SOAR Automation Engineer at Dragonfli Group
United States
<h3>Description</h3> <p>Dragonfli Group is a cybersecurity and IT consulting firm providing services to federal agencies and Fortune 100 enterprises. Headquartered in Washington, DC, Dragonfli supports clients in securing mission-critical systems across on-site, hybrid, and fully remote environments.</p><p><br/></p><p>This SOAR Automation Engineer role supports a large U.S. federal agency by designing, implementing, and scaling security automation capabilities across a complex enterprise environment. The role is centered on Splunk Phantom (Splunk SOAR) and focuses on automating security operations, improving response and investigation workflows, and integrating AI-enabled enrichment using Azure AI services where appropriate.</p><p><br/></p><p>This is a hands-on technical role with strategic influence, combining deep engineering work with ownership of automation design and continuous improvement across SOC workflows.</p><p><br/></p><p>This is a W2 contract, fully remote (CONUS only) role, supporting a large federal agency. Prior federal contracting experience is preferred.</p><p><br/></p><p>U.S. Citizenship or Permanent Residency is required.</p><p><br/></p><p>Responsibilities:</p><ul><li>Design, build, and maintain SOAR automation using Splunk Phantom</li><li>Develop and enhance automated playbooks to support detection, response, and investigation workflows</li><li>Integrate SOAR with SIEM, security tools, cloud platforms, and on-prem systems</li><li>Apply AI-enabled enrichment and decision support using Azure AI services</li><li>Lead automation design decisions and guide SOC teams on effective SOAR usage</li><li>Improve dashboards, metrics, and operational visibility tied to automated workflows</li><li>Collaborate with security analysts, engineers, and stakeholders to identify automation opportunities</li><li>Operationalize and scale automation across the security lifecycle</li><li>Ensure reliability, maintainability, and documentation of automation solutions</li></ul> <h3>Requirements</h3> <p>Must-Have</p><ul><li>4+ years of experience building and supporting SOAR / security automation solutions in enterprise environments</li><li>Hands-on experience with Splunk Phantom (Splunk SOAR)</li><li>Strong background in security workflow automation and playbook development</li><li>Experience integrating cloud and on-premise systems via APIs</li><li>Working familiarity with Azure AI services and applied AI use cases in cybersecurity</li><li>Strong problem-solving and analytical skills</li><li>Ability to collaborate across technical and non-technical teams</li><li>Excellent written and verbal communication skills</li><li>Bachelor’s degree in a cyber-related field or equivalent experience/certifications</li></ul><p>Nice-To-Have</p><ul><li>Federal cybersecurity environments</li><li>SOC operations and incident response workflows</li><li>Python or scripting for automation</li><li>SIEM integration (Splunk Enterprise / Splunk ES)</li><li>Familiarity with NIST cybersecurity frameworks</li></ul><p><br/></p><p><br/></p> <h3>Skill(s)</h3> <ul><li>Expertise in SOAR and AI technologies.</li></ul><ul><li>Strong technical and analytical skills.</li></ul><ul><li>Ability to work collaboratively with security teams.</li></ul><ul><li>Proficiency in developing automated security workflows.</li></ul><ul><li>Experience with cloud and on-premise system integration.</li></ul><ul><li>Strong communication and planning abilities.</li></ul><ul><li>Problem-solving and critical thinking skills.</li></ul><ul><li>Familiarity with cybersecurity frameworks and standards.</li></ul> <h3>Benefits</h3> <ul><li>Insurance – health, dental, and vision</li></ul><ul><li>Paid Time Off (PTO) and 11 Federal Holidays</li></ul><ul><li>401(k) employer match</li></ul> <h3>Travel</h3> None
Apply Now