Quick Overview
Job Description
Position: SOAR Automation Engineer
Location: Washington, DC
Visa: independent visa holder
Randstad is seeking a Senior SOAR Automation Engineer for a contract engagement with a premier enterprise transportation client. Reporting within the Cyber Advisory Governance and Enablement (CAGE) group, this role focuses heavily on workflow execution, low-code/no-code automation, and API development rather than traditional incident response. Working alongside a Lead SOAR Architect, you will optimize governance, risk, and compliance (GRC) capabilities within the Swimlane platform to build a single-pane-of-glass view across the organization's security stack. You will conduct technical discovery with stakeholders, build custom widgets and dashboards, and create scalable playbooks that automate complex security and operational workflows.
Key Responsibilities
- Swimlane Workflow Development: Design, build, and optimize automated playbooks, workflows, custom widgets, and user interfaces within the Swimlane SOAR platform.
- API & System Integration: Develop custom API connectors and data pipelines to integrate Swimlane with enterprise security tools, IT service management systems (e.g., ServiceNow), CMDBs, and cloud environments.
- Process & GRC Automation: Streamline risk triage, escalation, and compliance workflows; normalize operational datasets; and implement error handling, logging, and performance monitoring.
- Requirements & Stakeholder Engagement: Conduct technical discovery sessions to translate business and security needs into user stories, epics, technical specifications, and functional playbooks.
- Governance & Documentation: Maintain strict change controls, data validation standards, and technical documentation across all automation pipelines to support ongoing audit and compliance initiatives.
Qualifications
- Core SOAR Expertise: 3 to 5 years of hands-on experience developing and deploying automated playbooks, with strong preferred expertise in Swimlane. (Experience with Splunk SOAR or Microsoft Sentinel will be considered with transferable development skills.)
- Development Focus: Proven background in workflow engineering, software development, or API integrations (Python, REST APIs, JSON) rather than a pure Security Operations Center (SOC) or Incident Response (IR) background.
- Data & Interface Customization: Experience building custom forms, dashboards, reporting analytics, and dataset enrichment pipelines within security automation tools.
- Systems Familiarity: Working knowledge of cloud platforms (AWS, Azure, M365), ticketing systems, and hybrid enterprise infrastructure.
- Collaborative Mindset: Strong communication skills to gather requirements from non-technical stakeholders and collaborate effectively with lead architects and peer developers in an Agile environment.
Similar jobs
- CB
Information Security Analyst
NewCobalt Benefits Group LLC
Manchester, New Hampshire🇺🇸Hybrid1 hour agoPowerShellGenerative AISOC 2+2Technology - DO
IT Cybersecurity Specialist (Infosec) with Security Clearance
NewDepartment of Defense
Lakehurst, NJ🇺🇸HybridYesterdayTechnology - TA
Security Operations Center Analyst - Part Time with Security Clearance
NewTelaforce, a Titan Technologies company
Honolulu, HI🇺🇸$19/hrOn-siteYesterdayLESSMicrosoft WordTechnology - QU
Senior Cyber Intel Associate with Security Clearance
NewQuantech
Hanscom AFB, MA🇺🇸$115k/yrHybridYesterdayAzureTechnology - PA
Penetration Tester, Mid (TS/SCI Clearance) with Security Clearance
NewPraescient Analytics
Arlington, VA🇺🇸$90k - $130k/yrHybridYesterdayMachine LearningOWASPBash+3Technology - DE
Endpoint Security Engineer - 100% Remote - 1+ Year Contract
NewDexperts Inc
United States🇺🇸RemoteYesterdayTechnology