Tech Stack
AWSAzureCloudCyber SecurityGoogle Cloud PlatformJavaScriptPython
About the role
- Design, implement, and maintain SOAR playbooks to automate routine security tasks and incident response processes.
- Develop and maintain integrations between the SOAR platform and security tools such as SIEM, EDR, DLP and threat intelligence feeds.
- Collaborate with various teams to identify automation opportunities and improve response times.
- Work with cross-functional teams to gather requirements, design solutions, and ensure alignment with business objectives.
- Develop metrics to measure the effectiveness of automated workflows and identify areas of improvement.
- Provide training and documentation to CSOC analysts and other stakeholders on SOAR platform capabilities and playbook usage.
- Provide technical support to maintain our SOAR platform.
Requirements
- Undergraduate degree in Computer Science or Information Technology-related field or equivalent combination of training and experience.
- Proficiency in scripting and programming languages (e.g., Python, JavaScript, PowerShell)
- Experience with REST APIs, webhooks, JSON and/or web application development.
- Familiarity with development workflows and patterns
- Strong problem-solving and analytical skills
- Excellent communication and collaboration abilities.
- Strong understanding of cybersecurity concepts (preferred)
- Experience with SOAR platforms e.g. Tines (preferred)
- Experience in security automation, incident response, or related fields (preferred)
- Experience with cloud environments (AWS, Azure, GCP) (preferred)
- Relevant cybersecurity certifications (preferred)