11 days ago
Bengaluru, IndiaSenior / Staff+
Responsibilities
- Design and implement automated workflows and playbooks across SOC, CSPM, vulnerability management, and IAM platforms.
- Integrate Sentinel, Wiz, SailPoint, Check Point, Zscaler, SOAR platforms, threat intelligence tools, and ticketing systems using APIs and event-driven automation.
- Build incident response, threat enrichment, user isolation, phishing, malware, insider threat, and ticket closure automations.
- Develop cross-platform integrations across IT, OT, and cloud security tools for unified visibility and real-time telemetry correlation.
- Create reusable automation modules and templates for consistent deployment across global regions.
- Automate cloud posture monitoring and remediation across Azure, AWS, and GCP.
- Engineer infrastructure-as-code security controls and guardrails and integrate automation into DevSecOps pipelines.
- Continuously tune automation using MITRE ATT&CK and MITRE ATLAS techniques.
Requirements
- Bachelor's degree in Computer Science or Engineering.
- 16+ years of relevant experience and 7–12 years of cybersecurity or security engineering experience.
- At least 3 years of security automation or SOAR engineering experience.
- Hands-on expertise with Cortex XSOAR, FortiSOAR, Microsoft Sentinel Logic Apps, Splunk SOAR, or custom Python orchestration.
- Experience with Python, PowerShell, REST APIs, JSON, YAML, Azure, AWS, GCP, Terraform, Ansible, Jenkins, and GitHub Actions.
- Knowledge of integrating SIEM, EDR/XDR, IAM, DLP, CSPM, CNAPP, CASB, and vulnerability scanning tools.
- Strong understanding of incident response, SOC processes, and MITRE ATT&CK frameworks.
- Proven ability to reduce manual operational workload through automation at scale.
