Cybersecurity Automation Engineer

Iconma LLC

  • Atlanta, GA
  • 19 days ago

    Highlights

    This role will focus on ingesting and correlating data from third-party risk and security tools (e.g., Archer, SecurityScorecard, Splunk), enabling alerting for vendor-related threats, and executing automated response playbooks to reduce risk and response time. Design, build, and maintain integrations between XSOAR and platforms such as Archer (or other GRC tools), SecurityScorecard (or similar vendor risk tools), and SIEM solutions such as Splunk.

    Numbers & Facts

    LocationAtlanta, GA

    Description

    Our client, a Commercial Banking company, is looking for a Cybersecurity Automation Engineer for their Atlanta GA location.

    Responsibilities:

    • Cybersecurity Automation Engineer to design, build, and maintain integrations and automated workflows within our SOAR platform (Cortex XSOAR).
    • This role will focus on ingesting and correlating data from third-party risk and security tools (e.g., Archer, SecurityScorecard, Splunk), enabling alerting for vendor-related threats, and executing automated response playbooks to reduce risk and response time.

    SOAR Engineering & Integrations

    • Design, build, and maintain integrations between XSOAR and platforms such as Archer (or other GRC tools), SecurityScorecard (or similar vendor risk tools), and SIEM solutions such as Splunk.
    • Develop custom connectors and API-based integrations where native connectors do not exist.
    • Normalize, enrich, and correlate data from third-party and external risk sources for operational use.

    Third-Party Risk Alerting

    • Build alerting logic for vendor-related threats including vendor breaches, risk score degradation, SaaS abuse, and exposure of vendor-managed assets.
    • Correlate vendor risk signals with internal telemetry to determine potential business impact.
    • Enable SOC workflows for third-party-related detections.

    Automation & Playbooks

    • Design and implement SOAR playbooks to triage, enrich, and respond to vendor-related alerts.
    • Automate response actions such as token revocation, access suspension, ticket creation, and stakeholder notification.
    • Maintain and optimize playbooks to reduce manual effort and mean time to respond (MTTR).
    • Partner with SOC, Vendor Risk, Threat Modeling, and Detection Engineering teams to translate risk scenarios into automation logic.
    • Document integrations, workflows, and playbooks.
    • Monitor performance and reliability of SOAR automations.

    Requirements:

    • 3+ years of experience in security engineering, SOAR engineering, or security automation.
    • Hands-on experience with Cortex XSOAR (or similar SOAR platform).
    • Experience integrating SIEM platforms such as Splunk.
    • Strong API integration and scripting skills (Python, REST, JSON, webhooks).
    • Solid understanding of incident response workflows, SaaS security, IAM, and third-party risk.
    • Docker, Kubernetes, containerization pipeline, and deployment experience.
    • Other security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.).
    • Other technical Certifications (e.g. CCNA, RHCE, MCSE, etc.).
    • Demonstrated knowledge of Large Language Models (LLMs) and Generative AI, with a focus on Azure AI offerings"
    • Experience integrating Archer, ServiceNow GRC, SecurityScorecard, BitSight, or RiskRecon.
    • Knowledge of MITRE ATTACK and detection engineering concepts.
    • Experience automating SaaS security actions (token revocation, session termination).
    • Familiarity with External Attack Surface Management (EASM) tools

    Why Should You Apply?

    • Health Benefits
    • Referral Program
    • Excellent growth and advancement opportunities

    Similar Jobs

    See more jobs