responsible for transforming manual incident response processes into scalable, automated workflows that accelerate threat detection, containment, and remediation. The Splunk SOAR Engineer will lead the full lifecycle of platform architecture, integration, content development, and performance optimization while collaborating closely with SOC analysts, threat hunters, and incident response teams. An active TS/SCI clearance is required.

Responsibilities

Platform Architecture & Engineering

  • Design, deploy, document, and maintain distributed Splunk SOAR (Phantom) platform architecture to ensure high availability, scalability, and performance.

  • Support system upgrades, patching, and performance tuning across the SOAR infrastructure.

  • Provide advanced troubleshooting and resolution of platform issues and playbook execution errors.

  • Adhere to security best practices and compliance requirements within the operational environment.

Playbook Development & Automation

  • Develop, customize, and maintain complex SOAR playbooks using Python and the Phantom Playbook Editor for automated enrichment, triage, containment, and remediation of security incidents (e.g., phishing, malware, unauthorized access).

  • Translate manual security procedures into robust, automated workflows aligned with SecOps best practices.

  • Establish and track automation metrics, including utilization rates, automation coverage, and Mean Time to Respond (MTTR) improvements.

Integration & Interoperability

  • Integrate Splunk SOAR with Splunk Enterprise Security (ES) and other core security technologies, including EDR/XDR platforms, firewalls, vulnerability scanners, threat intelligence platforms, and ticketing systems.

  • Develop custom apps and integrations to connect proprietary or unsupported security tools using RESTful APIs and custom connectors.

  • Manage and optimize data flow between Splunk ES and Splunk SOAR to ensure effective event-triggered automation actions.

Collaboration & Documentation

  • Partner with SOC analysts, threat hunters, and incident response teams to gather requirements and document workflows.

  • Develop and maintain detailed technical documentation for platform configurations, integrations, and automation content.

  • Provide training and mentorship to SOC staff on SOAR usage, content development, and automation best practices.

  • Evaluate and integrate emerging security technologies and threat intelligence feeds into the automation ecosystem.

Requirements

  • Active TS/SCI security clearance.

  • U.S. citizenship.

  • Applicable DoD 8140 or DoD 8570 certification.

  • 8+ years of related experience in security engineering or security operations.

  • Hands-on expertise with Splunk SOAR (Phantom) administration, configuration, and maintenance in a distributed enterprise environment.

  • Advanced proficiency in Python scripting for playbook development, custom apps, and integrations.

  • Proven experience integrating SOAR platforms with Splunk Enterprise Security (ES), SIEMs, EDR/XDR tools, and other security technologies.

  • Strong understanding of security operations principles, incident response lifecycles, and threat detection methodologies.

  • Experience working with RESTful APIs and developing tool connectors.

  • Proficiency in data manipulation, log parsing, and understanding of the Common Information Model (CIM) in a security context.

  • Strong verbal and written communication skills with the ability to convey complex automation concepts to technical and non-technical audiences.

Preferred Qualifications

  • Familiarity with cloud security logging, containerization (Docker/Kubernetes), and CI/CD pipelines for playbook deployment.

  • Knowledge of the MITRE ATT&CK framework and its application in automated detection and response use cases.

  • Experience using Git or other version control systems for SOAR content management.

  • Familiarity with network protocols, Windows and Linux operating systems, and enterprise security architecture components.

  • Splunk Enterprise Security Certified Admin or Architect certification.

  • Splunk SOAR (Phantom) Certified Content Developer or Administrator certification.

  • Experience with other SOAR platforms (e.g., Palo Alto Cortex XSOAR, IBM Resilient).

  • Experience supporting USCENTCOM or multi-domain defense security operations environments.

  • ITIL 4 Foundation certification.

Benefits & conditions

Venatore offers a competitive benefits package designed to support the well-being of our employees, including:

  • Paid Time Off (PTO)

  • 10 Federal Holidays

  • 401(k) with company matching

  • Medical, dental, and vision insurance

  • Paid parental leave

  • Paid military leave

About the company

Venatore is a woman-owned small business headquartered in Tampa, Florida, providing mission-driven technology and professional services to federal defense and civilian agencies. We deliver expertise in information technology, engineering, logistics, and program support to help our clients achieve operational excellence and mission success.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

3:08 min

Aligning engineering processes with core business impact metrics

Chris Riley · WWC 2021

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

3:07 min

Establishing service level agreements directly for internal platforms

Pawel Piwosz · LIVE

Videos

See all

Related articles

See all