21 Aug
|
SteerLean Consulting
|
Gurugram
21 Aug
SteerLean Consulting
Gurugram
XSIAM Administrator & Automation Engineer About The Role We are looking for an XSIAM Administrator & Automation Engineer to own the day-to-day administration, data onboarding, detection engineering and automation strategy of our Cortex XSIAM (Extended Security Intelligence and Automation Management) platform.
This role sits at the intersection of security operations engineering and AI-driven automation — you will design, build, and continuously improve the detection content, playbooks, and AI-assisted workflows that let our SOC operate at machine speed. You will work closely with multiple security operations team such as incident response, threat hunt, insider risk to ensure XSIAM is correctly configured, fully onboarded, and increasingly autonomous in how it triages, investigates, and responds to threats.
Key Responsibilities Platform Administration
- Administer and maintain the Cortex XSIAM tenant: user roles, RBAC, licensing, health monitoring, and platform upgrades.
- Onboard and normalize new data sources (logs, endpoint telemetry, cloud, identity, network) using XDM (Cortex Data Model) mapping and parsing rules.
- Manage integrations and content packs, including third-party connectors, brokers, and collectors.
- Tune detection content — BIOCs, correlation rules, analytics, and incident scoring — to reduce noise and improve fidelity.
- Monitor platform performance, data ingestion costs, and storage tiering, and troubleshoot ingestion or parsing failures.
Logging and Detection Engineering
- Onboard logs directly from sources or via secure data pipeline management solution such as Cribl
- Extend detection engineering scope by creating corelation, analytics rule using XSIAM jupyter notebooks.
- Support detection engineering and threat-hunting initiatives with automation and XQL query development.
Automation & Playbook Engineering
- Design, build,
and maintain automation playbooks (XSOAR/XSIAM playbook engine) to automate alert triage, enrichment, containment, and remediation.
- Develop custom automations, scripts, and integrations (Python) to extend out-of-the-box XSIAM capabilities.
- Continuously identify manual SOC workflows and convert them into automated, auditable playbooks, driving down mean time to detect (MTTD) and mean time to respond (MTTR).
- Build and maintain CI/CD pipelines for playbook and content versioning, testing, and deployment across environments.
AI-Driven Security Operations
- Apply Cortex XSIAM's native AI/ML capabilities (AI-driven incident scoring, causality analysis, alert clustering, and DRP/attack-surface insights) to accelerate investigation and reduce analyst workload.
- Integrate large language model (LLM)-based assistants and agentic workflows into playbooks for tasks such as alert summarization, natural-language incident querying, phishing/malware triage, and auto-generated investigation reports.
- Evaluate and pilot emerging AI/agentic-SOC features (e.g., autonomous investigation agents, AI copilots, natural-language-to-XQL query generation) and lead responsible adoption across the security operations team.
- Build feedback loops and guardrails (human-in-the-loop approval steps, confidence thresholds, audit logging) to ensure AI-assisted actions remain safe, explainable, and compliant.
- Use AI-assisted coding tools to accelerate development of custom scripts,
integrations, and XQL queries, while maintaining rigorous testing and code-review standards.
Required Qualifications
- 3+ years of experience in security operations, SIEM/SOAR administration, or detection/automation engineering.
- Hands-on experience administering Cortex XSIAM, Cortex XSOAR, or a comparable SIEM/SOAR platform (Splunk SOAR, Microsoft Sentinel, IBM QRadar, etc.).
- Solid scripting ability in Python, and comfort working with REST APIs to build custom integrations.
- Practical knowledge of XQL (or equivalent query language) for building correlation rules, dashboards, and threat-hunting queries.
- Solid understanding of SOC workflows: alert triage, incident response, threat intelligence, and case management.
- Experience with data onboarding/parsing (log normalization, XDM/CIM-style schemas) from diverse sources (EDR, cloud, network, identity).
- Familiarity with applying or integrating AI/LLM capabilities into operational workflows (prompt design, AI copilots, or agentic automation) — production experience preferred, strong conceptual understanding acceptable.
Preferred Qualifications
- Palo Alto Networks Certified XSIAM Engineer, XSIAM Analyst, or XSOAR Engineer certification.
- Experience with CI/CD tooling (Git, Jenkins/GitHub Actions) for security content and playbook lifecycle management.
- Exposure to cloud platforms (AWS, Azure, GCP) and containerized environments.
- Experience with MITRE ATT&CK-mapped; detection engineering.
- Prior experience deploying agentic AI workflows, AI-assisted SOC copilots, or natural-language query interfaces in a security context.
Education Bachelor's degree in Computer Science, Information Technology, or a related field. Relevant certifications (CISSP, CISM, CEH) are preferred.
📌 Security Engineer II (Gurugram)
🏢 SteerLean Consulting
📍 Gurugram