Security Automation Engineer
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Security Automation Engineer – Managed Detection & Response (MDR)
As a Security Automation Engineer, you will design, build, and maintain automated response capabilities using Palo Alto Cortex XSOAR. Your work will directly impact the efficiency and consistency of handling security incidents across complex customer environments, translating detection signals into automated, reliable, and auditable response workflows.
We strongly believe in SOAR as code—automation content is version‑controlled, tested, and continuously improved.
Key Responsibilities
- Security Automation & Playbook Development
- Design, build, and maintain response playbooks in Cortex XSOAR for common and advanced security incidents.
- Translate detection alerts from SIEM and XDR platforms into automated investigation and response flows.
- Implement conditional logic, enrichment steps, human‑in‑the‑loop approvals, and automated containment actions.
- SOAR as Code
- Manage playbooks, integrations, scripts, and content packs using version control (Git).
- Apply software engineering best practices such as modularity, reusability, testing, and peer review.
- Contribute to standardized automation frameworks that can be reused across customers.
- Platform Integrations
- Build and maintain integrations between XSOAR and SIEM platforms, XDR/EDR solutions, ITSM tools, and identity, network, and cloud security controls.
- Troubleshoot and optimize integrations for reliability, performance, and scalability.
- Incident Response Enablement
- Collaborate closely with Detection Engineering and Incident Response teams to define automated investigation steps, response actions, containment strategies, and escalation handover points to analysts.
- Continuously improve response quality based on real incident feedback.
- Automation Lifecycle Management
- Maintain and evolve our automation content library.
- Tune playbooks to reduce noise, false positives, and manual effort.
Core Technologies
- Palo Alto Cortex XSOAR
- Microsoft Defender XDR and other XDR platforms
- SIEM platforms such as Microsoft Sentinel
- ITSM platforms (ServiceNow and equivalents)
- Cloud, identity, network, and third‑party security tooling