Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com
PG

Security Automation / Cortex XSOAR Engineer

Perfict Global, Inc.
  • Location not stated
  • Remote
  • 7 hours ago
  • Cortex
  • Incident Response
  • Python
  • Splunk
  • SIEM
  • CrowdStrike
  • Azure
  • Threat Intelligence
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Security Automation / Cortex XSOAR Engineer

Location: Remote
Job Type:Contract-to-Hire
Duration:
Contract to 8/2028; extensions possible
Job Summary
We are seeking a Security Automation / Cortex XSOAR Engineer to support and enhance our Security Operations and Incident Response capabilities. This role will focus on developing and maintaining Palo Alto Cortex XSOAR playbooks, automation workflows, and integrations that improve the speed, consistency, and effectiveness of security incident response.
The ideal candidate has strong hands-on experience with Cortex XSOAR, Python, Splunk, and security operations, with the ability to troubleshoot automation issues and work closely with Incident Response and SOC teams.
Key Responsibilities
  • Develop, enhance, and maintain Palo Alto Cortex XSOAR playbooks and automated security workflows.
  • Build automation to support Incident Response and Security Operations processes.
  • Troubleshoot XSOAR integrations, playbooks, scripts, and automation failures.
  • Develop and maintain integrations with security tools, SIEM platforms, and other enterprise technologies.
  • Partner with Incident Response Analysts and SOC teams to identify opportunities for security automation.
  • Analyze security events, incidents, and operational trends to identify areas for improvement.
  • Define and implement new SOAR use cases, automation requirements, and response workflows.
  • Use Python scripting/programming to develop and enhance security automation.
  • Work with security teams to streamline incident response processes and improve operational efficiency.
  • Support Splunk and other security monitoring technologies as part of incident investigation and automation workflows.
  • Document playbooks, integrations, workflows, troubleshooting procedures, and operational processes.
  • Participate in troubleshooting and resolution of security automation and integration issues.
  • Help maintain and improve security operations procedures, standards, and best practices.
Required Qualifications
  • High school diploma or equivalent.
  • 5+ years of hands-on cybersecurity, security operations, incident response, or security automation experience.
  • Strong hands-on experience developing and maintaining Palo Alto Cortex XSOAR playbooks.
  • Experience building and supporting SOAR automation workflows.
  • Strong Python scripting/programming skills.
  • Solid understanding of Incident Response processes and security operations workflows.
  • Hands-on experience with Splunk or another enterprise SIEM platform.
  • Strong troubleshooting and security data analysis skills.
  • Experience developing, maintaining, and troubleshooting automated security playbooks.
  • Ability to work effectively with SOC, Incident Response, Cybersecurity, and Infrastructure teams.
  • Strong written and verbal communication skills.
Preferred Qualifications
Candidates with the following experience will receive priority:
  • CrowdStrike
  • Proofpoint
  • Tanium
  • Microsoft Azure
  • Digital Forensics
  • Threat Intelligence
  • SIEM technologies
  • Network and security infrastructure
  • Security orchestration and automation
  • API integrations and security tool integrations
  • Additional scripting/programming experience

Security Automation / Cortex XSOAR Engineer · Perfict Global, Inc.

Auto apply with Likeremote