Security Orchestration, Automation & Response
Quick Summary
JOB SUMMARY Under the direction of the Chief Information Security Officer, the Security Orchestration, Automation, and Response (SOAR) Engineer is responsible for the development, implementation,
Under the direction of the Chief Information Security Officer, the Security Orchestration, Automation, and Response (SOAR) Engineer is responsible for the development, implementation, and administration of UConn’s security automation capabilities, including its infrastructure and systems, in support of the University’s Information Security Office. The engineer designs, builds, and maintains automated security workflows, integrations, and response playbooks that improve the efficiency and effectiveness of cybersecurity operations across the University’s academic, research, and administrative environments. Additionally, this role develops and supports technical solutions that strengthen threat detection, incident response, and operational resilience through the integration of security technologies, data sources, and industry best practices.
The SOAR Engineer is responsible for investigating and resolving a diverse range of security operations, automation, and technical issues across multiple platforms, working with a broad range of University stakeholders whose technical skills range from minimal to extensive. The engineer works among a team of skilled information security and IT professionals to address problems within a complex University environment and develop solutions that fit into that environment.
The SOAR Engineer is responsible for processes and procedures to ensure the continuous improvement of monitoring, detection, and mitigation capabilities. The engineer plans, organizes and establishes priorities related to an assignment; works independently with minimal outside support; and handles sensitive information in a confidential manner.
- Security Orchestration, Automation & Response Engineer 2 (Information Security Analyst 2 – UCP 6): $84,880 to $115,427
- Security Orchestration, Automation & Response Engineer 3 (Information Security Analyst 3 – UCP 7): $95066 to $129,289
Note: Please indicate the role you are applying for in your cover letter. All minimum qualifications must be met at the applicable level to be eligible for consideration at that level. Applicable role will be verified by the hiring committee with respect to qualifications and demonstrated experience. Salary will be commensurate with experience within the established range.
What We Offer
~1 min readResponsibilities
~1 min read- →Serves as domain and subject matter expert in one or more information security domains.
- →Leads the design, development, implementation, and maintenance of university security automation, monitoring, and/or incident response systems.
- →Designs, implements, and maintains new security solutions.
- →Leads the development and support of UConn’s security infrastructure, including but not limited to SIEM, SOAR, EDR/XDR, logging, identity and access management, forensic capabilities, and others.
- →Leads major projects and initiatives related to cybersecurity operations, engineering, automation, and incident response capabilities.
- →Develops and maintains integrations between enterprise security systems, operational platforms, and data sources.
- →Identifies enterprise-level security gaps, performs risk assessments, and recommends solutions to improve detection, response, visibility, and operational resilience.
- →Creates custom code, API/REST integrations, automation workflows, and maintainable tooling to facilitate data collection, orchestration, and information sharing across systems and platforms.
- →Assists in the development of operational procedures, response standards, metrics, and security operations best practices.
- →Provides technical leadership and mentoring to junior staff and project teams as appropriate.
- →Operates autonomously within general guidance and with limited supervision.
- Administer and use security tools to identify, investigate, analyze, and mitigate threats to the environment.
- Assists with the development and support of UConn’s security infrastructure, including but not limited to SIEM, SOAR, EDR/XDR, logging, identity and access management, forensic capabilities, and others.
- Develops, maintains, and supports automated workflows, integrations, scripts, and playbooks to improve security operations and incident response processes.
- Participates in cybersecurity incident response activities including triage, analysis, containment, eradication, recovery, and post-incident review activities.
- Produces and maintains detailed engineering plans, operating procedures, diagrams, workflows, standards, and documentation related to security operations and automation platforms.
- Proactively analyzes logs, alerts, telemetry, and security events to identify threats, intrusions, suspicious behavior, and/or compromises.
- Assists other information security domain owners and IT teams with operational security activities, investigations, troubleshooting, and implementation efforts as needed.
