Cybersecurity Automation Engineer, SOAR & Python
Overview
You will build security automation solutions for Booz Allen's Enterprise Cybersecurity division, hardening defenses across the company and its clients. You'll integrate Python scripts and APIs into the existing SOAR platform to automate incident response and threat management. Your work directly supports cybersecurity operations teams, capturing requirements and deploying automation that scales to match evolving threats. This role offers the chance to shape security infrastructure with AWS, Splunk, and Kubernetes at enterprise scale.
What You'll Do8
- 1Design and implement Python-based integrations to connect security tools with the SOAR platform.
- 2Manage and maintain existing automation workflows, ensuring uptime and reliability for incident response.
- 3Capture requirements from cybersecurity operations teams and translate them into automation solutions.
- 4Build and refactor playbooks in Swimlane, Phantom, or ServiceNow to streamline threat handling.
- 5Debug and resolve feature requests and bug reports from security analysts.
- 6Develop test plans for new integrations, validating performance and security posture.
- 7Explore new automation areas, adopting tools like Docker and Kubernetes to improve scalability.
- 8Document automation architecture and processes for cross-team knowledge sharing.
Requirements10
- 14+ years programming with Python, REST APIs, and SOAP APIs.
- 23+ years with network and system management tools, including Splunk, Carbon Black, CrowdStrike, or ArcSight.
- 33+ years developing playbooks on SOAR platforms such as Swimlane, Phantom, ServiceNow, or Demisto.
- 4Experience in security operations, incident response, or threat management.
- 5Experience with cloud providers: AWS, Azure, or Google Cloud.
- 6Proven ability to create and execute test plans for new integrations.
- 7Skilled at identifying automation improvements and prototyping solutions.
- 8Ability to obtain a Secret clearance.
- 9Bachelor's degree in a technical field.
- 10Nice to have: Elasticsearch, Logstash, Kibana, and Docker experience.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
631 Booz Allen Hamilton_United States
VerifiedDevSecOps Engineer and SME
Lead DevOps Engineer at Booz Allen Hamilton Washington DC. Oversee team streamlining software development lifecycle from requirements to monitoring. Implement CI/CD pipelines reduce manual tasks empower developers to focus on creating impactful solutions.
Zoox
VerifiedSenior Information Security Engineer Detection Automation AI Zoox
We seek a Senior Information Security Engineer who designs detection systems and automates workflows. You will architect SIEM logic map detections to MITRE ATT&CK reduce false positives and build SOAR playbooks. Implement LLM‑powered triage pipelines and act as senior escalation point for incidents across AWS and on‑premise environments. This role drives security operations as code and shapes a fast‑moving team.

BCforward
VerifiedCyber Security Engineer, SOC & Incident Response
Own security monitoring and incident response for a Fortune 500 client in Phoenix, AZ. You will join BCforward's security operations team, working onsite to detect, investigate, and mitigate threats across a hybrid cloud and on-premise environment. This role demands hands-on expertise with SIEM platforms and EDR tools, with a direct impact on the client's security posture.
631 Booz Allen Hamilton_United States
VerifiedCyber Machine Learning Engineer Senior Booz Allen Hamilton
Lead design and deployment of machine learning solutions for cyber defense at Booz Allen. Own development of scalable detection systems for DoD federal and commercial clients. Drive innovation using Python and Kubernetes. Shape the future of national security through cutting edge technologies.

Conquest Consulting
VerifiedSenior SOC Detection Engineer CrowdStrike Falcon & SOAR AI
Lead detection engineering for CrowdStrike Falcon and SOAR platforms. Own and scale threat detection solutions. Drive platform improvements. Shape security operations strategy. Differentiate by delivering proactive threat intelligence.
020 Cisco Systems, Inc.
VerifiedSecurity Engineer at Cisco Systems
Join the Talos Security Operations Team as a Security Engineer to protect assets and systems in a fast‑paced environment. You will own security automation and drive improvements across hybrid infrastructures. This role offers a chance to work with industry leaders and make a tangible impact on global security.