Job Summary
Experience:
5.00 - 8.00 Years
Industrial Type:
IT-Hardware & Networking
Location:
Mumbai
Functional Area:
IT Software - Client Server
Designation:
Senior SOAR Engineer
Key Skills:
(SIEM OR "Security Information and Event Management") AND Python
Educational Level:
Graduate/Bachelors
Job Post Date:
2026-07-30
Stream of Study:
Degree:
BCA, BE-Comp/IT, BE-Other, BSc-Comp/IT, BSc-Other, BTech-Comp/IT, BTech-Other, MCA, ME-Comp/IT, ME-Other, MSc-Comp/IT, MSc-Other, MTech-Comp/IT, MTech-Other
Company Description
Our Client is built on an AI-first, technology-agnostic approach to cybersecurity - engineered to outpace evolving threats, maximize ROI from existing investments, and strengthen enterprise-wide secu rity posture. Our Client help organizations tackle complex cybersecurity challenges with intelligence-led, outcome-focused services - delivered by experts with deep real-world experience to drive tangible business outcomes.
Job Description
Job Location: Airoli, Navi Mumbai (Client Location)
5 days Work from Office - General Shift
About the Role
We are looking for an experienced and driven SOAR Engineer to join our growing SOC Services team. The candidate will be responsible for designing, building, and maintaining automated playbooks and integrations within the SOAR platform. The role focuses on automation engineering, API integrations, scripting, and the orchestration of security tools to streamline incident response processes.
Key Responsibilities
1. Design and build automated playbooks for incident types such as: Phishing
investigations, Malware alerts, Suspicious authentication, Privilege misuse enrichment workflows.
2. Implement conditional logic (if/else, loops), Parallel execution flows, Automated enrichment steps, Escalation and approval workflows.
3. Convert manual SOC runbooks into fully automated workflows.
4. Build dynamic playbooks driven by alert severity and risk score.
5. Develop integrations with- SIEM, EDR/XDR, Firewall, Email security platforms, IAM, threat Intelligence platforms, ticketing systems such as Service Now.
6. Build custom integrations with REST APIs, Web hooks, and Python-based connectors.
7. Conduct regression testing after playbook creation/updates using synthetic data.
8. Troubleshooting failed automation, runbooks, and integration errors.
9. Maintain end-to-end documentation from conceptual, requirement gathering, to playbook production- sign-offs.
Required technical skill sets
10. Hands-on experience with at least one SIEM platform.
11. Strong Python scripting skills (mandatory) with knowledge of PowerShell/bash.
12. Experience with rest API’s, JSON & XML parsing, API authentication mechanisms,
Webhooks.
13. Experience developing custom connectors.
14. Experience with SIEM architecture, SOC incident response lifecycle, MIRTE Framework.
Required Experience
15. 5-6 years of hands-on experience in managing an enterprise SIEM platform.
16. Strong playbook building knowledge.
17. Proven track record in SOAR management, playbook building, and new data sources and integration.