- Triages and responds to service requests, operational issues, and escalations.
- Maintains awareness of current and emerging threats, vulnerabilities, attack techniques, and industry trends.
- Maintains appropriate documentation and diagrams of infrastructure and security systems.
- Promote security awareness and best practices to improve the overall security posture of the University.
- Participates in on-call rotation, after-hours changes, and security escalations as needed.
- Performs other related duties as assigned.
- Must meet and maintain eligibility requirements associated with working on CUI/CTI data, such as but not limited to holding U.S. citizenship or permanent residency, at the level required and as determined by the Facility Security Officer and the Office of Export Control.
- Bachelor’s degree and two (2) years of related experience (IT/Security), OR Associate’s degree and four (4) years of related experience (IT/Security), OR Six (6) years of related experience (IT/Security)
- One (1) or more years of experience working in an information security role in the security automation domain.
- Experience applying knowledge of SIEM concepts including log collection, event correlation, alerting, parsing/normalization, data ingestion, monitoring, and security analytics.
- Experience applying knowledge of SOAR platforms, security automation workflows, incident response processes, API integrations, and orchestration concepts.
- Experience with security monitoring, incident analysis, threat detection, or operational security investigations.
- Experience administering enterprise SIEM and/or SOAR platforms such as Microsoft Sentinel, Splunk Enterprise Security/SOAR, Cortex XSOAR, QRadar, or similar technologies.
- Experience developing searches, alerts and reports using knowledge of SIEM query languages such as Splunk Query Language (SPL), Kusto Query Language (KQL), CrowdStrike Query Language (CQL), or similar query languages.
- Experience programming or scripting using Python, PowerShell, Bash, or similar scripting languages.
- Experience with security analysis, operational procedures, policies, standards, and incident response practices.
- Demonstrated technical, analytical, interpersonal, and organizational skills.
- Bachelor’s degree or higher in a Science, Technology, Engineering, Math (STEM) field.
- Demonstrated ability to stay informed in securing evolving technologies.
- Demonstrated understanding of a wide array of enterprise applications/services including DNS, SMTP, SSL/TLS, IIS, Apache, LDAP, CAS, Entra, Azure/AWS, SQL, Splunk, KQL, etc.
- Experience using forensics and deception technologies.
- Experience working in and applying related security domain concepts including Identity & Access Management, Security Operations, Application Security, Risk Management, and Incident Management.
- Experience working in a higher education environment.
- Problem Solving: Demonstrates sound analytic and diagnostic skills dealing with issues that are loosely defined and/or where information is available but must be further manipulated. Once decisions are made, you can follow and direct action to implement intended results. Breaks a problem down to manageable pieces and implements effective, timely solutions. Openly and directly confront issues until resolved.
- Team Orientation: Builds relationships with peers and other departments to achieve objectives. Balances team and individual responsibilities. Exhibits objectivity and openness to others’ views. Gives and welcomes feedback. Puts success of team above self. Responsibilities are assigned with some latitude for setting priorities and decision-making using established policies and procedures. Results are reviewed with next-level team lead/manager for clarification and direction before proceeding.
- Planning and Project Management: Works with, or serves as, the project lead in identifying those project tasks that are most important, establishes clear priorities and understands the larger picture. Executes project tasks and creates documentation as required.
- Physical Demands: This position involves extended periods of sitting and the extensive use of computers and office equipment.
Requirements
~1 min read- Bachelor’s degree and four (4) years of related experience (IT/Security), OR Associate’s degree and six (6) years of related experience (IT/Security), OR Eight (8) years of related experience (IT/Security)
- Three (3) or more years of experience working in an information security role in the security operations/monitoring domain as an engineer.
- Experience designing, deploying and administering complex alerts, searches, APIs, orchestration, automation, and security management systems in an enterprise environment.
