Description
Project Details:
"SOAR Engineering & Integrations
- Design, build, and maintain integrations between XSOAR and platforms such as Archer (or other GRC tools), SecurityScorecard (or similar vendor risk tools), and SIEM solutions such as Splunk.
- Develop custom connectors and API-based integrations where native connectors do not exist.
- Normalize, enrich, and correlate data from third-party and external risk sources for operational use.
Third-Party Risk Alerting
- Build alerting logic for vendor-related threats including vendor breaches, risk score degradation, SaaS abuse, and exposure of vendor-managed assets.
- Correlate vendor risk signals with internal telemetry to determine potential business impact.
- Enable SOC workflows for third-party-related detections.
Automation & Playbooks
- Design and implement SOAR playbooks to triage, enrich, and respond to vendor-related alerts.
- Automate response actions such as token revocation, access suspension, ticket creation, and stakeholder notification.
- Maintain and optimize playbooks to reduce manual effort and mean time to respond (MTTR).
- Partner with SOC, Vendor Risk, Threat Modeling, and Detection Engineering teams to translate risk scenarios into automation logic.
- Document integrations, workflows, and playbooks.
- Monitor performance and reliability of SOAR automations."
Non Negotiables
"- 3+ years of experience in security engineering, SOAR engineering, or security automation.
- Hands-on experience with Cortex XSOAR (or similar SOAR platform).
- Experience integrating SIEM platforms such as Splunk.
- Strong API integration and scripting skills (Python, REST, JSON, webhooks).
- Solid understanding of incident response workflows, SaaS security, IAM, and third-party risk.
- Docker, Kubernetes, containerization pipeline, and deployment experience.
- Other security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.).
- Other technical Certifications (e.g. CCNA, RHCE, MCSE, etc.).
- Demonstrated knowledge of Large Language Models (LLMs) and Generative AI, with a focus on Azure AI offerings"
Negotiables
"- Experience integrating Archer, ServiceNow GRC, SecurityScorecard, BitSight, or RiskRecon.
- Knowledge of MITRE ATTACK and detection engineering concepts.
- Experience automating SaaS security actions (token revocation, session termination).
- Familiarity with External Attack Surface Management (EASM) tools"