24 Sep
|
WSNE Consulting
|
Mumbai
24 Sep
WSNE Consulting
Mumbai
Roles & Responsibilities
- Develop, maintain, and enhance automated SOAR playbooks to streamline and improve security incident response workflows.
- Design and implement automation workflows for incident detection, triage, investigation, enrichment, and remediation.
- Configure and optimize Cortex XSOAR/XSIAM or other SOAR platforms to improve security operations efficiency.
- Integrate SOAR playbooks with SIEM, EDR, firewalls, threat intelligence platforms, endpoint protection tools, and ticketing systems.
- Develop and manage custom SIEM content, including detection rules, correlation logic, and security monitoring use cases.
- Test, troubleshoot, and optimize playbooks, integrations, and automation workflows for performance, reliability, and scalability.
- Perform root cause analysis and resolve issues related to failed playbooks, integrations, and security automation processes.
- Collaborate with SOC analysts, incident responders, security engineers,
and IT teams to identify automation opportunities and improve security operations.
- Support threat detection, incident response, threat intelligence, network security, and vulnerability management activities.
- Develop and maintain automation scripts using Python, JavaScript, PowerShell, or similar scripting languages.
- Document playbook logic, workflows, integrations, configurations, and standard operating procedures.
- Continuously enhance existing automation processes based on security incidents, operational requirements, and performance feedback.
- Assist in evaluating and implementing SOAR technologies and security automation capabilities based on organizational requirements.
- Ensure security automation workflows align with established security processes, operational requirements, and organizational objectives.
📌 Assistant Manager (Mumbai)
🏢 WSNE Consulting
📍 Mumbai