The Role
Develop and support cybersecurity automation across Cortex XSOAR and Splunk. Build integrations, automated workflows, playbooks, and security data-source onboarding processes while improving SOC efficiency, reliability, and scalability. Collaborate with Incident Response, Threat Intelligence, Insider Risk, and SOC teams. Maintain internal and third-party tools, manage competing requests, and develop software using Python, web frameworks, Linux, Git, SQL, and front-end technologies.
Summary Generated by Built In
Qualifications
This role is responsible for developing, enhancing, and supporting security automation solutions across Cortex XSOAR and Splunk. The successful candidate will collaborate with Incident Response, Threat Intelligence, Insider Risk, and SOC stakeholders to build integrations and automated workflows, onboard and maintain security data sources, and improve the reliability and efficiency of security operations. The position requires strong software development experience and the ability to deliver scalable solutions in a fast-paced, cross-functional environment.
Key Responsibilities
- Collaborate closely with the Incident Response, Threat Intelligence, and Insider Risk teams to design, develop, and enhance capabilities on the Cortex XSOAR platform.
- Develop and implement automation solutions that reduce manual effort and improve the efficiency of Security Operations Center (SOC) processes.
- Operate effectively in a fast-paced environment, managing and prioritizing diverse requests from multiple teams.
- Develop, maintain, and enhance internally built and third-party tools, ensuring their reliability, scalability, and alignment with operational requirements.
Required Qualifications
- A minimum of seven years of software development experience using Python and web frameworks such as Django and Flask.
- Working knowledge of front-end technologies, including HTML, CSS, JavaScript, and jQuery.
- Hands-on experience working in Linux environments, including Red Hat Enterprise Linux (RHEL) and Debian-based distributions.
- Experience managing source code and collaborating through Git-based repositories.
- A sound understanding of SQL fundamentals and database management systems (DBMS).
- A demonstrated eagerness to learn new technologies and adapt quickly to changing requirements.
- Basic knowledge of Security Operations Center (SOC) operations, including security monitoring, alert triage, incident investigation, and escalation processes.
Added Advantage
- Experience designing and developing features, integrations, or automated playbooks within Security Orchestration, Automation, and Response (SOAR) platforms.
- Hands-on experience onboarding, configuring, and validating data sources in Splunk.
- Proficiency in developing and optimizing complex Splunk Search Processing Language (SPL) queries for security monitoring, investigation, and reporting.
- Experience working with cybersecurity tools that support incident response and threat intelligence operations.
- Experience integrating security platforms with IT service management tools and ITIL-aligned workflows, particularly ServiceNow.
Skills Required
- At least seven years of software development experience using Python and web frameworks such as Django and Flask
- Working knowledge of HTML, CSS, JavaScript, and jQuery
- Hands-on experience in Linux environments, including Red Hat Enterprise Linux and Debian-based distributions
- Experience managing source code and collaborating through Git-based repositories
- Understanding of SQL fundamentals and database management systems
- Eagerness to learn new technologies and adapt to changing requirements
- Basic knowledge of SOC operations, including security monitoring, alert triage, incident investigation, and escalation
- Experience designing and developing features, integrations, or automated playbooks in SOAR platforms
- Experience onboarding, configuring, and validating Splunk data sources
- Proficiency developing and optimizing complex Splunk SPL queries
- Experience with cybersecurity tools supporting incident response and threat intelligence operations
- Experience integrating security platforms with IT service management tools and ITIL-aligned workflows, particularly ServiceNow
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company






