Security Automation Specialist SOAR Consultant

Winged IT REMOTE 2026-08-19

Your skills and experiences:

  • 2–3 years of experience in Security Operations, Security Engineering, Security Automation, SOC, or a similar area. 
  • Hands-on experience with at least one SOAR platform, e.g. Torq, Palo Alto XSOAR, Splunk SOAR, Tines, Swimlane, or another comparable solution. 
  • Torq experience is not required — practical SOAR experience and willingness to learn Torq are sufficient. 
  • Good understanding of SOC processes and incident response workflows. 
  • Experience with REST APIs, JSON, authentication mechanisms, and webhooks. 
  • Experience with at least one SIEM platform such as Microsoft Sentinel, Splunk, QRadar, or Elastic. 
  • Knowledge of EDR technologies such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or Carbon Black. 
  • Scripting skills in Python, PowerShell, or a similar language. 
  • Familiarity with Azure, AWS, or GCP. 
  • Very good communication skills and ability to work independently in an international environment. 
  • Fluent English. 

Employer: International Pharmaceutical Company

Location: Remotely from Poland

Working hours: 3:00 PM–11:00 PM Polish time

Cooperation model: B2B

Start date: ASAP

Recruitment process: 2-3 online interviews

For our client, a global organization, we are looking for a Security Automation Specialist / SOAR Consultant to support security operations, automation, and incident response processes within a large enterprise environment.

The role combines SOAR engineering, security automation, SIEM support, and operational consulting. We are looking for someone with around 2–3 years of relevant experience, hands-on experience with any SOAR platform, and a strong interest in developing further with Torq.

Your role is:

  • Designing, maintaining, and improving automated security workflows within a SOAR environment.
  • Supporting SOC and incident response processes through automation.
  • Handling security-related tickets, operational requests, and workflow issues.
  • Automating use cases such as phishing, malware, suspicious authentication activity, and other security alerts.
  • Integrating security tools using REST APIs, webhooks, and custom connectors.
  • Enriching alerts with data from SIEM, EDR, identity, ticketing, and threat intelligence platforms.
  • Troubleshooting and optimizing existing security automations.
  • Working with security teams to identify processes that can be automated and improved.
  • Building hands-on expertise in Torq as part of the project.

Our client offers:

  • Great opportunity for personal development in a stable and friendly large multinational company.
  • Career growth and additional education.
,[] Requirements: Security, PM, Use cases, REST API, EDR, Palo Alto, Splunk, JSON, Python, PowerShell, Azure, AWS, GCP, Communication skills Additionally: Career growth.