Now hiring

Journeyman SOAR Engineer @ Shorepointinc

Las Vegas, NevadaOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Who we are:

ShorePoint is a fast-growing, industry-recognized and award-winning cybersecurity services firm focused on high-profile, high-threat public and private sector customers who demand experience and proven security models to protect their data. We embrace a “work hard, play hard” mentality and celebrate individual and company successes. We are passionate about our mission and going above and beyond to deliver for our customers, while fostering an environment that supports creativity, accountability, mission success, critical thinking and a desire to give back to our community.

The Perks:

As recognized members of the Cyber Elite, we work together in partnership to defend our nation’s critical infrastructure while building meaningful and exciting career development opportunities in a culture tailored to the individual’s technical and professional growth. We are committed to the belief that our team members do their best work when they are happy and well cared for. In support of this philosophy, we offer a comprehensive benefits package, major carriers for healthcare providers. Highlighted benefits include 144 hours of PTO, 11 holidays, 85% of insurance premiums covered, a 401(k), continuing education, certification maintenance and reimbursement and more.

Who we’re looking for:

We are seeking a Journeyman SOAR Engineer with deep cybersecurity expertise and automation capabilities to strengthen the detection security & automation utilized across various log sources, teams and tools within the central Security Information and Event Management (SIEM). This role supports Zero Trust and DevSecOps initiatives, enforces compliance and streamline operations through secure architecture design, automation and advanced threat detection. The Journeyman SOAR Engineer will play a critical role in building better detection logic, implementing automation within the detection & response, as well as serving as the Subject Matter Expert (SME) for the Security Orchestration, Automation and Response (SOAR) technologies. This is a unique opportunity to shape the growth, development and culture of an exciting and fast-growing company in the cybersecurity market.

What you’ll be doing:

• Serve as SME for SOAR technologies, detection logic, detection alerts and automation techniques implemented in the environment.

• Integrate automated detection logic for tools into CI/CD pipelines (e.g., Bitbucket, Jenkins, Git).

• Support automating detection logic with various log sources in a central SIEM utilizing various security & compliance tools.

• Fully managing & maintaining the detection lifecycle alongside assisting in implementing automated response within the detection lifecycle

• Monitor and manage SIEM tools (e.g., Azure Sentinel, SPLUNK) and log analytics for threat detection and operational insights.

• Automate security and operational tasks through scripting and platform-native automation tools (e.g., Splunk SOAR, Python, PowerShell).

• Contribute to risk assessments, Authorization to Operate (ATO) documentation and policy enforcement strategies.

• Assist with token management, certificate renewal automation and credential lifecycle tasks.

• Support performance monitoring, system patching and endpoint protection across the cloud landscape.

• Assist in the implementation of automation within the various SOC teams being supported within the environment.

What you need to know:

• Strong understanding of SOAR technologies, MITRE ATT&CK, MITRE D3FEND and SIEM technologies

• Proficiency in integrating automation & detections into SOC workflows within a central SIEM

• Knowledge of Git and how it is utilized within an environment.

• Hands-on experience with SIEM platforms and log analytics.

• Hands-on experience with SOAR technologies and platforms alongside integrating them into various toolsets for automated tasks.

• Basic Linux skills & knowledge of Linux platform technologies

• Ability to support ATO documentation, compliance activities and enforcement of security policies.

• Skilled in scripting for security automation using platform-native tools and languages.

Must have’s:

• Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Mathematics, Engineering or a related field.

• 5+ years of experience in:

• Cybersecurity Expertise and Automation.

• Designing and implementing automated operations across security tools and integrating into a central SIEM for SOC alerting.

• Proficient with SOAR tools (Tines, Splunk SOAR, XSOAR) and automation scripting (PowerShell, Python).

• DoD cybersecurity frameworks (RMF, NIST 800-53, STIGs).

• Experience with CI/CD pipelines, Gitlab and security integration.

• Strong understanding of networking, firewalls and role-based access control (RBAC).

• Analyzing logs and security alerts and develop proactive countermeasures.

• Proven ability to analyze complex requirements and translate them into clear, actionable tasks and processes through critical thinking.

• Applicants must hold and maintain an active DOE Q or equivalent DoD Top Secret clearance.

Beneficial to have:

• Master’s degree in Cybersecurity, Information Systems or a related technical discipline.

• Experience with cloud security automation tools in AWS and Azure.

• Proficiency with containerization and orchestration technologies such as Docker and Kubernetes.

• Knowledge of DevSecOps best practices.

Where it’s done:

• Onsite (Las Vegas, NV).

Skills

Staff

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores