Senior SOAR Engineer
Adobe
- Location
- Lehi
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 221 approvals (FY2023)
- Posted
- Aug 17, 2026
Skills
About this role
The Opportunity
Detection & Automation Engineering operates Adobe's detection and response backbone, closing the gap between detection and containment. As a Senior SOAR Engineer, you'll build, develop, and maintain production automation playbooks that reduce mean-time-to-respond. You'll collaborate with Detection Engineering to transform new detection rules into effective response actions. You'll also assist CSIRT/SOC Operations with enrichment and correlation logic. And you'll deliver Incident Response containment playbooks for live incidents. Join us if you're ready to make a world-class impact!
What you'll Do
Build, develop, and maintain SOAR playbooks that automate enrichment, correlation, and containment across the security stack. Work alongside Detection Engineering for every new detection rule that calls for a response action. They outline the logic, and you build and verify the automation. Support CSIRT/SOC Operations by adjusting automation related to data enrichment and event association. This reduces analyst triage time and improves signal quality. Own containment and remediation automation for Incident Response, including identity- and access-related response actions used during live incidents. Build and maintain policy-enforcement automation, ensuring upstream access and control decisions complete reliably, without gaps. Integrate SOAR with ecosystem tooling — identity providers, endpoint/EDR, ticketing systems — using built-in apps and REST APIs, or custom connectors when they don't exist. Triage production playbook issues as an operational priority, and track metrics for automation coverage, reliability, and time-to-remediate. Assist in Detection-as-Code integration following Detection Engineering's current standards, and record playbook logic for collective team ownership. Actively find ways to integrate AI into day-to-day work — playbook development, script writing, enrichment logic, triage, incident summarization, testing, and documentation. What you need to succeed Required: 7+ years in security engineering, security automation, or a closely related field. Hands-on experience building and maintaining SOAR playbooks (Splunk SOAR, Tines, XSOAR, etc.). Advanced proficiency in Python (or comparable scripting language) for custom actions, connectors, and playbook logic. Practical understanding of incident response and SOC triage workflows. Experience connecting SOAR with detection/SIEM platforms (Splunk or similar), identity/access solutions, and ticketing/case management systems through REST APIs. Ability to work independently on unstructured problems, making defensible, risk-based decisions on containment/response logic. Strong written and verbal communication. You'll detail playbook reasoning for engineers and explain the same tradeoffs to non-technical collaborators. Hands-on experience using AI-assisted development tools (e.g., Claude Code, Copilot, Cursor), and judgment on when they help. Preferred: Experience with identity/access systems (e.g., Okta, Entra ID) for containment tasks such as session revocation or account disabling. Comfort with both low-code playbook building and pro-code extensions, writing custom Python when built-in logic isn't enough. Experience with event-driven architectures and webhook-based integrations, beyond standard polling REST calls. Proficiency in more than one scripting or development language (e.g., PowerShell, Bash, Go) beyond Python. A track record of pushing AI tooling beyond baseline usage — custom prompts, agents, or workflows for playbook and script work. Familiarity with Detection-as-Code practices and CI/CD for security content. Experience mentoring other engineers or serving as a technical point of contact for automation work. Background supporting compliance-relevant controls where automation failures have audit implications. Relevant certifications (e.g., Splunk SOAR Certified Automation Developer, GCIH, CISSP) a plus but not required. About Adobe