XSOAR Security Automation Engineer - W2 ONLY
matlen silverDenver, CO
XSOAR Security Automation Engineer - W2 ONLY
L5
matlen silverDenver, CO2 days ago
Occupations
Information Security EngineersInformation Security AnalystsComputer Systems Engineers/ArchitectsIndustries
Computer Systems Design ServicesCustom Computer Programming ServicesOther Computer Related ServicesProject Details:"SOAR Engineering & Integrations- Design, build, and maintain integrations between XSOAR and platforms such as Archer (or other GRC tools), Security Scorecard (or similar vendor risk tools), and SIEM solutions such as Splunk.- Develop custom connectors and API-based integrations where native connectors do not exist.- Normalize, enrich, and correlate data from third-party and external risk sources for operational use. Third-Party Risk Alerting- Build alerting logic for vendor-related threats including vendor breaches, risk score degradation, SaaS abuse, and exposure of vendor-managed assets.- Correlate vendor risk signals with internal telemetry to determine potential business impact.- Enable SOC workflows for third-party-related detections. Automation & Playbooks- Design and implement SOAR playbooks to triage, enrich, and respond to vendor-related alerts.- Automate response actions such as token revocation, access suspension, ticket creation, and stakeholder notification.- Maintain and optimize playbooks to reduce manual effort and mean time to respond (MTTR).- Partner with SOC, Vendor Risk, Threat Modeling, and Detection Engineering teams to translate risk scenarios into automation logic.- Document integrations, workflows, and playbooks.- Monitor performance and reliability of SOAR automations." Non Negotiables"- 3+ years of experience in security engineering, SOAR engineering, or security automation.- Hands-on experience with Cortex XSOAR (or similar SOAR platform).- Experience integrating SIEM platforms such as Splunk.- Strong API integration and scripting skills (Python, REST, JSON, webhooks).- Solid understanding of incident response workflows, SaaS security, IAM, and third-party risk.- Docker, Kubernetes, containerization pipeline, and deployment experience.- Other security certifications (e.g. CCNA Security, GSEC, GCED, GPPA, etc.).- Other technical Certifications (e.g. CCNA, RHCE, MCSE, etc.).- Demonstrated knowledge of Large Language Models (LLMs) and Generative AI, with a focus on Azure AI offerings" Negotiables"- Experience integrating Archer, Service Now GRC, Security Scorecard, Bit Sight, or Risk Recon.- Knowledge of MITRE ATTACK and detection engineering concepts.- Experience automating SaaS security actions (token revocation, session termination).- Familiarity with External Attack Surface Management (EASM) tools"
Apply now
Level
SeniorL5
Location
Denver, CO
Occupation
Information Security Engineers
Industry
Computer Systems Design Services
Posted
2 days ago
To get sharper similar jobs, create your profile using the link below.