2 дня назад
Analyst II, Cybersecurity (Automation)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Analyst II, Cybersecurity (Automation) (SOAR/SIEM automation): Building and operating production-grade security automations for log ingestion, detection, case management, and incident response with an accent on resilient playbooks, API integrations, and strong data quality controls. Focus on tuning automated detections, improving alert fidelity and response consistency, and maintaining secure, reliable SOAR platforms.
Location: IND HRYN 402, India; onsite role
Company
is a Fortune 500 financial technology company providing solutions for banking, capital markets, retail, and corporate financial services.
What you will do
- Design, develop, test, deploy, and maintain automation for log ingestion, normalization, enrichment, and transformation across diverse data sources.
- Build and tune SOAR detections, rules, and playbooks to reduce false positives and improve response consistency.
- Integrate SOAR platforms with SIEM, EDR, threat intelligence, and ITSM systems using APIs and webhooks.
- Automate case and ticket lifecycle management, including enrichment, correlation, deduplication, SLA tracking, and closure.
- Monitor automation reliability and performance through metrics, logging, alerting, and SLOs; maintain runbooks and on-call documentation.
- Collaborate with SOC analysts, incident responders, threat intelligence, ITSM, and platform teams while supporting migrations, upgrades, and architectural improvements.
Requirements
- Bachelor’s degree in computer science, information security, or equivalent practical experience.
- 3–7 years of experience in security engineering, SOC automation, or security operations.
- Production experience with SOAR automations and playbooks in platforms such as TORQ, Google SecOps SOAR, or Cortex XSOAR.
- Proficiency in Python or another scripting language, such as PowerShell or Bash, for security workflow automation.
- Experience with SIEM, EDR, firewalls, detection content development, alert tuning, incident response, and vulnerability management.
- Knowledge of Azure or GCP, SaaS security tooling, REST or GraphQL APIs, webhooks, OAuth 2.0, JSON serialization, and secure development practices.
Culture & Benefits
- Full-time position with a high degree of responsibility and a broad range of opportunities.
- Professional education and personal development opportunities.
- Career development tools, resources, and opportunities.
- Competitive salary and benefits.
- Work in a global financial technology organization serving clients in more than 130 countries.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Analyst II, Security Operations Center
35 - 58$
1 день назад
Tier 2 Cybersecurity Operations Analyst (Cybersecurity)
20 часов назад
IT Security Analyst (AI)
4 дня назад
Sr. IS Analyst - Security Operations (Cybersecurity)
115 000 - 135 000$
1 час назад
Insider Threat Investigator III (Cybersecurity)
3 дня назад
Principal Cybersecurity Engineer (AI)
184 800 - 277 200$