- Demonstrated familiarity with IT Security frameworks and relevant regulatory obligations and audit requirements (GDPR, SOX, NIST, ISO, PCI, FERPA, HIPAA, and/or AICPA/SOC2)
- Senior level Security Engineer experience.
- Experience securing and supporting both on-premises and cloud-based enterprise environments.
- Experience developing, configuring, and troubleshooting automated incident response workflows and security orchestration playbooks.
- Senior-level experience with SIEM and/or SOAR platforms such as Microsoft Sentinel, Splunk Enterprise Security/SOAR, Cortex XSOAR, QRadar, or similar technologies.
- Experience integrating EDR/XDR, vulnerability management, identity management, email security, cloud security, and ticketing systems into SIEM/SOAR platforms.
- Experience developing automation and orchestration with iPaaS tools such as Boomi or similar technologies.
- Experience deploying, administering, operating, and troubleshooting enterprise security monitoring and case management systems.
- Experience deploying, administering, and operating forensics and deception technologies.
- Experience developing and maintaining integrations using REST APIs, webhooks, or related automation technologies.
- Experience with threat detection, incident response, digital forensics, or threat intelligence operations.
- Experience with monitoring and observability platforms used to support cybersecurity operations.
- Experience evaluating cybersecurity technologies, vendors, licensing, pricing, terms, and conditions.
- CISSP, GSEC, GCIH, GCIA, CASP+, Splunk Enterprise Certified Admin, or other senior-level cybersecurity or security operations certification.
This is a full-time, permanent position located at the Storrs Campus in Storrs, CT. This position is on-site. THIS IS NOT A REMOTE POSITION. The position may be eligible for a hybrid work schedule under applicable bargaining agreements, not less than an annual review, and management approval. This position may require you to travel in-state and you may be required to work irregular hours to support operational or security activities and initiatives.
The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment.
Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).
Employment of the successful candidate is contingent upon the successful completion of a pre-employment criminal background check. The successful candidate must be determined to be and remain eligible to work with CUI/CTI data as determined by the Facility Security Officer and the Office of Export Control.
Please apply online at Faculty and Staff Positions, Search #499688 to upload a resume, cover letter, that demonstrates how you meet the minimum qualifications for this position and contact information for three (3) professional references. Applicants must clearly demonstrate how they meet the stated minimum qualifications, and any preferred qualifications they may possess, in their application materials.
This job posting is scheduled to be removed at 11:55 p.m. Eastern time on August 10, 2026.
All employees are subject to adherence to the State Code of Ethics.
All members of the University of Connecticut are expected to exhibit appreciation of, and contribute to, an inclusive, respectful, and diverse environment for the University community.
The University of Connecticut aspires to create a community built on collaboration and belonging and has actively sought to create an inclusive culture within the workforce. The success of the University is dependent on the willingness of our diverse employee and student populations to share their rich perspectives and backgrounds in a respectful manner. This makes it essential for each member of our community to feel secure and welcomed and to thoroughly understand and believe that their ideas are respected by all. We strongly respect each individual employee’s unique experiences and perspectives and encourage all members of the community to do the same. All applicants will receive consideration for employment without regard to race, color, ethnicity, religion, age, sex, marital status, national origin, ancestry, sexual orientation, genetic information, physical or mental disabilities, veteran’s status, status as a victim of domestic violence and/or sexual assault and/or trafficking in persons as defined by Connecticut law, prior conviction of a crime, workplace hazards to the reproductive systems, or gender identity or expression.
The University of Connecticut is an AA/EEO employer including for Disability and Veteran status.
Advertised: Eastern Daylight Time
Applications close: Eastern Daylight Time
Location & Eligibility
Listing Details
- First seen
- July 27, 2026
- Last seen
- July 27, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 51%
- Scored at
- July 27, 2026
Signal breakdown
Please let University of Connecticut know you found this job on Jobera.
3 other jobs at University of Connecticut
View all →Explore open roles at University of Connecticut.
Similar Security jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.