Optiv

Sr. Engineer - SOAR | Onsite, Bangalore.

Optiv
Apply
24 hours ago
Bengaluru, IndiaSenior

Responsibilities

  • Design, develop, and maintain SOAR playbooks, workflows, integrations, and automation using Palo Alto XSOAR and Splunk SOAR.
  • Automate incident response processes for phishing, malware, endpoint, identity, vulnerability, and threat intelligence investigations.
  • Build custom integrations, scripts, automation components, and APIs using Python, REST APIs, JSON, and webhooks.
  • Integrate SOAR with SIEM, EDR/XDR, IAM, email security, network security, threat intelligence, vulnerability management, and other security platforms.
  • Troubleshoot and optimize playbooks, integrations, automation failures, and platform performance issues in production.
  • Participate in SOAR architecture, solution design, deployment, upgrades, migrations, platform administration, and enterprise implementation activities.
  • Establish development standards, documentation, testing procedures, and operational best practices for SOAR content.
  • Support critical automation issues in a 24x7 security operations environment and improve incident response effectiveness and SLAs.
  • Collaborate with SOC analysts, incident responders, threat intelligence, detection engineering, and security engineering teams.
  • Mentor junior SOAR engineers and contribute to technical standards and knowledge sharing.

Requirements

  • 5+ years of experience with Palo Alto XSOAR and/or Splunk SOAR.
  • Experience developing complex SOAR playbooks, workflows, integrations, and automation.
  • Experience with SOAR architecture, platform administration, upgrades, migrations, and enterprise deployments.
  • Strong Python programming and scripting skills.
  • Experience with REST APIs, JSON, webhooks, and API-based integrations.
  • Strong understanding of SOC operations, incident response, and security investigation processes.
  • Experience integrating SOAR with SIEM, EDR/XDR, IAM, email security, threat intelligence, vulnerability management, and related platforms.
  • Experience with Splunk, Palo Alto Networks, CrowdStrike, Microsoft security technologies, ServiceNow, and threat intelligence platforms.
  • Experience troubleshooting and supporting SOAR solutions in production environments.
  • Ability to translate complex security processes into scalable and maintainable automation.
  • Strong analytical, problem-solving, communication, and documentation skills.
  • Relevant vendor or tool certifications such as PCSAE or equivalent XSOAR certification, Splunk SOAR or Splunk Certified certifications, and relevant CrowdStrike, Microsoft, Google SecOps, Elastic, SIEM, EDR/XDR, threat intelligence, or security automation certifications.
  • Excellent English fluency is required.

Benefits

  • Inclusive workplace supported by Employee Resource Groups.
  • Work/life balance, professional training resources, and opportunities to tackle complex projects.
  • Volunteer opportunities through the Optiv Chips In program.
  • Work from office three days per week, with technology to work remotely/from home where applicable.
  • Availability is required during US working hours from 5:00 PM to 2:00 AM IST.

Tech Stack

PythonSplunk

Categories

Optiv

About Optiv

1,001-5,000 employees

Optiv provides cybersecurity consulting, technology integration, and managed security services for enterprises, covering areas such as identity and access management, threat and vulnerability management, and cloud security. The company operates service delivery through its Advanced Fusion Center for detection and response and other managed offerings. Founded in 2015 and headquartered in Leawood, Kansas, Optiv is privately held and owned by Kohlberg Kravis Roberts & Co. (KKR).

Contact me